Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS.
Not Applicable.
33
ITEM
1C. CYBERSECURITY
We operate in the biotechnology
field, which is subject to various cybersecurity risks that could adversely affect our business. We engage in the periodic assessment
and testing of our policies, standards, processes and practices that are designed to address cybersecurity risks. These efforts include
a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing, and other exercises
focused on evaluating the effectiveness of our cybersecurity measures and planning. We regularly engage third parties to perform assessments
on our cybersecurity measures, including information security maturity assessments, audits and independent reviews of our information
security control environment and operating effectiveness. The results of such assessments, audits and reviews are reported to the Audit
Committee and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided
by these assessments, audits and reviews.
Our Chief Information Officer,
or CIO, is responsible for day-to-day assessment, management of risks from cybersecurity threats our cybersecurity policies, standards,
processes and practices which are based on applicable industry standards. In general, we seek to address cybersecurity risks through a
comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information
that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity
incidents when they occur.
While we have experienced a cybersecurity incident in the past (see
Risk Factors - “A cybersecurity incident, other technology disruptions or failure to comply with laws and regulations relating to
privacy and the protection of data relating to individuals could negatively impact our business and our reputation.”) and cybersecurity
threats in the past in the normal course of business and expect to continue to experience such threats from time to time, to date, none
have had a material adverse effect on our business, financial condition, results of operations or cash flows. Even with the approach we
take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse
effect on us.
Risk Management and Strategy
As part of our overall risk
management, our cybersecurity program is focused on a comprehensive approach to identifying, preventing and mitigating cybersecurity threats
and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents
so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
The Company deploys technical
safeguards that are designed to protect the Company’s information systems from cybersecurity threats, including firewalls, intrusion
prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability
assessments and cybersecurity threat intelligence.
The Company has established
and maintains comprehensive incident response and recovery plans that fully address the Company’s response to a cybersecurity incident,
and such plans are tested and evaluated on a regular basis.
The Company maintains a comprehensive,
risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, CROs, service providers
and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business
in the event of a cybersecurity incident affecting those third-party systems.
34
Governance
The Audit Committee oversees
our risk management process, including the management of risks arising from cybersecurity threats. Our CIO is tasked with reporting any
and all matters relating to cybersecurity to the Audit Committee. The Audit Committee receives regular presentations and reports on cybersecurity
risks, which including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat
environment, technological trends and information security considerations arising with respect to our peers and third parties. The Audit
Committee receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as
well as ongoing updates regarding any such incident until it has been addressed.