XML 47 R30.htm IDEA: XBRL DOCUMENT v3.22.0.1
Subsequent Event
12 Months Ended
Dec. 31, 2021
Subsequent Event  
Subsequent Event

23. Subsequent Event

The Company relies on the integrity, security and successful functioning of its information technology systems and network infrastructure (collectively, “IT Systems”) across its operations. In February 2022, the Company announced that it was experiencing a cybersecurity incident that resulted in the encryption of certain IT Systems and theft of certain data and information (the “Cybersecurity Incident”). The Cybersecurity Incident resulted in the Company’s temporary inability to access certain of its IT Systems, caused by the disabling of some of its IT Systems by the threat actor and the Company temporarily taking certain other IT Systems offline as a precautionary measure. The Company engaged leading outside forensics and cybersecurity experts, launched containment and remediation efforts and a forensic investigation, and is working on restoring and ensuring the security of its IT Systems. The Company is also coordinating with law enforcement. The Company is in the early stages of this incident and has not determined the full scope or content of its lost or stolen data.

The Company has and expects to continue to incur incremental costs for the investigation, containment and remediation of the Cybersecurity Incident, including legal and other professional fees, and investments to enhance the security of its IT Systems. The containment, investigation, remediation, legal and other costs may exceed its insurance policy limits or may not be covered by insurance at all. Other actual and potential consequences include, but are not limited to, negative publicity, reputational damage, lost trust with customers, regulatory enforcement action, and litigation that could result in financial judgments or the payment of settlement amounts and disputes with insurance carriers concerning coverage. The Company has not yet determined if the Cybersecurity Incident will cause future disruptions to its business or how long such disruption could last. The Company has also not yet been able to estimate the incremental costs resulting from the Cybersecurity Incident, which are expected to adversely impact its future financial results. Based on the information currently known, the Company does not believe that the Cybersecurity Incident will have a material impact on its business, results of operations or financial condition, but no assurances can be given as the Company continues to assess the full impact from the Cybersecurity Incident, including costs, expenses and insurance coverage.