7 unchanged sentences
Risk Management and Strategy
−Removed: We have recently implemented additional security
−Removed: measures as part of an evolving cybersecurity posture and will continue to devote resources to address security vulnerabilities in an
−Removed: effort to prevent cyberattacks and mitigate the damage that could result from such an attack.
−Removed: All employees have recently begun receiving
−Removed: cybersecurity training and other education regarding their use of computers, information technology, and sensitive data including specifically
−Removed: how to recognize common attack strategies .
−Removed: As the Company does not have a physical office location, it does not have a local network or
−Removed: in-house servers and proprietary applications.
−Removed: We therefore utilize third parties applications and resources to support our information
−Removed: technology (“IT”) needs.
+Added: We have implemented additional security measures
+Added: as part of an evolving cybersecurity posture and will continue to devote resources to address security vulnerabilities in an effort to
+Added: prevent cyberattacks and mitigate the damage that could result from such an attack.
+Added: All employees have recently begun receiving cybersecurity
+Added: training and other education regarding their use of computers, information technology, and sensitive data including specifically how to
+Added: recognize common attack strategies.
+Added: As the Company does not have a physical office location, it does not have a local network or in-house
+Added: servers and proprietary applications.
+Added: We therefore utilize third parties applications and resources to support our information technology
+Added: (“IT”) needs.
All applications utilized by the Company are Software as a Service (“SaaS”) offerings.
−Removed: As our applications are developed and managed by third parties, we are dependent on these providers for many functions including disaster
−Removed: recovery during a disaster or cyber incident.
+Added: As our applications
+Added: are developed and managed by third parties, we are dependent on these providers for many functions including disaster recovery during
+Added: a disaster or cyber incident.
Our goal is to only utilize the most secure and trusted providers for our IT needs.
−Removed: business continuity plans are evaluated against evolving security and service level standards, which includes evaluating those cybersecurity
−Removed: threats associated with our use of key third party service providers.
+Added: Our business continuity
+Added: plans are evaluated against evolving security and service level standards, which includes evaluating those cybersecurity threats associated
+Added: with our use of key third party service providers.
Our cybersecurity management strategy consists
23 unchanged sentences
For our largest third-party provider,
−Removed: our Contract Research Organization (“CRO”) which is helping us manage our global trial of Berubicin, we
−Removed: are currently conducting a security assessment and review including their cybersecurity practices, protocols and protections, handling
−Removed: of information protected by HIPAA, and physical security.
−Removed: Board of Directors is responsible for oversight of cybersecurity risk.
−Removed: Financial Officer and Chief Executive Officer are the members of management responsible for managing and assessing our
−Removed: cybersecurity practices and have recently commenced reporting on such practices and risks.
−Removed: The plan for the future is that
−Removed: they will continue to report to the Board on cybersecurity at least quarterly.
−Removed: Should any cybersecurity threat or incident be
−Removed: detected, our senior management team would timely report such threat or incident to the Board of Directors and provide regular
−Removed: communications and updates throughout the incident and any subsequent investigation, in order that the impact, materiality, and
−Removed: reporting requirements of such incident are appropriately identified and assessed for further necessary or appropriate action to be
+Added: our Contract Research Organization (“CRO”) which is helping us manage our global trial of Berubicin, we are currently conducting
+Added: a security assessment and review including their cybersecurity practices, protocols and protections, handling of information protected
+Added: by HIPAA, and physical security.
+Added: The Board of Directors is responsible for oversight
+Added: of cybersecurity risk.
+Added: Our Chief Financial Officer and Chief Executive Officer are the members of management responsible for managing
+Added: and assessing our cybersecurity practices and have recently commenced reporting on such practices and risks.
+Added: The plan for the future is
+Added: that they will continue to report to the Board on cybersecurity at least quarterly.
+Added: Should any cybersecurity threat or incident be detected,
+Added: our senior management team would timely report such threat or incident to the Board of Directors and provide regular communications and
+Added: updates throughout the incident and any subsequent investigation, in order that the impact, materiality, and reporting requirements of
+Added: such incident are appropriately identified and assessed for further necessary or appropriate action to be taken.
We believe we are appropriately staffed (as supported
by our outsourced IT provider) to support a healthy cybersecurity posture given our size and scope.
−Removed: Our Chief Financial Officer , who reports
−Removed: to the Chief Executive Officer, is directly responsible for IT functions and has earned a Master of Business Administration and also a
−Removed: Master of Science degree in Accounting with a Management Information Systems concentration.
−Removed: To date, there have been no risks identified from
−Removed: cybersecurity threats or previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect
−Removed: However, despite all of the above aforementioned efforts, a cyberattack, if it occurred, could cause system operational problems,
−Removed: disrupt service to clinical trial sites, compromise important data or systems or result in an unintended release of confidential information.
+Added: To date, there have been no risks
+Added: identified from cybersecurity threats or previous cybersecurity incidents that have materially affected or are reasonably likely to materially
+Added: affect the company.
+Added: However, despite all of the above aforementioned efforts, a cyberattack, if it occurred, could cause system operational
+Added: problems, disrupt service to clinical trial sites, compromise important data or systems or result in an unintended release of confidential
See “Item 1A.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.