3 unchanged sentences
Risk Management and Strategy
−Removed: Given the importance of cybersecurity to our business, we maintain a cybersecurity program to help support the effectiveness of our systems and our preparedness for cybersecurity risks.
−Removed: Our program is informed by industry frameworks, such as the NIST Cybersecurity Framework, and comprises various components, including policies, procedures and protocols;
−Removed: threat monitoring and alerting;
−Removed: auditing and assessments;
−Removed: and other security controls and tools.
+Added: Given the importance of cybersecurity to our business, we maintain a cybersecurity program to help support the effectiveness of our systems, and our preparedness for cybersecurity risks, and our protection of the confidentiality, integrity, and availability of our critical systems and information.
+Added: Our cybersecurity risk management program is part of our overall risk management program and shares similar governance processes and reporting channels that apply across the risk management program to financial, legal, compliance, and other operational risk areas.
+Added: Our program is informed by industry frameworks, such as the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework 2.0 (“NIST CSF 2.0”).
+Added: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use frameworks such as NIST CSF 2.0 as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
We also require cybersecurity trainings when onboarding new employees and contractors, as well as annual cybersecurity awareness training for our employees and contractors.
−Removed: We use various means, including our Enterprise Risk Management (“ERM”) process, in an effort to assess and manage cybersecurity risks that may be associated with our systems, operations, and third-party service providers.
−Removed: We also are working towards enhancing our cybersecurity risk management practices and various other security controls following the Spin-Off, and have at times conducted internal audits and engaged external assessors to help review our cybersecurity program and identify opportunities for maturing our program.
−Removed: For additional information, see “Item 1A—Risk Factors”.
+Added: We use our Enterprise Risk Management (“ERM”) process to assess and manage cybersecurity risks that may be associated with our systems, operations, and third-party service providers.
+Added: We conduct internal audits and engage external assessors to help review our cybersecurity program and identify opportunities for maturing our program.
+Added: For additional information, see “Item 1A.
+Added: Risk Factors”.
Identifying, assessing and managing cybersecurity risks
−Removed: Our cybersecurity team and the owners of information technology systems across the business, led by our Chief Security Officer (“CSO”), monitor current events and trends related to cybersecurity in an effort to anticipate potential risks and threats on current systems and operations.
−Removed: We have implemented or are in the process of implementing various processes to identify, review and track risks to our systems and operations, including through the use of third-party solutions.
−Removed: We also seek to conduct due diligence in connection with the onboarding of new third-party vendors, and reviews are conducted on our critical third-party vendors.
−Removed: Following these assessments, we utilize the findings to improve and mature our cybersecurity practices and to promote continuous improvement.
−Removed: In addition, we have implemented a cybersecurity awareness program to train our employees and contractors on key cyber threats, which includes phishing exercises.
−Removed: In the event of a cybersecurity incident, we have policies and processes for detecting threats and managing incident response.
+Added: Our cybersecurity team and the owners of information technology systems across the business, led by our Chief Security Officer (“CSO”) and Vice President, Security (“VP, Security”), monitor current events and trends related to cybersecurity in an effort to anticipate potential risks and threats on current systems and operations.
+Added: We have implemented and continue to develop various processes to identify, review and track risks to our systems and operations, including through the use of third-party solutions and penetration testing of our systems.
+Added: We have policies and procedures for performing cybersecurity risk assessments of our third-party service providers that may have access to our systems, data, facilities, or that otherwise perform services on our behalf and for conducting due diligence in connection with the onboarding of new third-party vendors.
+Added: As a core component of our enterprise risk management strategy, we maintain a rigorous cybersecurity program that is periodically evaluated through internal assessments and independent third-party audits.
+Added: We perform comprehensive maturity assessments against the NIST CSF2.0 and the NIST Privacy Framework.
+Added: These strategic reviews complement our sustained compliance posture, which includes recurring annual audits for ISO/IEC 27001, SOC 2 Type 2, PCI DSS, UK Cyber Essentials and HIPAA.
+Added: We leverage these assessments to identify functional gaps and benchmark our cybersecurity program against applicable regulatory requirements.
+Added: The resulting findings are integrated into a formal Remediation Roadmap designed to mature our security posture and drive continuous improvement.
+Added: By integrating findings from both internal evaluations and independent external audits, we foster a culture of continuous improvement and operational resilience.
+Added: Recognizing that the human element is a critical line of defense, we maintain a robust cybersecurity awareness program.
+Added: This initiative equips our employees and contractors to recognize and mitigate evolving threats through continuous education and regular phishing simulation exercises designed to reinforce vigilant behavior.
+Added: Our process also includes initial due diligence, ongoing monitoring, and periodic reassessments of our third-party service providers.
+Added: In the event of a cybersecurity incident, we have an incident response framework that includes defined escalation procedures, cross-functional coordination protocols, regulatory notification assessment procedures, and post-incident review processes.
We also periodically conduct cross-functional exercises and activities to help detect, assess and respond to cybersecurity incidents, and have relationships with external providers to assist with incident response efforts, as needed.
1 unchanged sentence
We maintain specific coverage to help mitigate losses associated with certain cybersecurity incidents that impact our or our third parties’ systems, networks and technology.
−Removed: As of December 31, 2024, we are not aware of any risks from cybersecurity threats , or from previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company.
+Added: As of December 31, 2025, we have not identified any risks from cybersecurity threats , including as a result of any previous cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations, or financial condition.
