Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
We recognize the importance of protecting the confidentiality , integrity, and availability of our information systems and the data residing on them. As a clinical-stage biopharmaceutical company, we handle sensitive information, including proprietary research data, clinical trial data, and personal information of clinical trial participants. Although our current operations are relatively limited in scale, we have implemented cybersecurity risk management practices designed to be commensurate with our risk profile and stage of development, under the oversight of our Board of Directors and Audit Committee.
Cybersecurity Risk Management and Strategy
We consider cybersecurity risks alongside other company risks as part of our overall enterprise risk assessment process. Given our size and stage of development, we rely on a combination of internal controls and contracted third-party managed security service providers to implement and maintain our cybersecurity program.
122
Our cybersecurity program includes, among other things, the following activities:
●
employing technical safeguards designed to protect our information systems from cybersecurity threats, including firewalls, device encryption, multi-factor authentication, advanced threat protection for email, and access controls, which are evaluated and updated from time to time;
●
monitoring our networks and endpoints through our third-party managed security service provider to identify, assess, and respond to potential cybersecurity threats and vulnerabilities on an ongoing basis;
●
maintaining data backup systems with backup data stored in secure, off-site or cloud-based locations to support business continuity in the event of a cybersecurity incident; and
●
requiring employees and third-party service providers who handle our data to treat confidential information with appropriate care.
Use of Third-Party Service Providers
We engage third-party service providers, including contract research organizations (“CROs”), contract manufacturing organizations (“CMOs”), clinical sites, and information technology vendors, that may have access to our systems or data. We evaluate such third-party service providers from a cybersecurity risk perspective prior to engagement and, where appropriate, include contractual provisions requiring such providers to maintain appropriate security standards. Our third-party managed security service provider monitors our systems and provides ongoing support for threat detection, incident response, and vulnerability management.
Incident Response
We maintain a cybersecurity incident response process designed to prepare for, detect, contain, and remediate cybersecurity incidents in a timely manner. Cybersecurity incidents that meet certain severity thresholds are escalated to our senior management and, as appropriate, to our Audit Committee and Board of Directors. Our incident response process is periodically reviewed and, where appropriate, tested through tabletop exercises or other simulated incident scenarios to assess our readiness.
We face risks from cybersecurity threats that include our operations, business strategy, results of operations, or financial condition. During the reporting period, we have not identified any cybersecurity incidents or threats that we believe have materially affected , or are reasonably likely to materially affect, our business strategy, results of operations, or financial condition.
Cybersecurity Governance
Our Board of Directors considers cybersecurity risks as part of its broader risk oversight function and has delegated primary oversight responsibility for cybersecurity and information technology risks to our Audit Committee. The Audit Committee receives periodic updates from management regarding our cybersecurity program and any material cybersecurity risks or incidents, as well as the steps management has taken or proposes to take in response. The Audit Committee is also encouraged to engage with management on cybersecurity-related developments, including updates to applicable regulatory requirements and evolving industry standards. The Audit Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity oversight.
Our
cybersecurity program is overseen at the management
level by the finance department, who is responsible for managing our relationship with our contracted third-party managed security service
provider and for overseeing our cybersecurity policies and procedures. The
third-party security service provider is based in southern California and was selected based on their depth of experience in
providing IT consulting services, security and cloud services. Our management team reviews and assesses
reports of cybersecurity risks or incidents provided by our third-party managed security service provider and to evaluate potential
enhancements to our cybersecurity program, with input from third-party vendors and professional services firms as appropriate.
Our third-party managed security service provider has extensive experience in cybersecurity, is informed about our cybersecurity risk profile, and participates actively in our cybersecurity risk management and strategy processes described above. Our General Counsel reports to the Audit Committee periodically regarding cybersecurity matters, and promptly in the event of any significant cybersecurity incident.
123