3 unchanged sentences
We face a number of cybersecurity risks in connection with our business and recognize the growing threat within the general marketplace and our industry.
−Removed: To help the Company address these risks, we have implemented a cybersecurity risk management program that is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework.
+Added: To help address these risks, we have implemented a cybersecurity risk management program that is informed by recognized industry standards and frameworks and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework.
Our cybersecurity risk management program is integrated within our enterprise risk management program.
9 unchanged sentences
The Audit Committee of our Board of Directors oversees cybersecurity risks pursuant to its charter, and our governance framework includes oversight by the Audit Committee.
−Removed: The Audit Committee, with assistance from our management, including our Head of Information Technology (“IT”), periodically reports to the full Board of Directors to inform them of potential cybersecurity risks and threats, the status of projects to further develop our information security systems, and the emerging cybersecurity threat landscape .
+Added: The Audit Committee, with assistance from our management, including our Head of Information Technology (“IT”), periodically reports to the full Board of Directors to inform them of potential
+Added: cybersecurity risks and threats, the status of projects to further develop our information security systems, and the emerging cybersecurity threat landscape .
Our Head of IT has primary responsibility for day-to-day management of our cybersecurity risk management program , including leading a dedicated team of IT professionals to monitor and assess cybersecurity risks, and is responsible for strategic leadership of our cybersecurity risk management program.
The Head of IT role is currently held by an individual who has close to twenty years of professional IT management experience in the life sciences industry.
−Removed: Our Head of IT also provides regular updates on
−Removed: our cybersecurity risk to our executive leadership team and other management committees responsible for IT and cybersecurity risk management.
+Added: Our Head of IT also provides regular updates on our cybersecurity risk to our executive leadership team and other management committees responsible for IT and cybersecurity risk management.
Under our CSIRP and other applicable policies and procedures, we have established a framework for responding to cybersecurity incidents based on severity of the incident, which includes escalation to our executive leadership team and other management committees and assessment of materiality of cybersecurity incidents individually and in the aggregate .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.