1 unchanged sentence
Cybersecurity
−Removed: We recognize the critical importance of maintaining the trust and confidence of all of our stakeholders.
−Removed: Our business depends on the efficient and uninterrupted operation of our information technology systems and those of our third-party vendors.
−Removed: Our board of directors is actively involved in oversight of our risk management program, and cybersecurity represents an important component of our risk management and compliance program.
−Removed: Our cybersecurity policies, standards, processes and practices are fully integrated into the Company’s enterprise-wide risk management and compliance program and overseen by the Audit Committee, and are based on recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards .
−Removed: In general, we seek to address cybersecurity risks through a comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents when they occur .
+Added: We maintain a cybersecurity risk management program designed to identify, assess, and manage material risks arising from cybersecurity threats.
+Added: Our program incorporates elements of widely adopted industry cybersecurity frameworks standards and includes processes for threat monitoring, vulnerability and patch management, incident detection and response, security awareness training, and business continuity planning.
+Added: Our information systems support clinical trial operations, research and development activities, manufacturing collaborations, and corporate functions and include sensitive clinical data, research data, and intellectual property.
+Added: We conduct periodic risk assessments to evaluate emerging threats and potential impacts to our research, clinical, manufacturing, and corporate systems.
+Added: These assessments inform our technical and administrative safeguards, which include identity and access controls, network segmentation, encryption, logging, and continuous monitoring.
+Added: We also maintain an incident response plan and conduct tabletop exercises to evaluate readiness.
Risk Management and Strategy
2 unchanged sentences
Collaborative Approach :
−Removed: We have implemented a comprehensive, cross-functional approach to identifying, preventing and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
+Added: We have implemented a comprehensive, cross-functional approach for monitoring, identifying, preventing, detecting, and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
+Added: Administrative Safeguards :
+Added: We maintain a comprehensive set of administrative safeguards designed to govern the oversight, implementation, and continuous improvement of our cybersecurity program.
+Added: These safeguards include detailed policies and procedures and ongoing employee training to ensure security is embedded in daily activities.
+Added: We engage in periodic assessment of our policies, standards, processes and practices that are designed to address cybersecurity threats and incidents.
+Added: These efforts include a wide range of activities, including audits, assessments, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity program and corresponding controls.
+Added: The results of such assessments, audits and reviews are reported to the Audit Committee and the board of directors, and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the insights gained from the assessments, audits and reviews.
Technical Safeguards :
−Removed: We deploy technical safeguards that are designed to protect our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, Security Information and Event Management systems, Extended Detection and Response with 24/7 Security Operations Center , anti-malware functionality and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence .
+Added: We maintain a layered set of technical safeguards to protect the confidentiality, integrity, availability, and privacy of our systems and data.
+Added: Key controls include firewalls, network segmentation, intrusion detection and prevention, multi-factor authentication, encryption, anti-malware, endpoint protection, real-time threat intelligence and mitigation, and 24/7 logging, monitoring, and response.
Incident Response and Recovery Planning :
1 unchanged sentence
Third-Party Risk Management :
−Removed: We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, service providers and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
+Added: We maintain a risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, contract research organizations, contract development
+Added: and manufacturing organizations, technology service providers and other third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
Education and Awareness :
−Removed: We provide regular, mandatory training for personnel regarding cybersecurity threats as a means to equip our employees with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices.
+Added: We provide regular, mandatory training for personnel regarding cybersecurity threats as a means of providing our employees with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices.
We also perform periodic email phishing tests to keep cybersecurity awareness top of mind.
−Removed: We engage in the periodic assessment of our policies, standards, processes and practices that are designed to address cybersecurity threats and incidents.
−Removed: These efforts include a wide range of activities, including audits, assessments, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: The results of such assessments, audits and reviews are reported to the Audit Committee and the board of directors, and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided by these assessments, audits and reviews.
The board of directors, with leadership from the Audit Committee, oversees our cybersecurity risk management process.
The Audit Committee receives regular presentations and reports on cybersecurity risks, which address a wide range of topics including recent developments, evolving standards, vulnerability assessments, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
−Removed: The board of directors and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: The board of directors and the Audit Committee also receive prompt and timely information regarding any cybersecurity incident that meets established escalation and materiality thresholds consistent with applicable SEC reporting requirements, as well as ongoing updates regarding any such incident until it has been addressed.
On a periodic basis, the board of directors, through the Audit Committee, discuss our approach to cybersecurity risk management with management.
Our management team has implemented a program designed to protect our information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with our incident response and recovery plans.
−Removed: Through ongoing communications with our entire employee base and appropriate third-party contractors, the management team monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
−Removed: Our enterprise risk management team consists of cross-functional professionals who collaborate with subject matter specialists, as necessary, including an independent third-party expert we have retained to identify and assess material risks from cybersecurity threats, their severity, and potential mitigation steps.
−Removed: Our Chief Financial Officer, Kathleen Borthwick, currently serves as our Chief Cybersecurity Officer and leads our cybersecurity risk assessment and management processes.
−Removed: Prior to being named CFO, Ms.
−Removed: Borthwick served as the Company’s Senior Vice President, Finance, and interim CFO.
−Removed: She is supported by external Information Technology and third-party internal audit personnel who regularly review and assess cybersecurity initiatives, including our incident response plan, as well as cybersecurity compliance, training, and risk management efforts.
−Removed: No cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to affect us, including our business strategy, results of operations or financial condition.
+Added: Through ongoing communications with our entire employee base and appropriate third-party contractors, the management team oversees the prevention, detection, mitigation and remediation of cybersecurity threats and incidents through risk-based monitoring and periodic reporting to the Audit Committee when appropriate.
+Added: Our enterprise risk management team consists of the Executive team and cross-functional professionals who collaborate with subject matter specialists, as necessary, including an independent third-party expert we have retained to identify and assess material risks from cybersecurity threats, their severity, and potential mitigation steps.
+Added: Technical experts at our Managed Security Services Provider, or MSSP, also provide technical support and monitoring services under the oversight of management of our Company cybersecurity program, leveraging real-time threat intelligence and mitigation tools .
+Added: As of the date of this filing, we have not experienced a cybersecurity incident that we have determined to be material to our business, operations, or financial condition.
+Added: However, we continue to monitor and enhance our cybersecurity capabilities in response to evolving threats.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.