Item 1B. Unresolved Staff Comments
ITEM 1B.
UNRESOLVED STAFF COMMENTS
Not applicable.
ITEM 1C. CYBERSECURITY
Our corporate information technology, communication networks, enterprise applications, accounting and financial reporting platforms, and related systems are necessary for the operation of our business. We use these systems, among others, to manage our product development, to communicate internally and externally, to operate our accounting and record-keeping functions, to store and access data including sensitive patient data, digital assets and for many other key aspects of our business. Our business operations rely on the secure collection, storage, transmission, and other processing of proprietary, confidential, and sensitive data.
Risk Management and Strategy
We recognize the importance of assessing, identifying, and managing material risks associated with material cybersecurity threats, as such term is defined in Item 106(a) of Regulation S-K. These risks may include, among other things: operational risks, intellectual property theft, fraud, extortion, harm to employees, customers or patients, violation of data privacy or security laws, litigation, and legal, financial and reputational risk.
In coordination with third-party consultants, we have implemented and maintain various information security processes designed to identify, assess and manage material risks from cybersecurity threats to our critical systems, data, and digital assets. Depending on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards, and/or policies designed to manage and mitigate material risks from cybersecurity threats to our information systems and data, including risk assessments, incident detection and response, vulnerability management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, vendor risk management program and employee training. We conduct annual reviews and tests of our information security program to evaluate its effectiveness and improve our security measures and planning.
To operate our business, we utilize certain third-party service providers and vendors to support a variety of functions. We seek to engage reliable, reputable service providers and vendors that maintain cybersecurity programs, and we implement a vetting process designed to ensure that all third-party service providers and vendors comply with our cybersecurity program requirements. Depending on the nature of the services provided, the sensitivity and quantity of information
49
Table of Contents
processed, and the identity of the service provider, our vendor management process may include reviewing the cybersecurity practices of such provider, contractually imposing obligations on the provider, conducting security assessments, and conducting periodic reassessments during their engagement.
For more information on cybersecurity threats, please see the risk factor titled, “If we or the third parties with whom we work experience a security breach, cyber incident, or vulnerability impacting our systems or our data, or if unauthorized parties obtain access to our Solana, or if our private keys are lost or destroyed, or other similar circumstances or events occur, we may lose some or all of our Solana and our financial condition and results of operations could be materially adversely affected .”
Governance
Our Board of Directors holds oversight responsibility for the Company’s strategy and risk management, including material risks related to cybersecurity threats. Oversight of such cybersecurity risks is executed directly by the Board of Directors. The Board receives reports and engages in periodic discussions with management regarding the Company’s significant risk exposures resulting from material cybersecurity threats and the measures implemented to monitor and reasonably manage these risks .
Our Director of Information Technology leads our information security organization and reports to our Chief Executive Officer and Chief Financial Officer on matters related to cybersecurity who then in turn report to the Board of Directors any material information regarding such cybersecurity matters. Our Director of Information Technology has over 30 years of IT experience.
ITEM 2.
PROPERTIES
The Company leases corporate office space in Newtown, Pennsylvania under an operating lease. In February 2026, the Company entered into an agreement with the landlord to extend the term of such lease to expire in May 2026. The lease does not contain any options to extend. We believe our current facility is adequate for our needs.