3 unchanged sentences
Our board of directors has overall oversight responsibility for our risk management, and delegates its oversight of risk assessment and management guidelines to the audit committee of the board of directors.
−Removed: Members of the audit committee receive annual updates from senior management regarding matters of cybersecurity.
+Added: Members of the audit committee receive periodic updates from senior management regarding matters of cybersecurity.
These discussions may include updates on management’s efforts to address and mitigate cybersecurity risks, cybersecurity incidents (if any), and the status of key information security initiatives.
Under the oversight of our Chief Executive Officer (CEO) and executive management team, we have constituted an Information Technology (IT) Steering Committee that has primary responsibility for overseeing our management of cybersecurity risks.
−Removed: The IT Steering Committee is chaired by our Executive Director and Head of Information Technology (“Head of IT”), who reports directly to our Chief Operating Officer and General Counsel.
+Added: The IT Steering Committee is chaired by our Chief Operating Officer and General Counsel, supported by an external IT consultant who operates as our Head of Information Technology (Head of IT) and an external cybersecurity firm.
Other members of the IT Steering Committee include representatives from clinical development, technical operations, finance, human resources, business operations and legal.
−Removed: Our Head of IT, working with our third-party cybersecurity firm and the IT Steering Committee, assesses and manages our cybersecurity threat management processes.
−Removed: Our Head of IT has 40 years of information technology experience, including 30 years building and leading teams in the pharmaceutical, biotechnology and chemical industries, and has worked at a variety of institutions to implement, manage, and grow the information technology function, including cybersecurity programs.
−Removed: These entities have included large, publicly-traded companies and smaller startups.
+Added: Our Head of IT , working with our third-party cybersecurity firm, Chief Operating Officer and General Counsel, and the IT Steering Committee, assesses and manages our cybersecurity threat management processes.
+Added: Our Head of IT has 34 years of information technology experience, building and leading teams in the pharmaceutical and biotechnology industries, and has worked with a variety of institutions to implement, manage, and scale the information technology function, including cybersecurity programs.
+Added: These entities have included publicly-traded companies and smaller startups.
His experience also includes developing and maintaining tools and processes to protect internal networks, research and clinical databases, and supplier payment information and financial systems.
−Removed: Under the direction of our Head of IT, we have engaged a third-party cybersecurity firm, which provides cybersecurity support services for governance and security operations.
−Removed: The IT Steering Committee meets regularly, and as circumstances warrant, to discuss and monitor prevention, detection, mitigation and remediation of risks from cybersecurity threats.
−Removed: The Head of IT provides updates to the executive management team, and, as needed, the Audit Committee, on cybersecurity developments.
−Removed: In addition, we have created an IT Security Team to review the results of our cybersecurity assessments and related cybersecurity strategies as well as emerging threats in the cybersecurity landscape.
−Removed: The IT Security Team meets regularly and includes members from our cybersecurity firm and internal IT resources.
+Added: The IT Steering Committee meets as circumstances warrant, to discuss and monitor prevention, detection, mitigation and remediation of risks from cybersecurity threats.
+Added: The Head of IT provides updates to the Chief Operating Officer and General Counsel who communicates with the executive management team, and, as needed, the Audit Committee , on cybersecurity developments.
+Added: In addition, our IT Security Team is responsible for reviewing the results of our cybersecurity assessments and related cybersecurity strategies as well as emerging threats in the cybersecurity landscape.
+Added: The IT Security Team meets regularly and includes members from our cybersecurity firm and internal IT team.
Cyber Risk Management and Strategy
−Removed: Under the guidance of the IT Steering Committee and Head of IT, we have adopted cybersecurity risk management processes that are designed to address the identification of assets potentially at risk from cybersecurity threats, identification of potential sources of cybersecurity threats, assessment of protections to address cybersecurity threats, and the management of cybersecurity risks.
−Removed: Our cybersecurity firm is responsible for monitoring our information systems and implementing procedures to mitigate cyber risks under the oversight of our Head of IT.
+Added: Under the guidance of the IT Steering Committee, Chief Operating Officer and General Counsel, and Head of IT, we have adopted cybersecurity risk management processes that are designed to address the identification of assets potentially at risk from cybersecurity threats, identification of potential sources of cybersecurity threats, assessment of protections to address cybersecurity threats, and the management of cybersecurity risks.
+Added: Under the direction of our Chief Operating Officer and General Counsel, working with our Head of IT, we have engaged a third-party cybersecurity firm, which provides cybersecurity support services for governance and security operations.
+Added: Our cybersecurity firm is responsible for monitoring our information systems and implementing procedures to mitigate cyber risks.
The cybersecurity firm keeps the Company apprised of threats in the cybersecurity landscape through various means, including through threat intelligence and research sources, discussions with industry peers, security alerts, and security conferences and events, as appropriate.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.