1 unchanged sentence
CYBERSECURITY
−Removed: We believe a robust
−Removed: and proactive approach to cybersecurity risks and threats is essential to achieving our strategic business objectives and protecting
−Removed: our business.
−Removed: We may face a wide range of cybersecurity threats, such as ransomware and denial-of-service attacks.
−Removed: Our customers, suppliers
−Removed: and other business partners may also face similar cybersecurity threats, and a cybersecurity incident impacting us or any of these third
−Removed: parties could have a material adverse effect on our business and results of operations.
−Removed: Due to the risks that cybersecurity threats can
−Removed: pose to our business, we intend to continually evaluate best practices and methods, including cyber defense systems and training programs,
−Removed: to protect our business from a wide range of potential threats.
−Removed: We continue to evaluate
−Removed: our cybersecurity control processes and procedures to address the evolving cybersecurity risks that we may face in an increasingly technically
−Removed: capable environment.
−Removed: We are implementing policies to educate and provide guidance to our personnel, including awareness programs and
−Removed: other related cybersecurity best practices.
−Removed: We plan to conduct technical risk assessments to identify cybersecurity threats, as well
−Removed: as assessments in the event of a material change in our business practices that may affect information systems that are vulnerable to
−Removed: such cybersecurity threats.
−Removed: We also plan to conduct programmatic risk assessments, including identification of reasonably foreseeable
−Removed: internal and external risks, the likelihood and potential damage that could result from such risks, and the sufficiency of existing policies,
−Removed: procedures, systems, and safeguards in place to manage such risks.
+Added: We believe a robust and proactive approach
+Added: to cybersecurity risks and threats is essential to achieving our strategic business objectives and protecting our business.
+Added: a wide range of cybersecurity threats, such as ransomware and denial-of- service attacks.
+Added: Our customers, suppliers and other business
+Added: partners may also face similar cybersecurity threats, and a cybersecurity incident impacting us or any of these third parties could have
+Added: a material adverse effect on our business and results of operations.
+Added: Due to the risks that cybersecurity threats can pose to our business,
+Added: we intend to continually evaluate best practices and methods, including cyber defense systems and training programs, to protect our business
+Added: from a wide range of potential threats.
+Added: We continue to evaluate our cybersecurity control processes and procedures
+Added: to address the evolving cybersecurity risks that we may face in an increasingly technically capable environment.
+Added: We have implemented practices
+Added: and intend to implement policies to educate and provide guidance to our personnel, including awareness programs and other related cybersecurity
+Added: best practices.
+Added: We plan to conduct technical risk assessments to identify cybersecurity threats, as well as assessments in the event of
+Added: a material change in our business practices that may affect information systems that are vulnerable to such cybersecurity threats.
+Added: also plan to conduct programmatic risk assessments, including identification of reasonably foreseeable internal and external risks, the
+Added: likelihood and potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, and
+Added: safeguards in place to manage such risks.
Following these risk assessments, we will evaluate:
−Removed: i) whether and
−Removed: how to implement, and maintain reasonable safeguards to minimize identified risks, ii) how to reasonably address any identified gaps
−Removed: in existing safeguards;
−Removed: and how to regularly monitor the effectiveness of our safeguards.
−Removed: As we are a small pre-revenue company, we currently
−Removed: outsource our information technology (IT) functions to a third party.
−Removed: Working with the outsourced IT firm, our president will manage
−Removed: the risk assessment and mitigation process.
+Added: i) whether and how to implement, and maintain
+Added: reasonable safeguards to minimize identified risks, ii) how to reasonably address any identified gaps in existing safeguards;
+Added: to regularly monitor the effectiveness of our safeguards.
+Added: As we are a small pre-revenue company, we currently outsource our information
+Added: technology (IT) functions to a third party.
+Added: Working with the outsourced IT firm, our president will manage the risk assessment and mitigation
Third parties will play an important role in our cybersecurity program.
−Removed: We intend to engage
−Removed: third-party service providers to conduct evaluations of our security controls, including penetration testing and consulting on best practices.
−Removed: The third-party services include testing both the design and operational effectiveness of security controls.
−Removed: This dependence exposes
−Removed: us, along with others who use such service providers, to the impact of a cyber-attack on their service providers.
−Removed: It is possible for
−Removed: a cyber-attack at a third-party service provider to have a significant financial, operational, or reputational impact to us.
−Removed: the effective impact to us of a cyber-attack on a third-party service provider, we intend to monitor the risks associated with our service
−Removed: providers through periodic review of these providers’ cybersecurity programs.
−Removed: board of directors, through its audit committee, oversees our processes for identifying and mitigating risks, including cybersecurity
−Removed: Management will periodically brief the audit committee and/or the board of directors on our cybersecurity and information security
−Removed: policies and plans.
−Removed: Our board of directors will be apprised of cybersecurity incidents deemed to have a moderate or higher business impact,
−Removed: and we will provide updates on management’s incident response plan for addressing and mitigating any impacts and risks associated
−Removed: with such an incident.
−Removed: We intend to develop a formal incident response plan, which sets forth the steps to be followed from incident
−Removed: detection and assessment to mitigation, recovery and notification and reporting within our organization and to our board of directors.
−Removed: For additional information
−Removed: regarding whether any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect us, including
−Removed: our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this Report,
−Removed: including the risk factor entitled “Third parties might attempt to gain unauthorized access to our network or seek to compromise
−Removed: our insulin pump product.”
+Added: We intend to engage third-party service providers to
+Added: conduct evaluations of our security controls, including penetration testing and consulting on best practices.
+Added: The third-party services
+Added: include testing both the design and operational effectiveness of security controls.
+Added: This dependence exposes us, along with others who
+Added: use such service providers, to the impact of a cyber-attack on their service providers.
+Added: It is possible for a cyber-attack at a third-
+Added: party service provider to have a significant financial, operational, or reputational impact to us.
+Added: To reduce the effective impact to us
+Added: of a cyber-attack on a third-party service provider, we intend to monitor the risks associated with our service providers through periodic
+Added: review of these providers’ cybersecurity programs.
+Added: Our board of directors, through its audit
+Added: committee , oversees our processes for identifying and mitigating risks, including cybersecurity risks.
+Added: Management will periodically brief
+Added: the audit committee and/or the board of directors on our cybersecurity and information security policies and plans.
+Added: Our board of directors
+Added: will be apprised of cybersecurity incidents deemed to have a moderate or higher business impact, and we will provide updates on management’s
+Added: incident response plan for addressing and mitigating any impacts and risks associated with such an incident.
+Added: We intend to develop a formal
+Added: incident response plan, which sets forth the steps to be followed from incident detection and assessment to mitigation, recovery and notification
+Added: and reporting within our organization and to our board of directors.
+Added: For additional information regarding whether
+Added: any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect us, including our business
+Added: strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this Report, including
+Added: the risk factor entitled “Third parties might attempt to gain unauthorized access to our network or seek to compromise our insulin
+Added: pump product.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.