UNRESOLVED STAFF COMMENTS
−Removed: CYBERSECURITY
−Removed: Cybersecurity
−Removed: Risk Management and Strategy
−Removed: Company does not have its own cybersecurity policy but relies on the policies and procedures of its Contract Research Organizations (CROs)
−Removed: and Software as a Service (SaaS) contractors that handle its data and software.
−Removed: We are committed to protecting the confidentiality, integrity,
−Removed: and availability of our information assets and complying with applicable laws and regulations regarding cybersecurity.
+Added: Not applicable.
CYBERSECURITY
−Removed: Risks and Incidents
−Removed: Company faces various cybersecurity risks and threats that could potentially affect its operations, reputation, financial condition,
−Removed: and competitive position.
−Removed: These risks and threats include, but are not limited to, unauthorized access, use, disclosure, modification,
−Removed: or destruction of our data, systems, or networks;
+Added: Cybersecurity Risk Management and Strategy
+Added: The Company does not have its own cybersecurity
+Added: policy but relies on the policies and procedures of its Contract Research Organizations (“CROs”) and Software as a Service
+Added: (“SaaS”) contractors that handle its data and software.
+Added: We are committed to protecting the confidentiality, integrity, and
+Added: availability of our information assets and complying with applicable laws and regulations regarding cybersecurity.
+Added: Cybersecurity Risks and Incidents
+Added: The Company faces various cybersecurity risks
+Added: and threats that could potentially affect its operations, reputation, financial condition, and competitive position.
+Added: These risks and threats
+Added: include, but are not limited to, unauthorized access, use, disclosure, modification, or destruction of our data, systems, or networks;
denial of service attacks;
2 unchanged sentences
ransomware attacks;
−Removed: loss or theft of devices or media containing our data;
+Added: loss or theft of devices or
+Added: media containing our data;
human error or negligence;
1 unchanged sentence
power outages;
−Removed: Our data and systems may also be subject to cybersecurity breaches or incidents at its CROs, vendors, partners, or other
−Removed: third parties that we interact with or rely on.
−Removed: have not experienced any material cybersecurity breaches or incidents to date, but we cannot guarantee that we will not suffer any such
−Removed: breaches or incidents in the future.
−Removed: We may not be able to detect, prevent, or respond to all cybersecurity risks and threats in a timely
−Removed: or effective manner.
−Removed: We may also incur significant costs and liabilities as a result of any cybersecurity breaches or incidents, such
−Removed: as legal claims, regulatory fines, remediation expenses, reputational damage, loss of business opportunities, or competitive disadvantage.
−Removed: We may also face litigation, investigations, or enforcement actions by governmental authorities, customers, shareholders, or other parties
−Removed: arising from any cybersecurity breaches or incidents.
−Removed: Cybersecurity
−Removed: Policies and Procedures
−Removed: The Company does not have its own cybersecurity policy,
−Removed: but it contracts with CROs that handle all of its data and software.
+Added: Our data and systems may also be
+Added: subject to cybersecurity breaches or incidents at its CROs, vendors, partners, or other third parties that we interact with or rely on.
+Added: We have not experienced any material cybersecurity
+Added: breaches or incidents to date, but we cannot guarantee that we will not suffer any such breaches or incidents in the future.
+Added: be able to detect, prevent, or respond to all cybersecurity risks and threats in a timely or effective manner.
+Added: We may also incur significant
+Added: costs and liabilities as a result of any cybersecurity breaches or incidents, such as legal claims, regulatory fines, remediation expenses,
+Added: reputational damage, loss of business opportunities, or competitive disadvantage.
+Added: We may also face litigation, investigations, or enforcement
+Added: actions by governmental authorities, customers, shareholders, or other parties arising from any cybersecurity breaches or incidents.
+Added: Cybersecurity Policies and Procedures
+Added: The Company does not have its own cybersecurity
+Added: policy, but it contracts with CROs that handle all of its data and software.
