Item 1B. Unresolved Staff Comments
Item 1B. Unresolved
Staff Comments.
Not applicable.
Item 1C. Cybersecurity.
Cybersecurity is important
to our operations and technological development efforts. We face a multitude of cybersecurity threats that range from attacks common
to most industries, such as ransomware and denial-of-service. Our customers, suppliers, subcontractors, and business partners face similar
cybersecurity threats, and a cybersecurity incident impacting us or any of these entities could materially adversely affect our business
strategy, performance, and results of operations. These cybersecurity threats and related risks make it imperative that we expend resources
on cybersecurity.
We have processes in
place for assessing, identifying, and managing material risks from potential unauthorized occurrences on or through our information systems
that could adversely affect the confidentiality, integrity, or availability of our information systems or the information residing on
those systems. These include mechanisms, controls, and processes that are designed to prevent, detect, or mitigate data loss, theft,
misuse, unauthorized access, or other security incidents or vulnerabilities affecting the data. The data includes confidential, proprietary,
and business and personal information that we collect, process, store, and transmit as part of our business, including on behalf of third
parties . We consider cybersecurity risks associated with third-party vendors and service providers as part of our overall risk management
processes and may assess such vendors’ security practices where appropriate.
We maintain a cybersecurity
risk management program operating under our Information Security & Risk Management Strategy (“ISRM”). This program is
responsible for implementing and maintaining cybersecurity and data protection practices at Aditxt in close coordination with management
and other teams across Aditxt. In addition to our in-house cybersecurity capabilities, we may engage assessors, consultants, auditors,
or other third parties to assist with assessing, identifying, and managing cybersecurity risks . Management evaluates cybersecurity risks
and associated mitigation efforts. As of the date of this report, the Company is not aware of any material risks from cybersecurity threats
that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of
operations, or financial condition. Despite the measures we take to manage cybersecurity risk, we may not be successful in preventing
or mitigating a cybersecurity incident that could have a material adverse effect on the Company or its stakeholders.
The Audit Committee
oversees the Company’s cybersecurity risk management, including oversight of the Company’s Information Security & Risk
Management Strategy (“ISRM”). The ISRM establishes a governance framework for cybersecurity oversight and designates an ISRM
Leadership Group responsible for implementing and maintaining the Company’s cybersecurity and data protection practices. Management
reports to the Audit Committee regarding cybersecurity risks and significant cybersecurity incidents.
38
Risk
Management
We evaluate our security
controls through internal assessments and may engage third-party services to support penetration testing, independent reviews, or consulting
on best practices. We have established cybersecurity awareness training and ongoing monitoring.
In the event of a cybersecurity
incident, we follow established procedures to respond to and mitigate its impact, including coordination among internal personnel, use
of external service providers where appropriate, and implementation of disaster recovery procedures. We may engage external firms with
information technology and program management experience to assist in evaluating or managing cybersecurity risks. We have implemented
a governance structure and processes to assess, identify, manage, and report cybersecurity risks. We must comply with extensive regulations,
including requirements imposed by the U.S. Food and Drug Administration, laws governing the protection of patient information, and SEC
requirements related to cybersecurity incident disclosure. Assessing, identifying, and managing cybersecurity-related risks are factored
into our overall business approach. We rely heavily on our supply chain to deliver our products and services, and a cybersecurity incident
at a clinical site, subcontractor, or business partner could materially adversely impact us. We expect our subcontractors to report cybersecurity
incidents to us so that we can assess the potential impact.
Governance
The Audit Committee
has oversight responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure requirements,
cooperation with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations,
as appropriate, to the full board of directors for consideration . Management provides periodic reports to the Audit Committee regarding
cybersecurity risks and trends and any material cybersecurity incidents.
While we have not experienced
any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be the subject of future
threats or incidents. Despite the measures we take to manage cybersecurity risk, we may not be successful in preventing or mitigating
a cybersecurity incident that could have a material adverse effect on us. While we maintain cybersecurity insurance, the costs related
to cybersecurity threats or disruptions may not be fully insured. See “Risk Factors” for a discussion of cybersecurity risks.