1 unchanged sentence
Cybersecurity
−Removed: Company’s cybersecurity risks are theft of intellectual property, theft of other business data, fraud or extortion, lack of access
−Removed: to our information systems, harm to employees, harm to business partners, violation of privacy laws, potential reputational risk, and
−Removed: litigation or other legal risk if a cybersecurity incident were to occur.
−Removed: It is difficult to assign a monetary materiality assessment
−Removed: to these risks or to the impact if the Company were to sustain a breach of its systems.
−Removed: Our approach is based on the premise that any
−Removed: cybersecurity incident could result in material harm to the Company.
−Removed: Audit Committee has been designated with oversight responsibility for cybersecurity risks and our Chief Financial Officer is responsible
−Removed: for managing our efforts in this area.
−Removed: Neither the Chief Financial Officer nor any member of the Audit Committee has relevant expertise
−Removed: in cybersecurity.
−Removed: Rather, the Company retains an outside technical expert to support our information technology systems including addressing
−Removed: cybersecurity risks.
−Removed: conduct annual risk assessments and quarterly vulnerability scans of risks posed by cybersecurity threats in conjunction with our insurance
−Removed: renewal cycles.
−Removed: As a result of these assessments, we have implemented technical, administrative, and, where appropriate, physical controls
−Removed: and practices to proactively monitor our systems and user accounts including, but not limited to, deploying solutions to constantly monitor
−Removed: users accessing systems, implementation of two factor authentication for logins, and improved rules for password maintenance.
+Added: Management and Strategy
+Added: recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information
+Added: systems and protect the confidentiality, integrity, and availability of our data.
+Added: The Company considers its primary cybersecurity risks
+Added: to be theft of intellectual property, theft of other business data, fraud or extortion, lack of access to its information systems, harm
+Added: to employees, harm to business partners, violation of privacy laws, potential reputational risk, and litigation or other legal risk if
+Added: a cybersecurity incident were to occur.
+Added: It is difficult to assign a monetary materiality assessment to these risks or to the impact if
+Added: the Company were to sustain a breach of its systems.
+Added: The Company’s approach to cybersecurity is based on the premise that any cybersecurity
+Added: incident could result in material harm to the Company.
+Added: We have a cybersecurity and risk management processes in place to oversee risks
+Added: associated with cybersecurity and respond to emerging threats in a timely and effective manner.
+Added: We monitor our systems to assess cybersecurity risks and threats.
+Added: Material Risks & Integrated Overall Risk Management
+Added: have integrated cybersecurity risk management into our broader risk management framework.
+Added: This integration ensures that cybersecurity
+Added: considerations are an integral part of our decision-making process.
+Added: We conduct annual risk assessments and quarterly vulnerability scans
+Added: of risks posed by cybersecurity threats in conjunction with our insurance renewal cycles.
+Added: As a result of these assessments, we have implemented
+Added: technical, administrative, and, where appropriate, physical controls and practices to proactively monitor our systems and user accounts
+Added: including, but not limited to, deploying solutions to constantly monitor users accessing systems, implementation of two factor authentication
+Added: for logins, and improved rules for password maintenance .
many companies, we make use of cloud-based solutions provided by several large service providers for critical information technology
5 unchanged sentences
that they have suffered a breach of their systems.
−Removed: of our business partners also maintain data related to our trials and ongoing product development on servers they maintain.
−Removed: these partners to comply with all HIPAA standards for maintaining security of their systems where this data resides.
+Added: Third Parties on Risk Management
+Added: Audit Committee has been designated with oversight responsibility for cybersecurity risks and our Chief Financial Officer is responsible
+Added: for managing our efforts in this area.
+Added: Neither the Chief Financial Officer nor any member of the Audit Committee has relevant expertise
+Added: in cybersecurity.
+Added: Recognizing the complexity and evolving nature of cybersecurity threats, the Company has retained an third-party technical
+Added: expert to support its information technology systems including addressing cybersecurity risks.
+Added: This relationship enables us to leverage
+Added: specialized knowledge and insights, to ensure our cybersecurity strategies and processes are aligned with industry best practices.
+Added: Third Party Risk
+Added: utilize various third-party software applications in the functioning of our core business.
+Added: We conduct assessments of all third-party
+Added: providers and maintain ongoing reviews to ensure compliance with our cybersecurity standards.
+Added: Our assessment of risks associated with
+Added: the use of third-party providers is part of our overall cybersecurity framework .
+Added: In addition, some of our business partners also
+Added: maintain data related to our trials and ongoing product development on servers they maintain.
+Added: We require these partners to comply with
+Added: all HIPAA standards for maintaining security of their systems where this data resides.
+Added: from Cybersecurity Threats
+Added: face risk from cybersecurity threats that could have a material adverse effect on our business, financial condition, results of operations,
+Added: cash flows or reputation.
+Added: For more information about the cybersecurity risks we face, see the risk factor entitled “ Security
+Added: threats to our information technology infrastructure could expose us to liability and damage our reputation and business .”
+Added: in Item 1A., Risk Factors .
+Added: Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats, and recognizes the
+Added: significance of these threats to our operational integrity and stockholder confidence.
+Added: Management Personnel
+Added: utilize an out-sourced information technology (IT) network and cybersecurity compliance service provider, Windstar Technologies,
+Added: (“Windstar”) Windstar, under the supervision of our Chief Financial Officer, is responsible for developing and
+Added: implementing our information security program.
+Added: Windstar provides managed IT network and cloud services, network, cyber and web
+Added: security services, cyber risk audits and compliance and penetration testing assessments.
+Added: of Directors Oversight
+Added: Our Board is aware of the critical nature of managing risks associated with cybersecurity threats, and recognizes
+Added: the significance of these threats to our operational integrity and stockholder confidence .
+Added: Audit Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for this domain .
+Added: Role Managing Risk and Reporting to the Board
+Added: We do not currently have an employee who has significant and demonstrated professional IT management experience.
+Added: Presently, our Chief Financial Officer with assistance from our third-party IT services provider, Windstar,
+Added: are primarily responsible for informing the Audit Committee regarding cybersecurity risks.
+Added: They provide briefings to the Audit Committee
+Added: on a regular basis, with a minimum frequency of once per year .
+Added: addition to scheduled meetings, the Audit Committee and the Chief Financial Officer maintain an ongoing
+Added: dialogue regarding emerging or potential cybersecurity risks.
+Added: Together, they receive updates on any significant developments in the
+Added: cybersecurity domain, ensuring the Board’s oversight is proactive and responsive.
+Added: This involvement ensures that cybersecurity
+Added: considerations are integrated into the Company’s broader strategic objectives and helps in identify areas for improvement,
+Added: ensuring the alignment of cybersecurity efforts with the overall risk management framework.]
+Added: date, we have not experienced any previous cybersecurity incidents that have materially affected or are reasonably likely to materially
+Added: affect our business strategy, results of operations, or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.