Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
Not applicable.
Item 1C. Cybersecurity.
We believe cybersecurity is
critical to advancing our technological developments. We face a multitude of cybersecurity threats that range from attacks common to most
industries, such as ransomware and denial-of service. Our customers, suppliers, subcontractors, and business partners face similar cybersecurity
threats, and a cybersecurity incident impacting us or any of these entities could materially adversely affect our business strategy, performance,
and results of operations. These cybersecurity threats and related risks make it imperative that we expend resources on cybersecurity.
Risk Management
We engage third-party services
to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best practices
to address new challenges. We have established cybersecurity security awareness training and ongoing monitoring.
In the event of an incident,
we intend to follow our cybersecurity incident response plan, which outlines the steps to be followed from incident detection to mitigation,
and notification. We contract with external firms that have extensive information technology and program management experience. We have
implemented a governance structure and processes to assess, identify, manage, and report cybersecurity risks. We must comply with extensive
regulations, including requirements imposed by the Federal Drug Administration related to adequately safeguarding patient information
and reporting cybersecurity incidents to the SEC. We believe we are positioned to meet the requirements of the SEC. Assessing, identifying,
and managing cybersecurity related risks are factored into our overall business approach. We rely heavily on our supply chain to deliver
our products and services, and a cybersecurity incident at a clinical site, subcontractor, or business partner could materially adversely
impact us. We require that our subcontractors report cybersecurity incidents to us so that we can assess the direct impact of the incident.
Governance
The Audit Committee has oversight
responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements, cooperation
with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations, as appropriate,
to the full board of directors for consideration. Responsible personnel regularly discusses cyber risks and trends and, should they arise,
any material incidents with the Audit Committee.
36
While we have not experienced
any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future threats
or incidents. Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a
cybersecurity incident that could have a material adverse effect on us. While we maintain cybersecurity insurance, the costs related to
cybersecurity threats or disruptions may not be fully insured. See “Risk Factors” for a discussion of cybersecurity risks.
Risk Management
We engage third-party services
to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best practices
to address new challenges. We have established cybersecurity security awareness training and ongoing monitoring.
In the event of an incident,
we intend to follow our cybersecurity incident response plan, which outlines the steps to be followed from incident detection to mitigation,
and notification. We contract with external firms that have extensive information technology and program management experience. We have
implemented a governance structure and processes to assess, identify, manage, and report cybersecurity risks. We must comply with extensive
regulations, including requirements imposed by the Federal Drug Administration related to adequately safeguarding patient information
and reporting cybersecurity incidents to the SEC. We believe we are positioned to meet the requirements of the SEC. In addition to following
SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe
enhance our ability to identify and manage cybersecurity risks. Assessing, identifying, and managing cybersecurity related risks are factored
into our overall business approach. We rely heavily on our supply chain to deliver our products and services, and a cybersecurity incident
at a clinical site, subcontractor, or business partner could materially adversely impact us. We require that our subcontractors report
cybersecurity incidents to us so that we can assess the direct impact of the incident.
Governance
The Audit Committee has oversight
responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements, cooperation
with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations, as appropriate,
to the full board of directors for consideration. Senior management regularly discusses cyber risks and trends and, should they arise,
any material incidents with the Audit Committee.
While we have not experienced
any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future threats
or incidents. Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a
cybersecurity incident that could have a material adverse effect on us. While we maintain cybersecurity insurance, the costs related to
cybersecurity threats or disruptions may not be fully insured. See “Risk Factors” for a discussion of cybersecurity risks.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.