2 unchanged sentences
maintain a cyber risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
−Removed: underlying processes and controls of the bioAffinity cyber risk management program incorporate recognized best practices and standards
−Removed: for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity
−Removed: Framework (“CSF”).
−Removed: addition, bioAffinity maintains policies over areas, such as information security, access on/offboarding, and access and account management,
−Removed: to help govern the processes put in place by management designed to protect bioAffinity IT assets, data, and services from threats and
−Removed: vulnerabilities.
−Removed: bioAffinity partners with industry-recognized cybersecurity providers leveraging third-party technology and expertise.
−Removed: These cybersecurity partners, including consultants and other third-party service providers , are a key part of bioAffinity’s cybersecurity
−Removed: risk management strategy and infrastructure and provide services including maintenance of an IT assets inventory, periodic vulnerability
−Removed: scanning, identity access management controls including restricted access to privileged accounts, network integrity safeguarded by web-based
−Removed: software, including endpoint protection, endpoint detection and response, and remote monitoring management on all devices, industry-standard
−Removed: encryption protocols, critical data backups, infrastructure maintenance, incident response, cybersecurity strategy, and cyber risk advisory,
−Removed: assessment and remediation.
−Removed: bioAffinity’s
+Added: underlying processes and controls of our cyber risk management program incorporate recognized best practices and standards for cybersecurity
+Added: and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework
+Added: addition, we maintain policies over areas, such as information security, access on/offboarding, and access and account management, to
+Added: help govern the processes put in place by management designed to protect our IT assets, data, and services from threats and vulnerabilities.
+Added: We partner with industry-recognized cybersecurity providers leveraging third-party technology and expertise.
+Added: These cybersecurity partners,
+Added: including consultants and other third-party service providers , are a key part of our cybersecurity risk management strategy and infrastructure
+Added: and provide services including maintenance of an IT assets inventory, periodic vulnerability scanning, identity access management controls
+Added: including restricted access to privileged accounts, network integrity safeguarded by web-based software, including endpoint protection,
+Added: endpoint detection and response, and remote monitoring management on all devices, industry-standard encryption protocols, critical data
+Added: backups, infrastructure maintenance, incident response, cybersecurity strategy, and cyber risk advisory, assessment and remediation.
management team, in conjunction with third-party IT and cybersecurity service providers, is responsible for oversight and administration
4 unchanged sentences
public, or private sources.
−Removed: Audit Committee of the Board of Directors oversees bioAffinity cybersecurity risk exposures and the steps taken by management to monitor
−Removed: and mitigate cybersecurity risks .
+Added: Audit Committee of the Board of Directors oversees our cybersecurity risk exposures and the steps taken by management to monitor and
+Added: mitigate cybersecurity risks .
The cybersecurity stakeholders, including member(s) of management assigned with cybersecurity oversight
2 unchanged sentences
cyber risks on at least an annual basis.
−Removed: This includes updates on bioAffinity processes to prevent, detect, and mitigate cybersecurity
−Removed: In addition, cybersecurity risks are reviewed by our Board of Directors at least annually, as part of the Company’s
−Removed: corporate risk oversight processes.
−Removed: faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations,
+Added: This includes updates on our processes to prevent, detect, and mitigate cybersecurity incidents.
+Added: In addition, cybersecurity risks are reviewed by our Board of Directors at least annually, as part of the Company’s corporate risk
+Added: oversight processes.
+Added: face risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations,
cash flows, or reputation.
−Removed: bioAffinity acknowledges that the risk of cyber incident is prevalent in the current threat landscape and
−Removed: that a future cyber incident may occur in the normal course of its business.
−Removed: However, prior cybersecurity incidents have not had a material
−Removed: adverse effect on our business, financial condition, results of operations, or cash flows.
−Removed: The Company proactively seeks to detect and
−Removed: investigate unauthorized attempts and attacks against our IT assets, data, and services, and to prevent their occurrence and recurrence
−Removed: where practicable through changes or updates to internal processes and tools and changes or updates to service delivery;
−Removed: however, potential
−Removed: vulnerabilities to known or unknown threats will remain.
−Removed: Further, there is increasing regulation regarding responses to cybersecurity
−Removed: incidents, including reporting to regulators, investors, and additional stakeholders, which could subject the Company to additional liability
−Removed: and reputational harm.
−Removed: In response to such risks, the Company has implemented initiatives such as implementation of the cybersecurity
−Removed: risk assessment process and development of an incident response plan.
+Added: We acknowledge that the risk of cyber incident is prevalent in the current threat landscape and that a future
+Added: cyber incident may occur in the normal course of our business.
+Added: However, prior cybersecurity incidents have not had a material adverse
+Added: effect on our business, financial condition, results of operations, or cash flows.
+Added: We proactively seek to detect and investigate unauthorized
+Added: attempts and attacks against our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through
+Added: changes or updates to internal processes and tools and changes or updates to service delivery;
+Added: however, potential vulnerabilities to
+Added: known or unknown threats will remain.
+Added: Further, there is increasing regulation regarding responses to cybersecurity incidents, including
+Added: reporting to regulators, investors, and additional stakeholders, which could subject us to additional liability and reputational harm.
+Added: In response to such risks, we have implemented initiatives such as implementation of the cybersecurity risk assessment process and development
+Added: of an incident response plan.
For more information on cybersecurity risks see Item 1A.
−Removed: Factors – Our internal information technology systems, or those of our third-party clinical research organizations or other contractors
−Removed: or consultants, may fail or suffer security breaches, loss or leakage of data, and other disruptions, which could result in a material
−Removed: disruption of our diagnostic tests’ or therapeutic product candidates’ development programs, compromise sensitive information
−Removed: related to our business, or prevent us from accessing critical information, potentially exposing us to liability or otherwise adversely
−Removed: affecting our business.”
+Added: “Risk Factors – Our internal information
+Added: technology systems, or those of our third-party clinical research organizations or other contractors or consultants, may fail or suffer
+Added: security breaches, loss or leakage of data, and other disruptions, which could result in a material disruption of our diagnostic tests’
+Added: or therapeutic product candidates’ development programs, compromise sensitive information related to our business, or prevent us
+Added: from accessing critical information, potentially exposing us to liability or otherwise adversely affecting our business.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.