3 unchanged sentences
Risk management and strategy
−Removed: We have established and maintain various information security processes designed to identify, assess, and manage cybersecurity risks to our critical computer networks, third-party hosted services, communication systems, hardware, software, and vital data, such as intellectual property, confidential proprietary information, strategic assets, and nonclinical/clinical trial data (“Information Systems and Data”).
−Removed: Our Chief Operating and Financial Officer, Vice President of Information Technology, cybersecurity business partner and IT & Legal teams collaborate to address cybersecurity threats and risks, leveraging our risk register when needed.
−Removed: Our VP of Information Technology, members of our in-house IT team, and our third-party cybersecurity business partner all play an active role in monitoring and assessing risks from cyber threats through a variety of methods including automated tools, third-party testing, tabletop incident response exercises, threat actor analysis, industry risk profiling, and collaboration with law enforcement.
+Added: We have established and maintain various information security processes designed to identify, assess, and manage cybersecurity risks to our critical computer networks, third-party hosted services, communication systems, hardware, software, and vital data, such as intellectual property, confidential proprietary information, strategic assets, and non-clinical/clinical trial data (Information Systems and Data).
+Added: Our Chief Operating and Financial Officer, Vice President of Information Technology, vCISO (Virtual Chief Information Security Officer), cybersecurity business partner and IT & Legal teams collaborate to address cybersecurity threats and risks, leveraging our risk register when needed.
+Added: Our VP of Information Technology, vCISO, members of our in-house IT team, and our third-party cybersecurity business partner all play an active role in monitoring and assessing risks from cyber threats through a variety of methods including automated tools, third-party testing, tabletop incident response exercises, threat actor analysis, industry risk profiling, and collaboration with law enforcement.
We employ a range of measures, processes, standards, and policies tailored to specific environments designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data.
1 unchanged sentence
Our assessment and management of material risks from cybersecurity threats are integrated into the Company’s overall risk management processes.
−Removed: For example, the security team, which includes our VP of Information Technology and third-party service providers, works with management to prioritize our risk management processes and take steps to mitigate cybersecurity threats that are determined to be more likely to lead to a material impact to our business.
−Removed: Key findings and status of the cybersecurity landscape are reviewed with the Audit Committee of our Board of Directors, or Audit Committee, which evaluates our overall enterprise risk.
+Added: For example, the security team, which includes our VP of Information Technology, vCISO, and third-party service providers, works with management to prioritize our risk management processes and take steps to mitigate cybersecurity threats that are determined to be more likely to lead to a material impact to our business.
+Added: Key findings and status of the cybersecurity landscape are reviewed with the Audit Committee of our Board of Directors (the Audit Committee), which evaluates our overall enterprise risk.
We engage various categories of third-party service providers to augment our efforts in monitoring, identifying, assessing, and mitigating significant cybersecurity risks.
16 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.