+Added: We assess materiality based on quantitative and qualitative factors, including potential impact to our operations, financial condition, intellectual property, regulatory compliance obligations, and reputation.
While we maintain a cybersecurity program, the techniques used to infiltrate information technology systems continue to evolve.
−Removed: Accordingly, we may not be able to timely detect threats or anticipate and implement adequate security measures.
−Removed: For additional information, see “Item 1A—Risk Factors”.
+Added: Accordingly, we face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: For additional information, see Item 1A.
+Added: “Risk Factors –Our information technology systems, or those used by our third-party collaborators or other contractors or consultants, may fail or suffer cybersecurity incidents or cyberattacks”.
+Added: Cybersecurity Governance
Our Board of Directors administers its cybersecurity risk oversight function through its Audit Committee.
−Removed: The Audit Committee is charged with reviewing our cybersecurity and other information technology risks, controls, and procedures, including our plan to mitigate cybersecurity risks and respond to data or cybersecurity incidents.
−Removed: The Audit Committee is also charged with reviewing with management cybersecurity issues that could affect the adequacy of our internal controls.
−Removed: At least annually, the Audit Committee meets directly with the CSO and the executive leadership team and receives a report on our cybersecurity program, posture, risks and other matters.
−Removed: At least annually, we conduct an organization-wide ERM process to evaluate key risks in different areas of the business.
−Removed: Among those risks, cybersecurity risks are identified, and scores representing the potential likelihood and severity of each risk are determined.
−Removed: The executive leadership team and Audit Committee receive a direct report of the ERM program findings, including these cybersecurity risks.
+Added: The Audit Committee is charged with reviewing our cybersecurity and other information technology risks, controls, and procedures, including our processes to mitigate cybersecurity risks and respond to data or cybersecurity incidents.
+Added: The Audit Committee is also charged with reviewing cybersecurity issues with management that could affect the adequacy of our internal controls.
+Added: The Audit Committee meets periodically, and at least annually,with the CSO and/or VP, Security and the executive leadership team and receives a report on our cybersecurity program, posture, risks and other matters.
+Added: At least annually, we conduct an organization-wide ERM process to evaluate key risks in different areas of the business including cybersecurity.
+Added: During that process, cybersecurity risks are identified, and scores representing the potential likelihood and severity of each risk are determined.
+Added: The executive leadership team and Audit Committee receive a direct report of the ERM program findings, including these cybersecurity risks and incidents it considers to be significant or potentially significant.
Third-party assessors, consultants, counsel or other parties also participate in Audit Committee discussions as needed.
−Removed: More broadly, the Audit Committee reviews our policies and practices with respect to risk assessment and risk management, including results from our overall Enterprise Risk Management (“ERM”), and discusses with management our major financial risk exposures and the steps that have been taken to monitor and control such exposures.
+Added: More broadly, the Audit Committee reviews our policies and practices with respect to risk assessment and risk management, including results from our overall ERM review, and discusses with management our major risk exposures and the steps that have been taken to monitor and control such exposures.
Cybersecurity is a key piece of our overall ERM program.
1 unchanged sentence
As part of the ERM program, our Chief Compliance Officer gathers information about cybersecurity risk, and that information is included in the Chief Compliance Officer’s report to the Audit Committee.
+Added: Our cybersecurity team and information technology system owners across the business are led by our CSO and VP, Security.
+Added: Our CSO has over five years of tenure with the Company and more than 29 years of experience in technology, including 15 years in cybersecurity.
+Added: He previously served as Chief Technology Officer at NextBio and as Vice President of Software Engineering, Enterprise Informatics at Illumina, Inc.
+Added: He is supported by a cybersecurity organization comprising experts in strategy, governance, risk management, compliance, engineering, security operations, and incident response, including our VP, Security who has over two decades of specialized experience in cybersecurity and privacy.
The CSO is responsible for implementing and overseeing the controls and processes employed to identify, assess and manage the Company’s risks from cybersecurity threats.
We also maintain a Privacy and Security Steering Committee that regularly meets to review and discuss cybersecurity issues and review our cybersecurity-related metrics.
−Removed: The Privacy and Security Steering Committee is comprised of the CSO and other representatives from our cybersecurity, IT, legal, and privacy teams.
−Removed: The CSO, cybersecurity team, and members of the Privacy and Security Steering Committee combined have decades of experience in managing relevant information technology and cybersecurity matters.
−Removed: The CSO also provides regular briefings to our executive leadership team, including the CEO and CFO, and our Audit Committee on cybersecurity matters, such as threats, events, and the state of the program, and at least annually as part of our ERM process.
−Removed: Our security program also includes a yearly audit of our controls towards cybersecurity certifications, including ISO 27001, SOC 2 Type 2, PCI DSS, UK Cyber Essentials, and others.
+Added: The Privacy and Security Steering Committee is composed of the VP, Security, Chief Privacy Officer, Chief Compliance Officer, and other representatives from our cybersecurity, IT, legal, and privacy teams.
+Added: Security, cybersecurity team, and members of the Privacy and Security Steering Committee combined have decades of experience in managing relevant information technology and cybersecurity matters.
+Added: The VP, Security also provides regular briefings to our executive leadership team, including the CEO and CFO, and our Audit Committee on cybersecurity matters, such as threats, events, and the state of the program, and at least annually as part of our ERM process.
+Added: Our management team takes steps to stay informed about and monitor efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from IT personnel;
+Added: threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us;
+Added: and alerts and reports produced by security tools deployed in our IT environment.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.