10 unchanged sentences
effort to prevent cyberattacks and mitigate the damage that could result from such an attack.
−Removed: All employees have recently (subsequent
−Removed: to December 31, 2023) begun receiving cybersecurity training and other education regarding their use of computers, information technology,
−Removed: and sensitive data including specifically how to recognize common attack strategies.
−Removed: As the Company does not have a physical office location,
−Removed: it does not have a local network or in-house servers and proprietary applications.
−Removed: We therefore utilize third parties applications and
−Removed: resources to support our information technology (“IT”) needs.
−Removed: All applications utilized by the Company are Software as a Service
−Removed: (“SaaS”) offerings.
−Removed: As our applications are developed and managed by third parties, we are dependent on these providers for
−Removed: many functions including disaster recovery during a disaster or cyber incident.
−Removed: Our goal is to only utilize the most secure and trusted
−Removed: providers for our IT needs.
−Removed: To this end, we are currently reviewing the security credentials and certifications of our key application
−Removed: Our business continuity plans are evaluated against evolving security and service level standards, which includes evaluating
−Removed: those cybersecurity threats associated with our use of key third party service providers.
+Added: All employees have recently begun receiving
+Added: cybersecurity training and other education regarding their use of computers, information technology, and sensitive data including specifically
+Added: how to recognize common attack strategies .
+Added: As the Company does not have a physical office location, it does not have a local network or
+Added: in-house servers and proprietary applications.
+Added: We therefore utilize third parties applications and resources to support our information
+Added: technology (“IT”) needs.
+Added: All applications utilized by the Company are Software as a Service (“SaaS”) offerings.
+Added: As our applications are developed and managed by third parties, we are dependent on these providers for many functions including disaster
+Added: recovery during a disaster or cyber incident.
+Added: Our goal is to only utilize the most secure and trusted providers for our IT needs.
+Added: business continuity plans are evaluated against evolving security and service level standards, which includes evaluating those cybersecurity
+Added: threats associated with our use of key third party service providers.
Our cybersecurity management strategy consists
2 unchanged sentences
endpoint detection and response, firewalls, security information and event management, email security, multifactor authentication, and
−Removed: vulnerability management, with deployment of these tools completed subsequent to December 31, 2023.
−Removed: As part of the service offering from
−Removed: out outsourced IT security services provider, cybersecurity related alerts will be issued to us as relevant situations develop.
−Removed: alerts will be evaluated in concert with our IT provider and in the event an alert requires action within our environment, such actions
−Removed: will be taken promptly.
−Removed: Our process and cybersecurity posture will continue to be refined based on the results of periodic cybersecurity
−Removed: assessments conducted jointly with our IT provider.
−Removed: We have recently begun reporting on cybersecurity in reports to the Board of Directors
−Removed: and will continue to do so.
−Removed: To operate our business, we rely upon certain
−Removed: third-party service providers to perform a variety of functions, such as outsourced business critical functions,
−Removed: clinical research, professional services, SaaS platforms, managed services, cloud-based infrastructure, content delivery,
−Removed: encryption and authentication technology, corporate productivity services, and other functions.
−Removed: We are developing certain vendor
−Removed: management processes designed to help to manage cybersecurity risks associated with our use of certain of these providers.
−Removed: on the nature of the services provided, the sensitivity and quantity of information processed, and the identity of the service
−Removed: provider, our vendor management process may include reviewing the cybersecurity practices of such provider, contractually imposing
−Removed: obligations on the provider related to the services they provide and/or the information they process, conducting security
−Removed: assessments, conducting on-site inspections, requiring their completion of written questionnaires regarding their services and data
−Removed: handling practices, and conducting periodic re-assessments during their engagement.
−Removed: For our largest third-party provider, our
−Removed: Contract Research Organization (“CRO”) which is helping us manage our potentially pivotal global trial of Berubicin, we
−Removed: are currently conducting a comprehensive security assessment and review including their cybersecurity practices, protocols and
−Removed: protections, handling of information protected by HIPAA, and physical security.
−Removed: The Board of Directors is responsible for oversight
−Removed: of cybersecurity risk.
−Removed: Our Chief Financial Officer and Chief Executive Officer are the members of management responsible for managing
−Removed: and assessing our cybersecurity practices and have recently (subsequent to December 31, 2023) commenced reporting on such practices and
−Removed: The plan for the future is that they will continue to report to the Board on cybersecurity at least quarterly.
−Removed: Should any cybersecurity
−Removed: threat or incident be detected, our senior management team would timely report such threat or incident to the Board of Directors and provide
−Removed: regular communications and updates throughout the incident and any subsequent investigation, in order that the impact, materiality, and
−Removed: reporting requirements of such incident are appropriately identified and assessed for further necessary or appropriate action to be taken.
+Added: vulnerability management.
+Added: As part of the service offering from our outsourced IT security services provider, cybersecurity related alerts
+Added: will be issued to us as relevant situations develop.
+Added: These alerts will be evaluated in concert with our IT provider and in the event an
+Added: alert requires action within our environment, such actions will be taken promptly.
+Added: Our process and cybersecurity posture will continue
+Added: to be refined based on the results of periodic cybersecurity assessments conducted jointly with our IT provider.
+Added: We have recently begun
+Added: reporting on cybersecurity in reports to the Board of Directors and will continue to do so.
+Added: To operate our business, we rely upon certain third-party
+Added: service providers to perform a variety of functions, such as outsourced business critical functions, clinical research, professional services,
+Added: SaaS platforms, managed services, cloud-based infrastructure, content delivery, encryption and authentication technology, corporate productivity
+Added: services, and other functions.
+Added: We are developing certain vendor management processes designed to help to manage cybersecurity risks associated
+Added: with our use of certain of these providers.
+Added: Depending on the nature of the services provided, the sensitivity and quantity of information
+Added: processed, and the identity of the service provider, our vendor management process may include reviewing the cybersecurity practices of
+Added: such provider, contractually imposing obligations on the provider related to the services they provide and/or the information they process,
+Added: conducting security assessments, conducting on-site inspections, requiring their completion of written questionnaires regarding their
+Added: services and data handling practices, and conducting periodic re-assessments during their engagement.
+Added: For our largest third-party provider,
+Added: our Contract Research Organization (“CRO”) which is helping us manage our global trial of Berubicin, we
+Added: are currently conducting a security assessment and review including their cybersecurity practices, protocols and protections, handling
+Added: of information protected by HIPAA, and physical security.
+Added: Board of Directors is responsible for oversight of cybersecurity risk.
+Added: Financial Officer and Chief Executive Officer are the members of management responsible for managing and assessing our
+Added: cybersecurity practices and have recently commenced reporting on such practices and risks.
+Added: The plan for the future is that
+Added: they will continue to report to the Board on cybersecurity at least quarterly.
+Added: Should any cybersecurity threat or incident be
+Added: detected, our senior management team would timely report such threat or incident to the Board of Directors and provide regular
+Added: communications and updates throughout the incident and any subsequent investigation, in order that the impact, materiality, and
+Added: reporting requirements of such incident are appropriately identified and assessed for further necessary or appropriate action to be
We believe we are appropriately staffed (as supported
15 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.