BLKB.NASDAQBlackbaud INC

10-K/A: Blackbaud Amends 10-K to Enhance Cybersecurity and Governance Disclosures with iXBRL Tagging

Sentiment:

Amendment to Annual Report


Blackbaud, Inc. filed an Amendment No. 1 to its Annual Report on Form 10-K for the fiscal year ended December 31, 2024, primarily to include omitted iXBRL tagging for cybersecurity and insider trading policy disclosures and update certifications.

Summary

  • This Amendment No. 1 to Form 10-K/A for the fiscal year ended December 31, 2024, was filed by Blackbaud, Inc. to include inadvertently omitted iXBRL (Inline eXtensible Business Reporting Language) tagging.
  • The omitted tagging pertains to Part I, Item 1C. Cybersecurity, and Part III, Item 10 related to the Company's Insider Trading Policy.
  • The amendment also includes current-dated Exhibit 31.1, 31.2, 32.1, and 32.2 certifications from the Chief Executive Officer and Chief Financial Officer.
  • The document explicitly states that no other changes have been made to the Original Filing, and it speaks as of the original filing date of February 21, 2025.
  • Blackbaud maintains a comprehensive cybersecurity program founded on a four-prong strategy: operational security (leveraging CIA Triad Model, NIST Cybersecurity Framework, PCI DSS, SOC 1, SOC 2, GDPR, HIPAA, Trans-Atlantic Data Privacy Framework, Cloud Security Alliance), product security, incident response (24/7 monitoring, third-party coordination, routine testing, law enforcement relationships), and ongoing landscape analysis.
  • Cybersecurity risk management is integrated into the company's overall enterprise risk management (ERM) framework, business strategy, financial planning, and capital allocation.
  • The company regularly engages outside consultants and experts for cybersecurity assessments and incident response.
  • A dedicated program and team provide security oversight for third-party service providers.
  • Blackbaud's cybersecurity governance structure includes an Operational Risk Compliance and Security (ORCAS) Committee, a Risk Steering Committee (comprising executives including the CEO, COO, CFO, CTO, General Counsel, Chief Privacy Officer, and CISO), and oversight by the Board of Directors' Risk Oversight Committee.
  • The Chief Information Security Officer (CISO) has over 25 years of experience in information technology and security, holding CISSP and CCSP certifications.
  • The company has an Insider Trading Policy and Guidelines for Certain Securities Transactions designed to ensure compliance with insider trading laws and Nasdaq listing standards.

Sentiment

Score: 7

Explanation: The document is a compliance filing, inherently neutral in tone. However, the detailed disclosure of a robust cybersecurity program, strong governance structure, and management certifications contribute positively to transparency and confidence in the company's controls, despite the acknowledgment of past incidents and ongoing legal risks. The proactive measures and adherence to industry standards are favorable.

Positives

  • Blackbaud maintains a comprehensive and continuously assessed cybersecurity program, leveraging industry-standard frameworks like NIST, PCI DSS, SOC 1, SOC 2, GDPR, and HIPAA.
  • Cybersecurity risk management is deeply integrated into the company's overall business strategy, financial planning, and capital allocation, indicating a high level of prioritization.
  • The company engages external consultants and experts for annual cybersecurity assessments and incident response, demonstrating a commitment to external validation and expertise.
  • A dedicated program and team are in place for security oversight of third-party service providers, addressing a common vulnerability point.
  • The multi-level cybersecurity governance structure, including executive and board oversight, highlights robust internal controls and accountability.
  • The Chief Information Security Officer (CISO) possesses extensive experience (over 25 years) and holds recognized industry certifications (CISSP, CCSP), indicating strong leadership in cybersecurity.
  • The company has an established Insider Trading Policy and Guidelines, promoting ethical conduct and compliance with securities laws.
  • The CEO and CFO have provided current-dated certifications, affirming the accuracy of the report and the effectiveness of disclosure controls and internal financial reporting.

