2 unchanged sentences
Risk Management and Strategy
−Removed: We have implemented a cybersecurity program for assessing, identifying, and managing cybersecurity risks aligned with the National Institute of Standard and Technology Cybersecurity Framework (NIST CSF) and where appropriate we have integrated these processes into our enterprise risk management framework.
−Removed: We have implemented administrative, technical, and physical safeguards designed to protect our information systems and protect the confidentiality, integrity, and availability of our data.
−Removed: We are continuously working to improve our information technology systems and provide employee awareness training around phishing, malware, and other cyber risks to enhance our levels of protection.
−Removed: We engage external parties, such as consultants, to enhance our cybersecurity oversight as required.
−Removed: We conduct periodic risk assessments to evaluate our cybersecurity posture, including through annual third-party vulnerability assessment and penetration tests performed by reputable service providers.
−Removed: We conduct risk assessments, as appropriate, on critical third parties who maintain material data or information to help assess and validate the information security capabilities of these third parties.
−Removed: We maintain insurance coverage for cybersecurity insurance as part of our overall insurance portfolio.
−Removed: We also have implemented administrative, technical, and physical safeguards designed to protect our information systems and protect the confidentiality, integrity, and availability of our data.
−Removed: Governance Related to Cyber Security Risks
−Removed: The Audit Committee of the Board has oversight of management's efforts with respect to IT systems and cybersecurity.
−Removed: As part of this oversight, our Chief Information Security Officer (“CISO”) shares quarterly updates regarding any changes around our cybersecurity defenses, ongoing IT initiatives, and emerging threats and plans to pro-actively address these threats with the Audit Committee.
−Removed: During these meetings, the CISO provides the Audit Committee updates regarding any changes around our cyber defenses, ongoing IT initiatives, and emerging threats and plans to pro-actively address these threats.
−Removed: Our Board has delegated primary responsibility for the oversight of cybersecurity matters to the Audit Committee;
−Removed: however, the full Board reviews significant cybersecurity matters as appropriate.
−Removed: The Audit Committee provides updates to the Board on a quarterly basis on the activities that the Audit Committee oversees, including Cybersecurity .
−Removed: Our Chief Information Security Officer is responsible for strengthening and continuously monitoring the effectiveness of our cybersecurity program.
−Removed: The individual currently serving in the role of Chief Information Security Officer has over 30 years of information systems and cybersecurity experience within complex and international business verticals such as technology, financial services, biotech, and other scientific organizations.
−Removed: He also holds the Certified Information Systems Security Professional (CISSP) certification.
−Removed: In addition, our cybersecurity steering committee assists in managing certain technical aspects related to cybersecurity.
−Removed: Our cybersecurity steering committee is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents through monthly meetings and frequent communications.
−Removed: Regular members of the steering committee consist of participants from the IT infrastructure, Business Systems, AI and Modelling and Scientific Computing teams.
−Removed: Participants from other teams attend on an as-needed basis.
−Removed: To date, we have not identified any indication of a cybersecurity incident that would have a material impact on our business and consolidated financial statements.
−Removed: However, as discussed more fully under “Item 1A.
−Removed: Risk Factors”, the sophistication of cyber threats continues to increase and we cannot assure that our systems and processes will be successful, that we will be able to anticipate or detect all cyberattacks or other breaches, that we will be able to react to cyberattacks or other breaches in a timely manner or that our remediation efforts will be successful.
+Added: We maintain a cybersecurity program designed to assess, identify, and manage risks from cybersecurity threats and to protect the confidentiality, integrity, and availability of our information systems and data.
+Added: Our cybersecurity program is aligned with recognized cybersecurity frameworks, including the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and is integrated, where appropriate, into the Company’s broader enterprise risk management processes .
+Added: We have implemented administrative, technical, and physical safeguards designed to protect our information systems and data.
+Added: These safeguards include ongoing monitoring of information technology systems, employee awareness training regarding phishing and other cyber risks, and processes intended to detect, prevent, and respond to potential cybersecurity incidents.
+Added: We engage external consultants and service providers, as appropriate, to assist in evaluating and enhancing our cybersecurity posture.
+Added: Periodically, we conduct risk assessments, including third-party vulnerability assessments and penetration testing performed by reputable service providers.
+Added: We also evaluate cybersecurity risks associated with certain third-party vendors that may have access to our systems or data.
+Added: In addition, we maintain cybersecurity insurance coverage as part of our overall insurance portfolio.
+Added: To date, we have not identified any cybersecurity incidents that have had a material impact on our business strategy, results of operations, or financial condition.
+Added: However, cybersecurity threats continue to evolve in sophistication, and there can be no assurance that our systems and processes will be successful in preventing or detecting cyberattacks or other breaches or that remediation efforts will be successful.
+Added: Governance Related to Cybersecurity Risks
+Added: The Audit Committee of the Board of Directors oversees management’s processes related to information technology and cybersecurity risks and reports significant cybersecurity matters to the full Board as appropriate.
+Added: Historically, the Company’s cybersecurity program was overseen by the Company’s Chief Information Security Officer (“CISO”) .
+Added: The Company’s former CISO resigned in June 2025, and the Company is currently evaluating options regarding the role.
+Added: In the interim, certain cybersecurity monitoring and oversight activities are performed by the Company’s Senior Information Technology Systems Manager, who has over 15 years of experience in information technology and enterprise systems .
+Added: The Senior Information Technology Systems Manager reviews aspects of the Company’s information security posture, cybersecurity controls, and monitoring activities and escalates matters to senior management as appropriate .
+Added: The Company also utilizes external service providers to support certain cybersecurity monitoring and security management activities.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.