← Back to SFNC filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Other than as set forth below, there have been no material changes in the risk factors faced by the Company from those disclosed in the Company’s Annual Report on Form 10-K for the year ended December 31, 2025.
Our business is heavily reliant on information technology systems, facilities, and processes; and a disruption in those systems, facilities, and processes, or a breach, including cyber-attacks, in the security of our systems, could have significant, negative impacts on our business, result in the disclosure of confidential information, and create significant financial and legal exposure for us.
Our businesses are dependent on our ability and the ability of our third-party service providers to process, record and monitor a large number of transactions and personally identifiable information. If the financial, accounting, data processing or other operating systems and facilities fail to operate properly, become disabled, experience security breaches or have other significant shortcomings, our results of operations could be materially, adversely affected.
Although we and our third party service providers devote significant resources to maintain and regularly upgrade our systems and processes that are designed to protect the security of computer systems, software, networks and other technology assets and the confidentiality, integrity and availability of information belonging to us and our customers, there is no assurance that our security systems and those of our third-party service providers will provide absolute security. Financial services institutions and companies engaged in data processing have reported breaches in the security of their websites or other systems, some of which have involved sophisticated and targeted attacks intended to obtain unauthorized access to confidential information, destroy data, disable or degrade service, or sabotage systems, often through the introduction of computer viruses or malware, cyber-attacks and other means. Certain financial institutions in the United States have also experienced attacks from technically sophisticated and well-resourced third parties that were intended to disrupt normal business activities by making internet banking systems inaccessible to customers for extended periods. These “denial-of-service” attacks have not breached our data security systems, but require substantial resources to defend, and may affect customer satisfaction and behavior. We, our customers, regulators and other third parties, including other financial services institutions and companies engaged in data processing, have been subject to, and are likely to continue to be the target of, cyber-attacks. The techniques used in cyber-attacks change rapidly and are increasingly sophisticated, including through the use of generative artificial intelligence and deepfakes, and we expect in the future through the use of quantum computing, and we may not be able to anticipate cyber-attacks or data security breaches.
74
Despite our efforts and those of our third party service providers to ensure the integrity of our systems, it is possible that we may not be able to anticipate or to implement effective preventive measures against all security breaches of these types, especially because the techniques used change frequently or are not recognized until launched, and because security attacks can originate from a wide variety of sources, including persons who are involved with organized crime or associated with external service providers or who may be linked to terrorist organizations or hostile foreign governments. Those parties may also attempt to fraudulently induce employees, customers or other users of our systems to disclose sensitive information in order to gain access to our data or that of our customers or clients. These risks may increase in the future as artificial intelligence continues to evolve and we continue to increase our mobile payments and other internet-based product offerings and expand our internal usage of web-based products and applications. Furthermore, because certain of our employees are working, or may work, remotely, there is an increased risk of disruption to our systems because remote networks and infrastructure may not be as secure as in our office environment. If our security systems were penetrated or circumvented, it could cause serious negative consequences for us, including significant disruption of our operations, misappropriation of our confidential information or that of our customers, or damage our computers or systems and those of our customers and counterparties, and could result in violations of applicable privacy and other laws, financial loss to us or to our customers, loss of confidence in our security measures, customer dissatisfaction, significant litigation exposure, and harm to our reputation, all of which could have a material adverse effect on us.
Additionally, as cyber-attacks continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities or incidents.
If we are unsuccessful in developing new, and adapting our current, products and services so that they respond to changing industry standards and customer preferences, our business may suffer.
We provide a variety of commercial and consumer banking, as well as other financial, products and services designed to meet a broad range of needs. While many of these products and services are traditional both in their characteristics and their delivery channels, advancements in technology, changes in the regulatory environment, and evolving customer preferences require that we continuously evaluate the terms under which we provide our existing products and services (including, among other things, interest rates and loan covenants), the methods by which we deliver them (including the use of online and mobile banking), whether to partner with a FinTech company or other third-party vendor to provide products and services, and the potential for new products and services in order to remain competitive. These efforts, though, could require substantial investments, and we can provide no assurance that we will develop new products and services, or adequately adapt our existing products and services, in a timely or successful manner. Our inability to do so could harm our business and adversely affect our results of operations and reputation. Furthermore, any new line of business and/or new product or service could require the establishment of new key and other controls and have a significant impact on our existing system of internal controls. Failure to successfully manage these risks in the development and implementation of new lines of business and/or new products or services could have a material adverse effect on our business and, in turn, our financial condition and results of operations.
Recently, the financial services industry has experienced rapid developments in artificial intelligence, including agentic artificial intelligence. The use of artificial intelligence models developed by third parties introduces risks related to how those models are developed, trained, and deployed, including unauthorized material in training data and limited visibility into risk mitigation steps. The legal and regulatory environment for artificial intelligence is uncertain and rapidly involving, potentially increasing compliance costs and risks of noncompliance. We may be exposed to the risk that generative artificial intelligence models may produce incorrect outputs, release confidential information, reflect biases, or otherwise cause harm. Their complexity may make it challenging to understand all outputs and comply with documentation or explanation requirements. Further, regulators have warned financial institutions of an increased risk of cyber attacks with the use of artificial intelligence. Any of these risk could adversely affect our business, expose us to liability or other adverse legal or regulatory consequences, or otherwise adversely affect our financial results.
75
Item 2. Unregistered Sales of Equity Securities and Use of Proceeds
In January 2024, we announced a stock repurchase program (“2024 Program”) under which we could repurchase up to $175.0 million of our Class A Common Stock currently issued and outstanding. The 2024 Program terminated in January 2026, and the Company’s Board of Directors authorized a new stock repurchase program in January 2026 (“2026 Program”) under which the Company may repurchase up to $175.0 million of its Class A common stock currently issued and outstanding. The 2026 Program will be executed in accordance with Rule 10b-18 under the Securities Exchange Act of 1934, as amended, and is set to terminate on January 31, 2028 (unless terminated sooner). The timing, pricing, and amount of any repurchases under the 2026 Program will be determined by the Company’s management at its discretion based on a variety of factors, including, but not limited to, trading volume and market price of the Company’s common stock, corporate considerations, the Company’s working capital and investment requirements, general market and economic conditions, and legal requirements.
Information concerning our purchases of common stock during the quarter ended June 30, 2026 is as follows:
Period Total Number of Shares Purchased (1) Average Price Paid per Share Total Number of Shares Purchased as Part of Publicly Announced Plans or Programs Approximate Dollar Value of Shares that May Yet Be Purchased Under the Plans or Programs
April 1, 2026 - April 30, 2026 — $ — — $ 175,000,000
May 1, 2026 - May 31, 2026 240,085 21.30 5,114,745 $ 169,885,000
June 1, 2026 - June 30, 2026 421,997 21.64 9,130,679 $ 160,755,000
Total 662,082 $ 21.52 14,245,424
_______________________________________
(1)No shares of restricted stock were purchased in connection with employee tax withholding obligations under employee compensation plans, which are not purchases under any publicly announced plan.