CGTX · All filings · Read this filing
What changed 10-K
Item 1B. Unresolved Staff Comments
2025-03-20 compared with 2024-03-26 · 3 added, 0 removed, 19 unchanged (14% of the section changed)
7 unchanged sentences
We also maintain processes to assess and review the cybersecurity practices of third-party vendors and service providers prior to onboarding, including through review of System and Organization Controls (SOC) reports provided by potential vendors and inclusion of security requirements in contracts, as appropriate.
+Added: Employees are required to complete an annual cybersecurity awareness training program designed to raise awareness of cybersecurity threats across functions, as well as to encourage consideration of cybersecurity risks across our Company.
+Added: As part of our cybersecurity risk management, we have adopted an incident response plan that has been designed to identify and manage significant events that may impact our information technology infrastructure, including those arising from or related to cybersecurity threats.
+Added: We recently tested our incident response plan using a tabletop exercise with the goal of improving our processes and preparedness.
We, like other companies in our industry, face a number of risks from cybersecurity threats in connection with our business.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.