Our CRO’s data systems are 21 CFR 11 (Part 11) compliant,
2 unchanged sentences
incident response, backup and recovery, and employee training.
−Removed: We have reviewed the cybersecurity policies and procedures of our CRO
−Removed: and require them to report any cybersecurity breaches or incidents that may affect our data or systems.
−Removed: of the software that we use is Commercial Off the Shelf Software (COTS) and Microsoft, Dropbox, and Google cloud services.
−Removed: develop, modify, or customize any software for our own use.
−Removed: We rely on the cybersecurity measures and practices of our software and cloud
−Removed: service providers and update our software and systems regularly to address any known vulnerabilities or issues.
−Removed: We also limit the access
−Removed: and use of our software and cloud services to authorized personnel and encourage them to use strong passwords and multifactor authentication.
−Removed: We do not store any sensitive or confidential data on our own devices or media but use password-protected cloud storage.
−Removed: Cybersecurity
−Removed: Oversight and Governance
−Removed: Company’s management is responsible for overseeing and managing our cybersecurity risks and activities as part of its overall risk
−Removed: assessment portfolio.
−Removed: Our management regularly evaluates and reviews the Company’s cybersecurity posture and performance and reports
−Removed: to the board of directors on any material cybersecurity matters or developments.
−Removed: Our management also coordinates with our CROs, vendors,
−Removed: partners, and other third parties to ensure that they comply with our cybersecurity expectations and requirements and to address any
−Removed: cybersecurity issues or concerns that may arise.
−Removed: Company’s board of directors is responsible for overseeing and approving our cybersecurity strategy and policies.
−Removed: directors receives updates from management on the Company’s cybersecurity status and initiatives and provides guidance and feedback
−Removed: on the cybersecurity goals and objectives.
−Removed: Our board of directors also monitors the Company’s cybersecurity risks and exposures
−Removed: and ensures that the company has adequate cybersecurity resources and capabilities to protect its data and systems.
−Removed: Company leases office space in Vero Beach, Florida for its headquarters operation at less than $100 per month.
+Added: We have reviewed the cybersecurity policies and procedures of our CRO and
+Added: require them to report any cybersecurity breaches or incidents that may affect our data or systems.
+Added: All of the software that we use is Commercial
+Added: Off the Shelf Software (“COTS”) and Microsoft, Dropbox, and Google cloud services.
+Added: We do not develop, modify, or customize
+Added: any software for our own use.
+Added: We rely on the cybersecurity measures and practices of our software and cloud service providers and update
+Added: our software and systems regularly to address any known vulnerabilities or issues.
+Added: We also limit the access and use of our software and
+Added: cloud services to authorized personnel and encourage them to use strong passwords and multifactor authentication.
+Added: We do not store any
+Added: sensitive or confidential data on our own devices or media but use password-protected cloud storage.
+Added: Cybersecurity Oversight and Governance
+Added: The Company’s management is responsible
+Added: for overseeing and managing our cybersecurity risks and activities as part of its overall risk assessment portfolio.
+Added: Our management regularly
+Added: evaluates and reviews the Company’s cybersecurity posture and performance and reports to the board of directors on any material
+Added: cybersecurity matters or developments.
+Added: Our management also coordinates with our CROs, vendors, partners, and other third parties to ensure
+Added: that they comply with our cybersecurity expectations and requirements and to address any cybersecurity issues or concerns that may arise.
+Added: The Company’s board of directors is responsible
+Added: for overseeing and approving our cybersecurity strategy and policies.
+Added: Our board of directors receives updates from management on the Company’s
+Added: cybersecurity status and initiatives and provides guidance and feedback on the cybersecurity goals and objectives.
+Added: Our board of directors
+Added: also monitors the Company’s cybersecurity risks and exposures and ensures that the company has adequate cybersecurity resources
+Added: and capabilities to protect its data and systems.
+Added: The Company leases office space in Vero Beach,
+Added: Florida for its headquarters operation at less than $100 per month.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.