6 unchanged sentences
We have implemented and utilize a risk-based approach that incorporates various information security processes designed to assess, identify and manage risks from potential unauthorized occurrences on or through our information technology systems that may result in adverse effects on the confidentiality, integrity and availability of information technology systems and the data residing therein.
−Removed: The critical data contained on our information systems include intellectual property, confidential
−Removed: information that is proprietary, strategic or competitive in nature, and sensitive, personal information that we collect, use, store and transmit digitally in the ordinary course of our business.
+Added: The critical data contained on our information systems include intellectual property, confidential information that is proprietary, strategic or competitive in nature, and sensitive, personal information that we collect, use, store and transmit digitally in the ordinary course of our business.
These processes are managed and monitored by a dedicated information technology team, which is led by our Senior Vice President of Information Technology, and include mechanisms, controls, technologies, systems, and other processes designed to monitor and evaluate our threat environment, prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable information technology environment.
10 unchanged sentences
In the last fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us , but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect us.
−Removed: Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors,” under the heading “Our internal information technology systems, or those of any of our CROs, manufacturers, other contractors or consultants, third party service providers, or potential future collaborators, may fail or suffer security or data privacy breaches or other unauthorized or improper access to, use of, or destruction of our proprietary or confidential data, employee data or personal data, which could result in additional costs, loss of revenue, significant liabilities, harm to our brand and material disruption of our operations.”
+Added: Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors,” under the heading “Our internal information technology systems, or those of any of our CROs, manufacturers, other contractors or consultants, third party service providers, or potential future collaborators, may fail or suffer security or data privacy breaches or other unauthorized or improper access to, use of,
+Added: or destruction of our proprietary or confidential data, employee data or personal data, which could result in additional costs, loss of revenue, significant liabilities, harm to our brand and material disruption of our operations.”
Our Senior Vice President of Information Technology, a certified CISSP, who reports directly to the Chief Financial Officer and has over twenty years of experience managing information technology and cybersecurity, is responsible for assessing and managing cybersecurity risks .
1 unchanged sentence
The Board of Directors, as a whole and at the committee level, has oversight for the most significant risks facing us and for our processes to identify, prioritize, assess, manage, and mitigate those risks.
−Removed: The Audit Committee, which is comprised solely of independent directors, has been designated by our Board to oversee cybersecurity risks.
+Added: The Audit Committee, which comprises solely independent directors, has been designated by our Board to oversee cybersecurity risks .
The Audit Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our Senior Vice President of Information Technology .
The Board also receives updates from management and the Audit Committee on cybersecurity risks on at least an annual basis.
+Added: We maintain a corporate headquarters in Waltham, Massachusetts, laboratory and office space in Boston, Massachusetts, office space in San Francisco, California and otherwise operate virtually in the United States.
+Added: Our corporate headquarters in Waltham, Massachusetts, consists of 1,087 square feet of leased office space under a lease agreement that expires in September 2025.
+Added: We also lease a laboratory facility located in Boston, Massachusetts, which consists of 17,685 square feet of R&D laboratories and office space under a lease agreement that expires in November 2026, with the option to extend for one year.
+Added: In September 2024, the Company entered into a lease agreement for 15,710 square feet of office space in San Francisco, California.
+Added: The lease expires in September 2029 with two one-year options to extend.
+Added: We believe these arrangements support our current needs.
+Added: If we require additional space, we believe that we will be able to obtain such space on acceptable, commercially reasonable terms.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.