5 unchanged sentences
of third-party service providers.
−Removed: In addition, the Company leverages the security and monitoring tools of third-party service providers.
−Removed: These processes are integrated into the Company’s overall risk management program and systems, as overseen by the Board, primarily
−Removed: through the Audit Committee.
−Removed: We maintain physical, technical
−Removed: and administrative safeguards to prevent and identify cybersecurity risks, and have implemented practices and procedures to address cybersecurity
+Added: These processes are integrated into the Company’s overall risk management program and systems,
+Added: as overseen on a day-to-day basis by the Company’s Senior Manager, IT.
+Added: We maintain a formal data
+Added: protection program consistent with the National Institute of Standards and Technology Cybersecurity Framework, including physical,
+Added: technical and administrative safeguards to prevent and identify cybersecurity risks, and have implemented practices and procedures to
+Added: address cybersecurity risks.
To this end, among other things, we:
−Removed: annual mandatory training for our employees regarding cybersecurity threats as a means to equip them with effective tools to address
−Removed: cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices;
−Removed: regular simulation modules for all employees to enhance awareness and responsiveness to possible threats;
−Removed: cybersecurity management and incident training for employees involved in our systems and processes that handle sensitive data;
−Removed: cyber liability insurance that is intended to provide protection against the potential losses arising from a cybersecurity incident.
−Removed: We are currently working
−Removed: with outside counsel to further develop a formal cybersecurity incident response plan as a part of our review of and improvements to
−Removed: the Company’s cybersecurity policies.
+Added: provide annual mandatory training for our employees regarding cybersecurity threats as a means to equip them with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices;
+Added: conduct regular simulation modules for all employees to enhance awareness and responsiveness to possible threats;
+Added: conduct cybersecurity management and incident training for employees involved in our systems and processes that handle sensitive data;
+Added: carry cyber liability insurance that is intended to provide protection
+Added: against the potential losses arising from a cybersecurity incident;
+Added: review and monitor internal control audit reports for our significant third-party vendors to ensure sufficient controls are in place to mitigate security-related risks.
+Added: In addition, we have in place
+Added: a formal cybersecurity incident response plan, which we are currently harmonizing between the two companies as a result of the Merger
+Added: in the third quarter of 2025.
+Added: CorMedix has a formal process
+Added: to respond to events, identify incidents, and track progress for remediation.
+Added: No events, either individually or in the aggregate of related
+Added: occurrences, have materially affected the Company in the period covered by this Annual Report on Form 10-K.
+Added: In determining materiality,
+Added: cybersecurity incidents are reviewed not only for potential financial impacts, which could include potential legal and regulatory penalties,
+Added: stolen assets or funds, system damage, forensic and remediation costs, lost revenue or litigation costs, but also the breadth and sensitivity
+Added: of data exposure, data exfiltration, impacts on the ability to operate our business or provide our services and loss of investor confidence.
While we are regularly exposed
3 unchanged sentences
are reviewed not only for potential financial impacts, which could include potential legal and regulatory penalties, stolen assets or
−Removed: funds, system damage, forensic and remediation costs, lost revenue or litigation costs, but also the breadth and sensitivity of data
−Removed: exposure, data exfiltration, impacts on the ability to operate our business or provide our services and loss of investor confidence.
−Removed: The Board executes its oversight
−Removed: responsibility for risk management both directly and through delegating oversight of certain risks to its committees.
−Removed: The Board has authorized
−Removed: the Audit Committee to oversee risks related to cybersecurity threats.
−Removed: Our Audit Committee has primary oversight responsibility for cybersecurity
−Removed: and information security risk management and controls.
−Removed: As part of its oversight function, the Audit Committee oversees the Company’s
−Removed: risk assessment and risk management policies, including related to cybersecurity and the overall data protection program.
−Removed: Our senior management is responsible for assessing
−Removed: and managing the Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including
−Removed: the identification of risks through an enterprise risk management framework and the creation of appropriate risk management programs
−Removed: and policies to address such risks.
−Removed: In particular, the Company’s Senior Manager, IT, has 24 years of experience in enterprise IT
−Removed: and has primary responsibility for managing our cybersecurity program and efforts.
−Removed: Our finance and IT teams are responsible for the testing
−Removed: and audit of our information-technology related internal controls.
+Added: funds, system damage, forensic and remediation costs, lost revenue or litigation costs, but also the breadth and sensitivity of data exposure,
+Added: data exfiltration, impacts on the ability to operate our business or provide our services and loss of investor confidence.
+Added: Our Board of Directors (the
+Added: “Board”) executes its oversight responsibility for risk management both directly and through delegating oversight of certain
+Added: risks to its committees.
+Added: In particular, the Board has authorized the Audit Committee to oversee risks related to cybersecurity threats.
+Added: As part of that oversight function, the Audit Committee oversees the Company’s risk assessment and risk management policies, including
+Added: related to cybersecurity and the Company’s overall data protection program.
+Added: Our senior management is responsible
+Added: for assessing and managing the Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis,
+Added: including the identification of risks through an enterprise risk management framework and the creation of appropriate risk management
+Added: programs and policies to address such risks.
+Added: In particular, the Company’s Senior Manager, IT, has 25 years of experience in enterprise
+Added: IT and has primary responsibility for managing our cybersecurity program and efforts.
+Added: Our finance and IT teams are responsible for the
+Added: testing and audit of our information-technology related internal controls.
+Added: Company management regularly reports to the Audit Committee
+Added: on our cybersecurity program strategy and implementation, and on an ad-hoc basis, as needed, in the event of a security incident.
See Item 1A, Risk Factors ,
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.