−Removed: STAFF COMMENTS
+Added: UNRESOLVED STAFF COMMENTS
CYBERSECURITY
−Removed: Risk Management and Strategy
−Removed: operate in the life sciences sector, which is subject to various cybersecurity risks that could adversely affect our business, financial
−Removed: condition, and results of operations.
−Removed: We have developed and maintain processes, aligned with industry standards and best practices designed
−Removed: to assess, identify, and manage cybersecurity risks from potential unauthorized occurrences on or through our information technology
−Removed: systems that may result in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing
−Removed: The scope of these processes includes risks that may be associated with both our internally managed information technology (“IT”)
−Removed: systems and key business functions and sensitive data operated or managed by or maintained at third-party service providers.
−Removed: These processes
−Removed: are managed and monitored by a dedicated information technology team, which is led by our head of IT, and include mechanisms, controls,
−Removed: technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities
+Added: Cyber Risk Management and Strategy
+Added: We operate in the life sciences
+Added: sector, which is subject to various cybersecurity risks that could adversely affect our business, financial condition, and results of
+Added: We have developed and maintain processes, aligned with industry standards and best practices designed to assess, identify,
+Added: and manage cybersecurity risks from potential unauthorized occurrences on or through our information technology systems that may result
+Added: in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing therein.
+Added: The scope of these
+Added: processes includes risks that may be associated with both our internally managed information technology (“IT”) systems and
+Added: key business functions and sensitive data operated or managed by or maintained at third-party service providers.
+Added: These processes are managed
+Added: and monitored by a dedicated information technology team, which is led by our head of IT, and include mechanisms, controls, technologies,
+Added: systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities
affecting the data and maintain a stable information technology environment.
5 unchanged sentences
We leverage standard industry tools from a software and hardware perspective and maintain a cybersecurity risk insurance policy.
−Removed: consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework.
−Removed: the last fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity
−Removed: incidents, which have materially affected us, but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably
−Removed: likely to materially affect us.
−Removed: Related to Cybersecurity Risks
−Removed: Board of Directors, as a whole and at the committee level, has oversight for the most significant risks facing us and for our processes
−Removed: to identify, prioritize, assess, manage, and mitigate those risks.
−Removed: The Compliance Committee, which is comprised solely of independent
−Removed: directors, has been designated by our Board to oversee cybersecurity risks.
−Removed: The Compliance Committee receives periodic updates on cybersecurity
−Removed: and information technology matters and related risk exposures.
−Removed: The Board also receives updates from management and the Compliance Committee
−Removed: on cybersecurity risks on at least an annual basis.
−Removed: Vice President of Information Technology has over 15 years of experience managing information technology and cybersecurity matters.
−Removed: Vice President of Information Technology, together with our senior leadership team, are responsible for assessing and managing cybersecurity
−Removed: risks and they work collaboratively across our company to implement policies and procedures designed to protect our information and systems
−Removed: from cybersecurity threats and to respond promptly to any material cybersecurity incidents in accordance with our incident response plans.
−Removed: A cross-functional team is responsible for responding to cybersecurity incidents.
+Added: We consider cybersecurity,
+Added: along with other significant risks that we face, within our overall enterprise risk management framework.
+Added: In the last fiscal year, we
+Added: have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, which have materially
+Added: affected us, but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect us.
+Added: Governance Related to Cybersecurity Risks
+Added: The Board of Directors, as
+Added: a whole and at the committee level, has oversight for the most significant risks facing us and for our processes to identify, prioritize,
+Added: assess, manage, and mitigate those risks.
+Added: The Compliance Committee, which is comprised solely of independent directors, has been designated
+Added: by our Board to oversee cybersecurity risks.
+Added: The Compliance Committee receives periodic updates on cybersecurity and information technology
+Added: matters and related risk exposures.
+Added: The Board also receives updates from management and the Compliance Committee on cybersecurity risks
+Added: on at least an annual basis.
+Added: The Director of Information
+Added: Systems and Support, together with our senior leadership team, are responsible for assessing and managing cybersecurity risks and they
+Added: work collaboratively across our company to implement policies and procedures designed to protect our information and systems from cybersecurity
+Added: threats and to respond promptly to any material cybersecurity incidents in accordance with our incident response plans.
+Added: A cross-functional
+Added: team is responsible for responding to cybersecurity incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.