Unresolved Staff Comments.
−Removed: reporting companies are not required to provide the information required by this item.
Cybersecurity.
−Removed: believe cybersecurity risk management is an important part of its overall risk management efforts.
−Removed: The Company has a policy of transparency
−Removed: regarding our data collection, use, retention and sharing practices, and it is our commitment to implement appropriate technical security
−Removed: measures to protect all Company stakeholders and manage third party risk.
+Added: We believe cybersecurity risk management is an
+Added: important part of its overall risk management efforts.
+Added: The Company has a policy of transparency regarding our data collection, use, retention
+Added: and sharing practices, and it is our commitment to implement appropriate technical security measures to protect all Company stakeholders
+Added: and manage third party risk.
Our operations may, in some cases, involve the
14 unchanged sentences
costs or contractual liabilities with third-party vendors and customers).
−Removed: on the environment and system, we implement and maintain various technical, physical, and organizational measures, processes, standards
−Removed: and policies designed to manage and mitigate material risks from cybersecurity threats, including, for example, periodic cybersecurity
−Removed: testing and cybersecurity awareness training for employees.
−Removed: Company is actively engaged in identifying and managing cybersecurity risks.
−Removed: Protecting company data, non-public customer and employee
−Removed: data, and the systems that collect, process, and maintain this information is deemed critical.
−Removed: use third-party service providers to perform a variety of functions throughout our business, including manufacturing our product candidates
−Removed: and assisting with R&D activities.
−Removed: Depending on the nature of the services provided, the sensitivity of the systems and data at issue,
−Removed: and the identity of the provider, our vendor contracting processes may include imposing certain contractual provisions related to privacy
−Removed: and cybersecurity.
+Added: Depending on the environment and system, we implement
+Added: and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate
+Added: material risks from cybersecurity threats, including, for example, periodic cybersecurity testing and cybersecurity awareness training
+Added: for employees.
+Added: The Company is actively engaged in identifying
+Added: and managing cybersecurity risks.
+Added: Protecting company data, non-public customer and employee data, and the systems that collect, process,
+Added: and maintain this information is deemed critical.
+Added: We use third-party service providers to perform
+Added: a variety of functions throughout our business, including manufacturing our product candidates and assisting with R&D activities.
+Added: Depending on the nature of the services provided, the sensitivity of the systems and data at issue, and the identity of the provider,
+Added: our vendor contracting processes may include imposing certain contractual provisions related to privacy and cybersecurity.
In addition, the Board will oversee any cybersecurity
5 unchanged sentences
or more frequently as needed, to ensure cybersecurity risks are appropriately managed and integrated into our broader risk oversight strategy.
−Removed: Cybersecurity
−Removed: 2018, the United States Securities and Exchange Commission (the “ SEC ”) published interpretive guidance to assist public
−Removed: companies in preparing disclosures about cybersecurity risks and incidents.
−Removed: These SEC guidelines, and any other regulatory guidance,
−Removed: are in addition to notification and disclosure requirements under state and federal laws and regulations.
−Removed: If we fail to observe this
−Removed: regulatory guidance or standards, we could be subject to various regulatory sanctions, including financial penalties.
−Removed: regulators have been increasingly active in implementing privacy and cybersecurity standards and regulations.
−Removed: Recently, several states
−Removed: have adopted regulations requiring certain financial institutions to implement cybersecurity programs and providing detailed requirements
−Removed: with respect to these programs, including data encryption requirements.
−Removed: Many states have also recently implemented or modified their
−Removed: data breach notification, information security and data privacy requirements.
−Removed: We expect this trend of state-level activity in those areas
−Removed: to continue and are continually monitoring developments where our customers are located.
−Removed: and exposures related to cybersecurity attacks, including litigation and enforcement risks, are expected to be elevated for the foreseeable
−Removed: future due to the rapidly evolving nature and sophistication of these threats, as well as due to the expanding use of Internet banking,
−Removed: mobile banking, and other technology-based products and services by us.
−Removed: Board, in coordination with the Audit Committee, oversees the Company’s processes for assessing and managing risk.
−Removed: The Board and
−Removed: Audit Committee may review the measures implemented by the Company to identify and mitigate data protection and cybersecurity risks.
−Removed: The Company’s Audit Committee is also responsible for overseeing cybersecurity risk and are informed in a timely manner of any
−Removed: incidents considered potentially serious, together with details on the prevention, detection, mitigation and remediation of such incidents.
−Removed: from Cybersecurity Threats
−Removed: of the date of this report, we are not aware of any material risks from cybersecurity threats that have materially affected or are reasonably
−Removed: likely to materially affect the Company, including our business strategy, results of operations, or financial condition.
−Removed: cannot provide assurance that we will not experience any such event in the future.
−Removed: For a description of the risks from cybersecurity
−Removed: threats that may materially affect the Company and how they may do so, see our risk factors under Part 1.
−Removed: Risk Factors in this
−Removed: Annual Report, including the risk entitled “Our computer systems or data, or those of our collaborators or other contractors or
−Removed: consultants, maybe compromised, which could result in adverse consequences, including but not limited to regulatory investigations or
−Removed: fines and penalties;
−Removed: significant disruption of our product development programs and our ability to operate our business
−Removed: reputational harm;
−Removed: and other adverse consequences.”
+Added: Cybersecurity Risk
+Added: In 2023, the SEC adopted new
+Added: rules to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incidents by public companies
+Added: that are subject to the reporting requirements of the Exchange Act.
+Added: These require current disclosure about material cybersecurity incidents,
+Added: as well as requiring periodic disclosures about a public company’s processes to assess, identify, and manage material cybersecurity
+Added: risks, management’s role in assessing and managing material cybersecurity risks, and the board of directors’ oversight of
+Added: cybersecurity risks.
+Added: If we fail to comply with these rules, we could be subject to various regulatory sanctions, including
+Added: financial penalties.
+Added: State regulators have been increasingly active
+Added: in implementing privacy and cybersecurity standards and regulations.
+Added: Recently, several states have adopted regulations requiring certain
+Added: financial institutions to implement cybersecurity programs and providing detailed requirements with respect to these programs, including
+Added: data encryption requirements.
+Added: Many states have also recently implemented or modified their data breach notification, information security
+Added: and data privacy requirements.
+Added: We expect this trend of state-level activity in those areas to continue and are continually monitoring
+Added: developments where our customers are located.
+Added: Risks and exposures related to cybersecurity attacks,
+Added: including litigation and enforcement risks, are expected to be elevated for the foreseeable future due to the rapidly evolving nature
+Added: and sophistication of these threats, as well as due to the expanding use of Internet banking, mobile banking, and other technology-based
+Added: products and services by us.
+Added: The Board, in coordination with the Audit Committee,
+Added: oversees the Company’s processes for assessing and managing risk.
+Added: The Board and Audit Committee may review the measures implemented
+Added: by the Company to identify and mitigate data protection and cybersecurity risks.
+Added: The Company’s Audit Committee is also responsible
+Added: for overseeing cybersecurity risk and are informed in a timely manner of any incidents considered potentially serious, together with details
+Added: on the prevention, detection, mitigation and remediation of such incidents.
+Added: Risks from Cybersecurity Threats
+Added: As of the date of this Annual Report, we are
+Added: not aware of any material risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect
+Added: the Company, including our business strategy, results of operations, or financial condition.
+Added: However, we cannot provide assurance that
+Added: we will not experience any such event in the future.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.