1 unchanged sentence
CYBERSECURITY
−Removed: We have no business operations.
−Removed: Since our IPO, our sole business activity has been identifying and evaluating suitable acquisition transaction candidates.
−Removed: we have not adopted any cybersecurity risk management program or formal processes for assessing cybersecurity risk, which may make us
−Removed: susceptible to heightened cybersecurity risk.
−Removed: Our board of directors is generally responsible for the oversight of risks from cybersecurity
−Removed: threats, if there is any.
−Removed: We have not encountered any cybersecurity incidents since our IPO.
+Added: management and strategy
+Added: recognizes the critical importance of developing, implementing, and maintaining cybersecurity measures designed to safeguard our information
+Added: systems and protect the confidentiality, integrity , and availability of our critical data.
+Added: Material Risks & Integrated Overall Risk Management
+Added: cybersecurity team, led by our IT consultants, identify and assesses risks from cybersecurity threats by monitoring and evaluating our
+Added: threat environment and the Company’s risk profile using various methods including, for example, through third-party threat assessments
+Added: and third-party conducted red/blue team testing and tabletop incident response exercises and by subscribing to reports and services that
+Added: identify cybersecurity threats, analyzing reports of threats and actors, conducting scans of the threat environment, evaluating our and
+Added: our industry’s risk profile, evaluating threats reported to us, conducting threat assessments for internal and external threats
+Added: and conducting vulnerability assessments.
+Added: Our IT consultants provide regular updates to the Company, and all cyber security risks and
+Added: measures are further monitored by Ben Hwang, Chief Executive Officer.
+Added: on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards and policies
+Added: designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including, for example:
+Added: maintaining an incident response plan, a vulnerability management policy, disaster recovery and business continuity plans and a vendor
+Added: risk management program;
+Added: conducting employee training, systems monitoring and penetration testing;
+Added: implementing security standards, network
+Added: security controls, access controls and physical security;
+Added: encrypting and segregating data;
+Added: though asset management, tracking and disposal;
+Added: and maintaining cybersecurity insurance.
+Added: have strategically integrated cybersecurity risk management into our broader risk management framework to promote a culture of cybersecurity
+Added: risk management.
+Added: This integration is designed to make cybersecurity considerations an integral part of our decision-making processes.
+Added: Our risk management team works closely with our IT department and cybersecurity team to evaluate and address cybersecurity risks connected
+Added: with our business objectives and operational needs.
+Added: Third-Parties on Risk Management
+Added: the complexity and evolving nature of cybersecurity threats, Profusa engages with a range of external experts, including cybersecurity
+Added: assessors, consultants, and auditors in evaluating and testing our risk management systems.
+Added: These partnerships enable us to leverage
+Added: specialized knowledge and insights.
+Added: Our collaboration with these third parties includes periodic audits, threat assessments, and consultation
+Added: on security enhancements.
+Added: Third-Party Risk
+Added: we are aware of the potentially material risks from cybersecurity threats associated with third-party service providers, Profusa implements
+Added: processes to oversee and manage these risks.
+Added: Depending on the nature of the services provided and the identity of the service provider,
+Added: we may conduct security assessments of the provider before engagement and may monitor their compliance with our cybersecurity policies
+Added: after engagement.
+Added: The monitoring includes periodic assessments by our Chief Information Security Officer and on an ongoing basis by our
+Added: security specialists.
+Added: This approach is designed to mitigate risks related to data breaches or other security incidents originating from
+Added: third parties.
+Added: from Cybersecurity Threats
+Added: have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially
+Added: However, we face ongoing risks from cybersecurity threats that may materially affect the Company in the future .
+Added: information, see Part I.
+Added: Risk Factors in this Annual Report, including the discussion under the heading “Cybersecurity
+Added: risks and cyber incidents could result in the compromise of confidential data or critical data systems and give rise to potential harm
+Added: to customers, remediation and other expenses, expose us to liability under HIPAA, consumer protection laws, or other common law theories,
+Added: subject us to litigation and federal and state governmental inquiries, damage our reputation, and otherwise be disruptive to our business
+Added: and operations .”.
+Added: Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats.
+Added: Our Board has established
+Added: oversight mechanisms designed to ensure effective governance in managing material risks associated with cybersecurity threats because
+Added: we recognize the significance of these threats to our operational integrity and stakeholder confidence.
+Added: of Directors Oversight
+Added: Audit Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for this domain.
+Added: The Audit Committee is composed of Board members with diverse expertise, including, risk management, technology, and finance.
+Added: Committee reports to the Board of Directors periodically regarding cybersecurity topics presented to the Audit Committee, and all materials
+Added: made available to the Audit Committee are available to rest of the Board of Directors.
+Added: Role Managing Risk
+Added: Chief Executive Officer and Chief Financial Officer play a pivotal role in informing the Audit Committee on cybersecurity risks.
+Added: provide cybersecurity briefings to the Audit Committee on a regular basis, at least once per year.
+Added: These briefings encompass a broad
+Added: range of topics, including as applicable:
+Added: the current cybersecurity landscape and emerging threats, the status of ongoing cybersecurity
+Added: initiatives and strategies, incident reports and learnings from any cybersecurity events, and compliance with regulatory requirements
+Added: and industry practices.
+Added: addition to our scheduled meetings, the Audit Committee, our Chief Executive Officer and Chief Financial Officer maintain an ongoing
+Added: dialogue regarding emerging or potential cybersecurity risks.
+Added: Together, they receive updates from one another, as appropriate, on any
+Added: significant developments in the cybersecurity domain, ensuring the Board’s oversight is proactive and responsive.
+Added: The Audit Committee
+Added: actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives.
+Added: This involvement
+Added: ensures that cybersecurity considerations are integrated into the broader strategic objectives of Profusa.
+Added: The Audit Committee conducts
+Added: an annual review of the company’s cybersecurity posture and the effectiveness of its risk management strategies.
+Added: This review helps
+Added: in identifying areas for improvement and ensuring the alignment of cybersecurity efforts with the overall risk management framework.
+Added: Personnel in Cybersecurity
+Added: responsibility for assessing, monitoring and managing our risks from cybersecurity threats rests with our Chief Executive Officer.
+Added: Chief Executive Officer has overall responsibility for the Company’s IT department and operations, including oversight over the
+Added: cybersecurity team to ensure efforts to contain and remediate security incidents are sufficient and effective.
+Added: Cybersecurity Incidents
+Added: Chief Executive Officer is responsible for staying apprised of the latest developments in cybersecurity, including potential threats
+Added: and innovative risk management techniques.
+Added: The CISO implements and oversees processes for the monitoring of our information systems.
+Added: This includes the deployment of security measures and system audits to identify potential vulnerabilities.
+Added: In the event of a cybersecurity
+Added: incident, the Chief Executive Officer is equipped with a well-defined incident response plan.
+Added: This plan includes immediate actions designed
+Added: to mitigate the impact and long-term strategies for remediation and prevention of future incidents.
+Added: to Board of Directors
+Added: Chief Executive Officer regularly informs our executive management team of material cybersecurity risks and incidents.
+Added: This is how executive
+Added: management is kept abreast of our cybersecurity posture and potentially material cybersecurity risks facing Profusa.
+Added: Furthermore, significant
+Added: cybersecurity matters, and strategic risk management decisions are escalated by any of our executive officers to the Audit Committee,
+Added: so that the Audit Committee can oversee and provide guidance on critical cybersecurity issues .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.