Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
Not applicable.
Item 1C. Cybersecurity.
Risk management and strategy
We have established and maintain various information security processes designed to identify, assess, and manage cybersecurity risks to our critical computer networks, third-party hosted services, communication systems, hardware, software, and vital data, such as intellectual property, confidential proprietary information, strategic assets, and non-clinical and clinical trial data (Information Systems and Data). Our Chief Legal Officer, Vice President of Information Technology, vCISO (Virtual Chief Information Security Officer), cybersecurity business partner, and IT and Legal teams collaborate to address cybersecurity threats and risks, leveraging our risk register and enterprise risk management framework when needed. Our Vice President of Information Technology, vCISO, members of our in-house IT team, and our third-party cybersecurity business partner play an active role in monitoring and assessing risks from cyber threats through a variety of methods including automated tools, third-party testing, tabletop incident response exercises, threat intelligence analysis, industry benchmarking, and collaboration with law enforcement.
We employ a range of measures, processes, standards, and policies tailored to specific environments designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data. These include data encryption at rest and in transit, network security controls, secure physical facilities, employee training, access management, including role based access controls and periodic access reviews, change management and comprehensive asset management, tracking, and disposal procedures.
Periodic access reviews are conducted for systems subject to GxP and Sarbanes Oxley compliance requirements.
Our assessment and management of material risks from cybersecurity threats are integrated into the Company’s overall risk management processes. For example, the security team, which includes our VP of Information Technology, vCISO, and third-party service providers, works with management to prioritize risk management activities and take steps to mitigate cybersecurity threats that are determined to be more likely to lead to a material impact to our business. Key findings and status of the cybersecurity landscape are reviewed with the Audit Committee of our Board of Directors (the Audit Committee), which evaluates our overall enterprise risk. Management evaluates identified cybersecurity risks and incidents to determine whether escalation to executive leadership or the Audit Committee is appropriate.
126
Table of Contents
We engage various categories of third-party service providers to augment our efforts in monitoring, identifying, assessing, and mitigating significant cybersecurity risks. These third-party service providers encompass professional services firms such as legal counsel, cybersecurity consultants, providers of cybersecurity software solutions, managed cybersecurity service providers offering ongoing monitoring and support, external testing firms specializing in penetration testing and vulnerability assessments, and forensic investigators who may be enlisted to conduct investigations and assessments when specific incidents or suspected incidents occur.
We enlist third-party service providers across our business functions, including application providers, hosting companies, contract manufacturers, and supply chain resources. Depending on the service type and data sensitivity, our vendor management process assesses cybersecurity risks and may include contractual provisions addressing data protection and incident notification requirements.
For a description of the risks from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under "Part 1. Item 1A. Risk Factors" in this Annual Report.
Governance
Our Board of Directors retains responsibility for evaluating key business risks faced by the Company, including information security and cybersecurity risks. Our Board of Directors addresses its oversight function in part by delegating the Company's cybersecurity risk oversight to the Audit Committee. The Audit Committee supervises risk mitigation efforts related to cybersecurity threats and evaluates the effectiveness of information security policies and practices.
Our cybersecurity risk assessment and management processes are implemented and maintained by certain members of Company management, including our Vice President of Information Technology, who has over 15 years of experience managing information technology and cybersecurity programs and who reports into our Chief Legal Officer. The Vice President of Information Technology is responsible for hiring appropriate personnel, integrating cybersecurity risk considerations into the Company's overall risk management strategy, and communicating key priorities to relevant personnel. The Chief Legal Officer, together with the Chief Financial Officer, is responsible for approving cybersecurity budgets, supporting preparation for cybersecurity incidents, approving cybersecurity related processes, and reviewing security assessments and other security-related reports.
The Chief Legal Officer also oversees regulatory reporting and disclosure considerations related to cybersecurity incidents.
Our cybersecurity incident response procedures involve escalating specific incidents to certain members of management as needed, including the Vice President of Information Technology, Chief Legal Officer, Chief Financial Officer, and Chief Executive Officer. The Chief Legal Officer collaborates with our incident response team, which includes members of our in-house IT, facilities, human resources, regulatory, legal, and communications teams, to address and resolve reported cybersecurity incidents. Olema’s incident response procedures mandate reporting certain types of cybersecurity incidents to the Audit Committee and external stakeholders, including regulatory authorities, required by law.
The Audit Committee periodically receives reports from the Vice President of Information Technology on the Company's significant cybersecurity threats, risks, mitigation processes, and incident preparedness. The Audit Committee also receives various summaries, presentations, and reports pertaining to cybersecurity threats, risks, and mitigation.
127
Table of Contents