2 unchanged sentences
Risk management and strategy
−Removed: We take a risk-based approach in implementing and maintaining various information security processes designed to identify, assess and manage material risks from cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, and information related to our clinical trials, products in development, and proprietary technologies (“Information Systems and Data”).
+Added: We take a risk-based approach in implementing and maintaining various information security processes designed to identify, assess and manage material risks from threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, and information related to our clinical trials, products in development, and proprietary technologies (“Information Systems and Data”).
Our information security function, supported by members of our IT and Legal departments and our third-party IT service providers, helps identify, assess and manage the Company’s cybersecurity threats and risks.
18 unchanged sentences
(2) the information security function works with senior management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business;
−Removed: (3) our senior management evaluates material risks from cybersecurity threats against our overall business objectives and reports to the audit committee of the board of directors, which evaluates our overall enterprise risk, (4) policies and procedures to manage how Information Systems and Data are collected, maintained and stored, (5) communicating with and training personnel on cybersecurity risks and trends.
+Added: (3) our senior management evaluates material risks from cybersecurity threats against our overall business objectives and reports to the audit committee of the board of directors on at least a quarterly basis, which evaluates our overall enterprise risk, (4) policies and procedures to manage how Information Systems and Data are collected, maintained and stored, (5) communicating with and training personnel on cybersecurity risks and trends.
We use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example:
professional services firms, cybersecurity consultants, cybersecurity software providers, managed cybersecurity service providers, and penetration testing firms.
+Added: We conduct penetration tests and audits of our Information Systems and Data environment with an external cybersecurity firm at least annually.
We use third-party service providers to perform a variety of functions throughout our business, such as application providers, contract research organizations (CROs), contract development and manufacturing organizations (CDMOs) and supply chain resources.
5 unchanged sentences
Our board of directors addresses the Company’s cybersecurity risk management as part of its general oversight function.
−Removed: The board of directors’ audit committee is responsible for overseeing Company’s cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats.
−Removed: Members of the Audit Committee receive scheduled updates from senior management.
−Removed: Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including our Director of IT Security and Executive Director/Head of IT.
+Added: The board of directors’ audit committee is responsible for overseeing Company’s cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats.
+Added: Members of the Audit Committee receive scheduled quarterly updates from senior management.
+Added: Our cybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including our Director of IT Security and Vice President of IT .
Our Director of IT Security has over 13 years of experience leading IT security and has certifications including CISSP and CCSP.
−Removed: Our Executive Director IT Data Management, Analytics and Integration has over 20 years of experience in IT, data engineering, and data analytics.
−Removed: Our Director of IT Security is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s overall IT risk management strategy, communicating key priorities to relevant personnel, overseeing cybersecurity operations, and managing the cybersecurity technologies, processes, and projects.
−Removed: Our Executive Director of IT Data Management, Analytics and Integration is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and conducting regular reviews of security assessments and other security-related reports.
−Removed: Our cybersecurity incident response and vulnerability management policies are designed to escalate certain cybersecurity incidents to members of management depending on the circumstances, including Director of IT Security, Data Management, Analytics and Integration, and General Counsel.
−Removed: Director of IT Security, Data Management, Analytics and Integration, and General Counsel work with the Company’s cross functional incident response team to help the Company mitigate and remediate cybersecurity incidents of which they are notified.
+Added: Our Vice President IT has over 20 years of experience in IT, data engineering, and data analytics.
+Added: Our Vice President of IT Security is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s overall IT risk management strategy, communicating key priorities to relevant personnel, overseeing cybersecurity operations, and managing the cybersecurity technologies, processes, and projects.
+Added: Our Vice President of IT is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and conducting regular reviews of security assessments and other security-related reports.
+Added: Our cybersecurity incident response and vulnerability management policies are designed to escalate certain cybersecurity incidents to members of management depending on the circumstances, including the Vice President of IT and General Counsel.
+Added: The Vice President of IT and General Counsel work with the Company’s cross functional incident response team to help the Company mitigate and remediate cybersecurity incidents of which they are notified.
In addition, the Company’s incident response and vulnerability management policies and procedures include reporting to the audit committee of the board of directors for certain cybersecurity incidents.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.