−Removed: Unresolved Staff Comments.
+Added: Staff Comments.
Not applicable.
Cybersecurity.
−Removed: We believe cybersecurity is
−Removed: critical to advancing our technological developments.
−Removed: We face a multitude of cybersecurity threats that range from attacks common to most
−Removed: industries, such as ransomware and denial-of service.
−Removed: Our customers, suppliers, subcontractors, and business partners face similar cybersecurity
−Removed: threats, and a cybersecurity incident impacting us or any of these entities could materially adversely affect our business strategy, performance,
−Removed: and results of operations.
−Removed: These cybersecurity threats and related risks make it imperative that we expend resources on cybersecurity.
−Removed: Risk Management
−Removed: We engage third-party services
−Removed: to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best practices
−Removed: to address new challenges.
−Removed: We have established cybersecurity security awareness training and ongoing monitoring.
−Removed: In the event of an incident,
−Removed: we intend to follow our cybersecurity incident response plan, which outlines the steps to be followed from incident detection to mitigation,
−Removed: and notification.
−Removed: We contract with external firms that have extensive information technology and program management experience.
−Removed: implemented a governance structure and processes to assess, identify, manage, and report cybersecurity risks.
−Removed: We must comply with extensive
−Removed: regulations, including requirements imposed by the Federal Drug Administration related to adequately safeguarding patient information
−Removed: and reporting cybersecurity incidents to the SEC.
−Removed: We believe we are positioned to meet the requirements of the SEC.
−Removed: Assessing, identifying,
−Removed: and managing cybersecurity related risks are factored into our overall business approach.
−Removed: We rely heavily on our supply chain to deliver
−Removed: our products and services, and a cybersecurity incident at a clinical site, subcontractor, or business partner could materially adversely
−Removed: We require that our subcontractors report cybersecurity incidents to us so that we can assess the direct impact of the incident.
−Removed: The Audit Committee has oversight
−Removed: responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements, cooperation
−Removed: with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations, as appropriate,
−Removed: to the full board of directors for consideration.
−Removed: Responsible personnel regularly discusses cyber risks and trends and, should they arise,
−Removed: any material incidents with the Audit Committee.
−Removed: While we have not experienced
−Removed: any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future threats
−Removed: or incidents.
−Removed: Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a
−Removed: cybersecurity incident that could have a material adverse effect on us.
−Removed: While we maintain cybersecurity insurance, the costs related to
−Removed: cybersecurity threats or disruptions may not be fully insured.
−Removed: See “Risk Factors” for a discussion of cybersecurity risks.
−Removed: Risk Management
−Removed: We engage third-party services
−Removed: to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best practices
−Removed: to address new challenges.
−Removed: We have established cybersecurity security awareness training and ongoing monitoring.
−Removed: In the event of an incident,
−Removed: we intend to follow our cybersecurity incident response plan, which outlines the steps to be followed from incident detection to mitigation,
−Removed: and notification.
−Removed: We contract with external firms that have extensive information technology and program management experience.
−Removed: implemented a governance structure and processes to assess, identify, manage, and report cybersecurity risks.
−Removed: We must comply with extensive
−Removed: regulations, including requirements imposed by the Federal Drug Administration related to adequately safeguarding patient information
−Removed: and reporting cybersecurity incidents to the SEC.
−Removed: We believe we are positioned to meet the requirements of the SEC.
−Removed: In addition to following
−Removed: SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe
−Removed: enhance our ability to identify and manage cybersecurity risks.
+Added: Cybersecurity is important
+Added: to our operations and technological development efforts.
+Added: We face a multitude of cybersecurity threats that range from attacks common
+Added: to most industries, such as ransomware and denial-of-service.
+Added: Our customers, suppliers, subcontractors, and business partners face similar
+Added: cybersecurity threats, and a cybersecurity incident impacting us or any of these entities could materially adversely affect our business
+Added: strategy, performance, and results of operations.
+Added: These cybersecurity threats and related risks make it imperative that we expend resources
+Added: on cybersecurity.
+Added: We have processes in
+Added: place for assessing, identifying, and managing material risks from potential unauthorized occurrences on or through our information systems
+Added: that could adversely affect the confidentiality, integrity, or availability of our information systems or the information residing on
+Added: those systems.
