3 unchanged sentences
We operate in the biotechnology
−Removed: field, which is subject to various cybersecurity risks that could adversely affect our business.
−Removed: We engage in the periodic assessment
−Removed: and testing of our policies, standards, processes and practices that are designed to address cybersecurity risks.
−Removed: These efforts include
−Removed: a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing, and other exercises
−Removed: focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: We regularly engage third parties to perform assessments
−Removed: on our cybersecurity measures, including information security maturity assessments, audits and independent reviews of our information
−Removed: security control environment and operating effectiveness.
−Removed: The results of such assessments, audits and reviews are reported to the Audit
−Removed: Committee and we adjust our cybersecurity policies, standards, processes and practices as necessary based on the information provided
−Removed: by these assessments, audits and reviews.
−Removed: Our Chief Information Officer,
−Removed: or CIO, is responsible for day-to-day assessment, management of risks from cybersecurity threats our cybersecurity policies, standards,
−Removed: processes and practices which are based on applicable industry standards.
−Removed: In general, we seek to address cybersecurity risks through a
−Removed: comprehensive, cross-functional approach that is focused on preserving the confidentiality, security and availability of the information
−Removed: that we collect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity
−Removed: incidents when they occur.
−Removed: While we have experienced a cybersecurity incident in the past (see
−Removed: Risk Factors - “A cybersecurity incident, other technology disruptions or failure to comply with laws and regulations relating to
−Removed: privacy and the protection of data relating to individuals could negatively impact our business and our reputation.”) and cybersecurity
−Removed: threats in the past in the normal course of business and expect to continue to experience such threats from time to time, to date, none
−Removed: have had a material adverse effect on our business, financial condition, results of operations or cash flows.
−Removed: Even with the approach we
−Removed: take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse
−Removed: effect on us.
+Added: industry, where the protection of sensitive information and the continuity of our operations are critical.
+Added: We are subject to cybersecurity
+Added: risks which could adversely affect our business, financial condition, or results of operations.
+Added: We maintain a risk-based cybersecurity
+Added: program designed to identify, assess, and mitigate cybersecurity threats.
+Added: Our program incorporates applicable industry standards and
+Added: is managed through a cross-functional approach involving our Information Technology, legal, compliance, and other relevant teams.
+Added: is overseen by our Chief Information Officer (“CIO”), who is responsible for the day-to-day management of cybersecurity risks
+Added: and the implementation of our information security program and incident response plans.
+Added: Our risk management activities
+Added: include periodic assessments, vulnerability testing, and tabletop exercises, as well as regular engagement with third-party experts to
+Added: perform independent security assessments.
+Added: We have expanded employee training and phishing simulations, and we conduct ongoing monitoring
+Added: of access to our systems, including oversight of third-party vendors and service providers.
+Added: The results of assessments and reviews are
+Added: reported to senior management and the Audit Committee, and our policies and controls are updated as necessary.
+Added: While we have experienced
+Added: a cybersecurity incident in the past and encounter cybersecurity threats from time to time in the ordinary course of business, none to
+Added: date have had a material adverse effect on our business, financial condition, results of operations or cash flows.
+Added: Despite our proactive
+Added: measures, including expanded employee training and enhanced vendor oversight, cybersecurity threats continue to evolve, and no system
+Added: can be entirely secure.
+Added: A future cybersecurity incident could materially impact our operations, financial results, or reputation.
Risk Management and Strategy
−Removed: As part of our overall risk
−Removed: management, our cybersecurity program is focused on a comprehensive approach to identifying, preventing and mitigating cybersecurity threats
−Removed: and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents
−Removed: so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner.
−Removed: The Company deploys technical
−Removed: safeguards that are designed to protect the Company’s information systems from cybersecurity threats, including firewalls, intrusion
−Removed: prevention and detection systems, anti-malware functionality and access controls, which are evaluated and improved through vulnerability
−Removed: assessments and cybersecurity threat intelligence.
−Removed: The Company has established
−Removed: and maintains comprehensive incident response and recovery plans that fully address the Company’s response to a cybersecurity incident,
−Removed: and such plans are tested and evaluated on a regular basis.
−Removed: The Company maintains a comprehensive,
−Removed: risk-based approach to identifying and overseeing cybersecurity risks presented by third parties, including vendors, CROs, service providers
−Removed: and other external users of the Company’s systems, as well as the systems of third parties that could adversely impact our business
−Removed: in the event of a cybersecurity incident affecting those third-party systems.
−Removed: The Audit Committee oversees
−Removed: our risk management process, including the management of risks arising from cybersecurity threats.
−Removed: Our CIO is tasked with reporting any
−Removed: and all matters relating to cybersecurity to the Audit Committee.
−Removed: The Audit Committee receives regular presentations and reports on cybersecurity
−Removed: risks, which including recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat
−Removed: environment, technological trends and information security considerations arising with respect to our peers and third parties.
−Removed: Committee receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as
−Removed: well as ongoing updates regarding any such incident until it has been addressed.
+Added: As part of our overall
+Added: risk management framework, our cybersecurity program takes a comprehensive, layered approach to identifying, preventing and mitigating
+Added: cybersecurity threats and incidents.
+Added: This includes implementing controls and escalation procedures to ensure that significant incidents
+Added: are promptly communicated to management for timely decision-making regarding public disclosure and regulatory reporting.
+Added: We deploy multiple
+Added: technical safeguards designed to protect our information systems, including firewalls, intrusion prevention and detection systems, anti-malware
+Added: tools, access controls, and continuous monitoring.
+Added: These safeguards are evaluated and enhanced through regular vulnerability assessments,
+Added: penetration testing and ongoing cybersecurity threat intelligence.
+Added: We maintain formal
+Added: incident response and recovery plans that define our procedures for addressing cybersecurity incidents.
+Added: These plans are tested, updated,
+Added: and refined on a regular basis to ensure readiness.
+Added: We apply a risk-based
+Added: approach to managing cybersecurity risks posed by third parties , including vendors, contract research organizations, service providers
+Added: and other external users of the our systems.
+Added: This also includes assessing and overseeing risks related to third-party systems that, if
+Added: compromised, could negatively impact our business operations.
+Added: The Audit Committee
+Added: of our Board oversees our risk management process, including the management of risks from cybersecurity threats.
+Added: Oren Kochavi,
+Added: is an accomplished executive with 14 years of experience leading information technology, enterprise systems, information security, and
+Added: related technology functions.
+Added: Kochavi holds an MBA in Business Administration and multiple professional certifications, and is responsible
+Added: for the day-to-day administration of our cybersecurity program and reports to the Audit Committee on cybersecurity matters.
+Added: Committee receives periodic reports and presentations addressing cybersecurity risks, recent developments, evolving standards, results
+Added: of vulnerability assessments, findings from third-party and independent reviews, current threat intelligence, technological trends, and
+Added: relevant developments regarding security considerations arising with respect to our peers and third parties.
+Added: According to our procedures,
+Added: the Audit Committee is promptly informed of any cybersecurity incident that meets established reporting thresholds and receives ongoing
+Added: updates until the matter is fully resolved.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.