1 unchanged sentence
CYBERSECURITY
−Removed: Risk Management and Strategy
−Removed: The Company is a late-stage clinical biotechnology company committed to applying scientific leadership in the field of localized cancer reduction leading to anti-cancer immune activation.
−Removed: Currently, management has not adopted a formal cybersecurity risk management program or process for assessing cybersecurity risk.
−Removed: Management assesses material risks from cybersecurity threats on an ongoing basis, including any potential unauthorized access to or occurrence on or conducted through the Company’s information systems that may result in adverse effects on the confidentiality, integrity, or availability of information systems or any information residing therein.
−Removed: To this end, the Company utilizes an outsourced information technology consultant to implement systems and procedures designed to reduce, respond to and monitor for cybersecurity threats and vulnerabilities.
−Removed: The outsourced information technology consultant conducts proactive patching and monitoring of all of our existing systems and has implemented systems and procedures to mitigate cybersecurity risks that the Company believes are appropriate for a company of our size, stage of growth and financial condition.
−Removed: In addition, the Company carries insurance with coverage for cyber events that it believes is suitable for a company of our size, stage of growth and financial condition.
−Removed: As of the date of this Annual Report on Form 10-K, the Company is not aware of any cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected the Company, including the Company’s business strategy, results of operations or financial condition.
−Removed: Management is responsible for the day-to-day management of the risks we face, while our Board of Directors as a whole has responsibility for the oversight of risk management, including as to material risks from cybersecurity threats.
−Removed: In its risk oversight role, the Company’s Board of Directors has the responsibility to satisfy itself that the risk management processes designed and implemented by management are appropriate and functioning as designed.
−Removed: The Board of Directors has delegated to the Audit Committee of the Board of Directors the responsibility for the oversight of information technology (including cybersecurity) risks.
−Removed: In general, the Company seeks to address cybersecurity risks through a cross-functional approach that is focused on preserving the confidentiality, integrity, and availability of the information that it collects and stores by identifying, preventing, and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
+Added: We recognize the critical importance of maintaining the trust and confidence of our business partners, such as CROs, clinical trial investigators, patients, employees, subcontractors and other vendors.
+Added: We are committed to protecting the confidentiality, integrity and availability of our business operations and systems, and its board of directors is actively involved in oversight of our risk management activities, and cybersecurity represents an essential element of our overall approach to risk management.
+Added: In general, we seek to address cybersecurity risks through a comprehensive, cross-functional
+Added: approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents should they occur.
+Added: Cybersecurity Risk Management and Strategy;
+Added: Effect of Risk
+Added: We face risks related to cybersecurity, such as unauthorized access, cybersecurity attacks, phishing, and other security incidents, including perpetration by hackers and unintentional damage or disruption to hardware and software systems, loss of data, phony invoices, and misappropriation of confidential information.
+Added: To identify and assess material risks from cybersecurity threats, we, together with our contracted third-party cybersecurity advisors, maintain a comprehensive cybersecurity program to ensure our systems are effective and prepared for information security risks, including regular oversight of our programs for security monitoring of internal and external threats to ensure the confidentiality and integrity of its information assets.
+Added: We consider risks from cybersecurity threats alongside other company risks as part of our overall risk assessment process.
+Added: As discussed in more detail under “Cybersecurity Governance” below, our board of directors provides oversight of our cybersecurity risk management and strategy processes, which are led by management.
+Added: We, with assistance from our contracted third-party cybersecurity advisors, identifies, protects, and responds to our cybersecurity risks and incidents, through the following activities:
+Added: • monitoring emerging data protection laws and implementing changes to processes that are designed to comply with such laws;
+Added: • requiring employees, as well as third parties that provide services on our behalf, to treat confidential information and data with care;
+Added: • employing technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality, double verification software, and access controls;
+Added: • performing backups of local hard drives and our financial systems in the cloud and on physical media that are stored off-site in locked locations;
+Added: • providing mandatory training for our employees regarding cybersecurity threats;
+Added: • carrying information security risk insurance that provides protection against the potential losses arising from a cybersecurity incident.
+Added: Our processes also address cybersecurity threat risks associated with our selection and oversight of third-party service providers, including our suppliers and manufacturers or those who have access to patient and employee data or our systems.
+Added: We generally require those third parties that could introduce significant cybersecurity risk to agree by contract to manage their cybersecurity risks in specified ways.
+Added: We do not have any in-house servers or systems.
+Added: An integral part of our cybersecurity is the security built into this third-party software operated by large corporations such as Microsoft.
+Added: Our control system, therefore, includes the review of annual Service Organization Controls reports in order to annually assess the controls of these software systems.
+Added: To date, we have not experienced any material cybersecurity incidents.
+Added: Cybersecurity Governance;
+Added: Cybersecurity is an important part of our risk management processes and an area of focus for the board of directors and management.
+Added: Management is responsible for the operational oversight of company-wide cybersecurity strategy, policy, and standards across relevant departments to assess and help prepare the Company to address cybersecurity risks.
+Added: Our board of directors provides direct oversight over cybersecurity risk and receives periodic updates from management regarding cybersecurity matters and is notified between such updates regarding any significant new cybersecurity threats or incidents.
+Added: Our cybersecurity risk management and strategy processes, which are discussed in greater detail above, are led by our Chief Executive Officer with the assistance of contracted third-party cybersecurity advisors.
+Added: These management team members are informed about and monitor the prevention, mitigation, detection, and remediation of cybersecurity incidents through their management of, and participation in, the cybersecurity risk management and strategy processes described above, including incident response processes.
+Added: We currently maintain all of our operations at 1 Enterprise Drive, Suite 430, Shelton, Connecticut pursuant to a 5.5- year lease entered into in July 2023 (the “Shelton Lease”).
+Added: We consider our current office space adequate for our current operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.