+Added: These include mechanisms, controls, and processes that are designed to prevent, detect, or mitigate data loss, theft,
+Added: misuse, unauthorized access, or other security incidents or vulnerabilities affecting the data.
+Added: The data includes confidential, proprietary,
+Added: and business and personal information that we collect, process, store, and transmit as part of our business, including on behalf of third
+Added: We consider cybersecurity risks associated with third-party vendors and service providers as part of our overall risk management
+Added: processes and may assess such vendors’ security practices where appropriate.
+Added: We maintain a cybersecurity
+Added: risk management program operating under our Information Security & Risk Management Strategy (“ISRM”).
+Added: This program is
+Added: responsible for implementing and maintaining cybersecurity and data protection practices at Aditxt in close coordination with management
+Added: and other teams across Aditxt.
+Added: In addition to our in-house cybersecurity capabilities, we may engage assessors, consultants, auditors,
+Added: or other third parties to assist with assessing, identifying, and managing cybersecurity risks .
+Added: Management evaluates cybersecurity risks
+Added: and associated mitigation efforts.
+Added: As of the date of this report, the Company is not aware of any material risks from cybersecurity threats
+Added: that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of
+Added: operations, or financial condition.
+Added: Despite the measures we take to manage cybersecurity risk, we may not be successful in preventing
+Added: or mitigating a cybersecurity incident that could have a material adverse effect on the Company or its stakeholders.
+Added: The Audit Committee
+Added: oversees the Company’s cybersecurity risk management, including oversight of the Company’s Information Security & Risk
+Added: Management Strategy (“ISRM”).
+Added: The ISRM establishes a governance framework for cybersecurity oversight and designates an ISRM
+Added: Leadership Group responsible for implementing and maintaining the Company’s cybersecurity and data protection practices.
+Added: reports to the Audit Committee regarding cybersecurity risks and significant cybersecurity incidents.
+Added: We evaluate our security
+Added: controls through internal assessments and may engage third-party services to support penetration testing, independent reviews, or consulting
+Added: on best practices.
+Added: We have established cybersecurity awareness training and ongoing monitoring.
+Added: In the event of a cybersecurity
+Added: incident, we follow established procedures to respond to and mitigate its impact, including coordination among internal personnel, use
+Added: of external service providers where appropriate, and implementation of disaster recovery procedures.
+Added: We may engage external firms with
+Added: information technology and program management experience to assist in evaluating or managing cybersecurity risks.
+Added: We have implemented
+Added: a governance structure and processes to assess, identify, manage, and report cybersecurity risks.
+Added: We must comply with extensive regulations,
+Added: including requirements imposed by the U.S.
+Added: Food and Drug Administration, laws governing the protection of patient information, and SEC
+Added: requirements related to cybersecurity incident disclosure.
Assessing, identifying, and managing cybersecurity-related risks are factored
2 unchanged sentences
at a clinical site, subcontractor, or business partner could materially adversely impact us.
−Removed: We require that our subcontractors report
−Removed: cybersecurity incidents to us so that we can assess the direct impact of the incident.
−Removed: The Audit Committee has oversight
−Removed: responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements, cooperation
−Removed: with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations, as appropriate,
−Removed: to the full board of directors for consideration.
−Removed: Senior management regularly discusses cyber risks and trends and, should they arise,
−Removed: any material incidents with the Audit Committee.
+Added: We expect our subcontractors to report cybersecurity
+Added: incidents to us so that we can assess the potential impact.
+Added: The Audit Committee
+Added: has oversight responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements,
+Added: cooperation with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations,
+Added: as appropriate, to the full board of directors for consideration .
+Added: Management provides periodic reports to the Audit Committee regarding
+Added: cybersecurity risks and trends and any material cybersecurity incidents.
While we have not experienced
−Removed: any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future threats
−Removed: or incidents.
−Removed: Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a
−Removed: cybersecurity incident that could have a material adverse effect on us.
−Removed: While we maintain cybersecurity insurance, the costs related to
−Removed: cybersecurity threats or disruptions may not be fully insured.
+Added: any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future
+Added: threats or incidents.
+Added: Despite the measures we take to manage cybersecurity risk, we may not be successful in preventing or mitigating
+Added: a cybersecurity incident that could have a material adverse effect on us.
+Added: While we maintain cybersecurity insurance, the costs related
+Added: to cybersecurity threats or disruptions may not be fully insured.
See “Risk Factors” for a discussion of cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.