Negatives

  • The company experienced a ransomware attack in May 2020, which resulted in a copy of a subset of data being removed from its self-hosted environment.
  • As a direct result of the 2020 Security Incident, Blackbaud is currently subject to certain legal proceedings and claims.
  • There is a potential for additional future legal proceedings, claims, inquiries, and investigations related to the Security Incident, which could lead to adverse judgments, settlements, fines, or penalties.
  • Despite strong commitments, the company acknowledges that it may not be successful in preventing or mitigating all future cybersecurity incidents, which could have a material adverse effect.

Risks

  • Ongoing legal proceedings and claims stemming from the May 2020 ransomware attack, with potential for additional future legal actions, inquiries, and investigations.
  • Risk of adverse judgments, settlements, fines, or penalties as a result of current or future legal proceedings related to the Security Incident.
  • Inability to successfully prevent or mitigate future cybersecurity incidents, which could materially adversely affect the company's operations, financial condition, or reputation.
  • Risks associated with the security posture of third-party service providers, despite the company's oversight program.
  • General cybersecurity and data protection risks, including potential liabilities from data breaches or non-compliance with privacy regulations.

Future Outlook

The document includes a general cautionary statement regarding forward-looking statements, which encompass anticipated growth, future financial performance, the effect of general economic and market conditions, business strategy, and the impact of integrating new technologies like generative AI. However, this amendment does not provide specific new financial guidance or updated forward-looking projections.

Management Comments

  • "Based on my knowledge, this report does not contain any untrue statement of a material fact or omit to state a material fact necessary to make the statements made, in light of the circumstances under which such statements were made, not misleading with respect to the period covered by this report." (Michael P. Gianoni, CEO; Chad M. Anderson, CFO)
  • "Based on my knowledge, the financial statements, and other financial information included in this report, fairly present in all material respects the financial condition, results of operations and cash flows of the registrant as of, and for, the periods presented in this report." (Michael P. Gianoni, CEO; Chad M. Anderson, CFO)
  • "The Report fully complies with the requirements of Section 13(a) or 15(d) of the Securities Exchange Act of 1934; and The information contained in the Report fairly presents, in all material respects, the financial condition and results of operations of the Company." (Michael P. Gianoni, CEO; Chad M. Anderson, CFO)

Industry Context

The detailed disclosure of Blackbaud's cybersecurity program, adherence to global data privacy regulations (GDPR, HIPAA), and utilization of industry-standard frameworks (NIST, PCI DSS, SOC) reflects a pervasive and escalating focus on data security and privacy across all industries. This trend is driven by increasing regulatory scrutiny, the growing sophistication of cyber threats, and the critical importance of data integrity for business continuity and customer trust. The company's proactive stance aligns with best practices in an environment where cybersecurity resilience is a key competitive differentiator and a fundamental expectation for publicly traded companies, especially those handling sensitive data for non-profit and social good organizations.

Comparison to Industry Standards

  • Blackbaud's cybersecurity program is built upon the National Institute of Standards and Technology (NIST) Cybersecurity Framework, a widely adopted and respected standard for managing cybersecurity risks across various industries.
  • The company maintains compliance with PCI DSS (Payment Card Industry Data Security Standard), which is essential for any entity processing credit card transactions, demonstrating adherence to critical payment security protocols.
  • Blackbaud's use of System and Organization Controls (SOC) 1 and SOC 2 reports indicates a commitment to robust internal controls over financial reporting and the security, availability, processing integrity, confidentiality, and privacy of customer data, aligning with common assurance standards for service organizations.
  • Compliance with GDPR (General Data Protection Regulation) and HIPAA (Health Insurance Portability and Accountability Act) demonstrates adherence to significant international and U.S. data privacy regulations, crucial for a company handling diverse customer data.
  • The company also aligns with the Trans-Atlantic Data Privacy Framework and Cloud Security Alliance, showcasing its commitment to evolving global data transfer mechanisms and cloud security best practices, which are increasingly vital in a cloud-first world.

