2 unchanged sentences
Risk Management and Strategy
−Removed: We rely on information technology and data to operate our business of developing new drugs and providing contract research services.
+Added: We rely on information technology and data to operate our business of developing product candidates and providing contract research services.
Our critical information technology resources include computer networks and hardware, third party hosted services, communications systems and software, and critical data including confidential, personal, proprietary and sensitive data (collectively, “Information Assets”).
26 unchanged sentences
For a description of the risks from cybersecurity threats that may materially affect us and how they may do so, refer to “Item 1A.
−Removed: Risk factors” in this Annual Report on Form 10-K, including “If our information technology systems, those of third parties upon which we rely, or our data are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
+Added: Risk factors” in this Annual Report, including “If our information technology systems, those of third parties upon which we rely, or our data are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions;
fines and penalties;
5 unchanged sentences
The Audit Committee is responsible for overseeing the Company’s cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats.
−Removed: Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including our Chief Financial Officer who is supported by our IT department which includes personnel with over 10 years of experience overseeing and working with various cybersecurity tools.
+Added: Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including our Chief Financial Officer who is supported by our IT department which includes personnel with experience overseeing and working with various cybersecurity tools.
+Added: For example, our Senior Director of IT has over 20 years of experience in IT infrastructure and cybersecurity, with extensive expertise in security frameworks, regulatory compliance, and cloud infrastructure management.
Our cybersecurity risk management strategy relies on input from management to help us understand cybersecurity risks, establish priorities, and determine the scope and details of our cybersecurity program and to implement it.
2 unchanged sentences
Our cybersecurity incident response process involves members of management who also participate in our disclosure controls and procedures.
−Removed: Our cybersecurity incident response plan and information security incidence response procedures are designed to escalate certain cybersecurity incidents to members of management depending on the circumstances, including the Chief Financial Officer and the General Counsel.
+Added: Our cybersecurity incident response plan and information security incidence response procedures are designed to escalate certain cybersecurity incidents to members of finance and legal, depending on the circumstances, who report to the Chief Financial Officer and the General Counsel.
The Chief Financial Officer and the General Counsel work with our cybersecurity incident response team to help us mitigate and remediate cybersecurity incidents of which they are notified.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.