UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
CYBERSECURITY
−Removed: We operate in the biotechnology
−Removed: sector, which is subject to various cybersecurity risks that could adversely affect our business, financial condition, and results of
−Removed: operations, including intellectual property theft;
−Removed: harm to customers and/or corporate partners or customers;
−Removed: of privacy laws and other litigation and legal risk;
+Added: operate in the biotechnology sector, which is subject to various cybersecurity risks that could adversely affect our business, financial
+Added: condition, and results of operations, including intellectual property theft;
+Added: harm to customers and/or corporate partners
+Added: or customers;
+Added: violation of privacy laws and other litigation and legal risk;
and reputational risk.
−Removed: We have implemented
−Removed: various security measures to identify and assess the cybersecurity threats that could affect our business and information systems.
−Removed: use various tools and methodologies to manage cybersecurity risk that are tested on a regular cadence.
−Removed: We also monitor and evaluate our
−Removed: cybersecurity posture and performance on an ongoing basis through regular vulnerability scans, penetration tests and threat intelligence
−Removed: We require third-party service providers with access to personal, confidential or proprietary information to implement and maintain
−Removed: comprehensive cybersecurity practices consistent with applicable legal standards and industry best practices.
−Removed: Our business depends
−Removed: on the availability, reliability, and security of our information systems, networks, data, and intellectual property.
−Removed: Any disruption,
−Removed: compromise, or breach of our network systems or infrastructure due to a cybersecurity threat or incident could adversely affect our operations,
−Removed: serviced, product development, and competitive position.
−Removed: They may also result in a breach of our contractual obligations or legal duties
−Removed: to protect the privacy and confidentiality of our customers’ and partners’ proprietary information, which may include personally
−Removed: identifiable information.
−Removed: Such a breach could expose us to business interruption, lost revenue, ransom payments, remediation costs, liabilities
−Removed: to affected parties, cybersecurity protection costs, lost assets, litigation, regulatory scrutiny and actions, reputational harm, customer
−Removed: dissatisfaction and harm to our relationships with corporate partners.
−Removed: We are currently in the process of implementing
−Removed: a more formalized cybersecurity program.
+Added: have implemented various security measures to identify and assess the cybersecurity threats that could affect our business and information
+Added: We use various tools and methodologies to manage cybersecurity risk that are tested on a regular cadence.
+Added: We also monitor and
+Added: evaluate our cybersecurity posture and performance on an ongoing basis through regular vulnerability scans, penetration tests and threat
+Added: intelligence feeds.
+Added: We require third-party service providers with access to personal, confidential or proprietary information to implement
+Added: and maintain comprehensive cybersecurity practices consistent with applicable legal standards and industry best practices.
+Added: Risk management is further managed through
+Added: the use of an expert third party company to assist in managing relevant risks.
+Added: We outsource our monitoring to a third-party provider
+Added: whereby we benefit from a professionally managed network monitoring, management, maintenance, detection and response system and a
+Added: 24/7 security operations center with both onsite and remote support services.
+Added: Any cybersecurity incident would be reported to us
+Added: promptly by our third-party provider and material and potentially material incidents would be assessed by management for remediation
+Added: and future prevention and detection.
+Added: business depends on the availability, reliability, and security of our information systems, networks, data, and intellectual property.
+Added: Any disruption, compromise, or breach of our network systems or infrastructure due to a cybersecurity threat or incident could adversely
+Added: affect our operations, services, product development, and competitive position.
+Added: They may also result in a breach of our contractual obligations
+Added: or legal duties to protect the privacy and confidentiality of our customers’ and partners’ proprietary information, which
+Added: may include personally identifiable information.
+Added: Such a breach could expose us to business interruption, lost revenue, ransom payments,
+Added: remediation costs, liabilities to affected parties, cybersecurity protection costs, lost assets, litigation, regulatory scrutiny and
+Added: actions, reputational harm, customer dissatisfaction and harm to our relationships with corporate partners.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.