Corporate Governance

Change TypeDescriptionEffective DateImpact Assessment
Policy Disclosure EnhancementInclusion of iXBRL tagging for the Company's Insider Trading Policy and Guidelines for Certain Securities Transactions, which is designed to promote compliance with insider trading laws and Nasdaq listing standards.NAEnhances transparency and accessibility of corporate governance policies for investors and regulators, reinforcing the company's commitment to ethical conduct and compliance.
Cybersecurity Oversight Structure DisclosureDetailed disclosure of a multi-level cybersecurity governance and risk management structure, including the ORCAS Committee, Risk Steering Committee, and Board's Risk Oversight Committee, with clear reporting lines and executive involvement.NAProvides greater transparency into how cybersecurity risks are managed and overseen at all levels of the organization, from operational to board level, potentially increasing investor confidence in risk management capabilities.
Internal Control CertificationsInclusion of current-dated certifications (Exhibits 31.1, 31.2, 32.1, 32.2) by the CEO and CFO regarding the effectiveness of disclosure controls and internal control over financial reporting, and compliance with Section 906 of the Sarbanes-Oxley Act.May 27, 2025Reinforces management's accountability for the accuracy and reliability of financial reporting and internal controls, which is a cornerstone of strong corporate governance.

Legal Proceedings

  • The company is currently subject to certain legal proceedings and claims as a result of a ransomware attack that occurred in May 2020.
  • There is a potential for the company to be subject to additional legal proceedings, claims, inquiries, and investigations in the future related to the Security Incident.
  • These legal matters might result in adverse judgments, settlements, fines, penalties, or other resolutions.

Stakeholder Impact

  • **Shareholders:** The amendment provides enhanced transparency regarding the company's cybersecurity risk management and corporate governance practices, which may bolster confidence in the company's operational resilience and compliance efforts. However, it also reiterates the ongoing legal risks associated with the past ransomware incident.
  • **Customers:** The detailed cybersecurity program and adherence to industry standards and privacy regulations (GDPR, HIPAA) offer reassurance regarding the protection of their data and the company's commitment to security.
  • **Employees:** The explicit mention of the Insider Trading Policy reinforces the company's commitment to ethical conduct and compliance, guiding employee behavior regarding securities transactions.
  • **Regulatory Authorities:** The filing demonstrates Blackbaud's commitment to fulfilling SEC disclosure requirements, particularly concerning critical areas like cybersecurity and corporate governance, and its efforts to comply with relevant laws and regulations.

Next Steps

  • The registrant's definitive Proxy Statement for the 2025 Annual Meeting of Stockholders is expected to be filed with the U.S. Securities and Exchange Commission no later than 120 days after the conclusion of the fiscal year ended December 31, 2024.
  • The 2025 Annual Meeting of Stockholders is currently scheduled to be held on June 11, 2025.

Key Dates

DateDescription
May 2020Ransomware attack against Blackbaud occurred.
June 28, 2024Date used for calculating the aggregate market value of common stock held by non-affiliates ($2,269,744,966 based on a closing price of $76.17).
December 31, 2024End of the fiscal year covered by the Annual Report on Form 10-K.
February 18, 2025Date for the reported number of outstanding common shares (49,236,495 shares).
February 21, 2025Original Annual Report on Form 10-K for the fiscal year ended December 31, 2024, was filed with the SEC.
May 27, 2025Signing date of this Amendment No. 1 on Form 10-K/A by the Chief Executive Officer and Chief Financial Officer.
June 11, 2025Currently scheduled date for Blackbaud's 2025 Annual Meeting of Stockholders.

Recommendation

hold

Keywords

Blackbaud, BLKB, SEC filing, 10-K/A, Annual Report Amendment, Cybersecurity, Data Security, Risk Management, Corporate Governance, Insider Trading Policy, iXBRL, Compliance, Ransomware, NIST, GDPR, HIPAA, Sarbanes-Oxley

Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.