25 unchanged sentences
Management also conducts periodic and on-demand assessments of our cybersecurity risks.
−Removed: Our CCO, is responsible for developing and implementing the cybersecurity
−Removed: risk management program and reporting on cybersecurity matters to the Board.
−Removed: Additionally, members of the third-party service providers
−Removed: have cybersecurity experience and/or certifications.
−Removed: We view cybersecurity as a shared responsibility across our management team and periodically
−Removed: perform simulations and incorporate external resources and advisors as needed.
−Removed: All employees are required to complete cybersecurity training
−Removed: at least annually and have access to more frequent cybersecurity training through online events.
+Added: Our CCO, is responsible for developing and implementing
+Added: the cybersecurity risk management program and reporting on cybersecurity matters to the Board.
+Added: Additionally, members of the third-party
+Added: service providers have cybersecurity experience and/or certifications.
+Added: We view cybersecurity as a shared responsibility across our management
+Added: team and periodically perform simulations and incorporate external resources and advisors as needed.
+Added: All employees are required to complete
+Added: cybersecurity training at least annually and have access to more frequent cybersecurity training through online events.
The CCO is responsible for continuously monitoring
2 unchanged sentences
To operate our business, we utilize certain third-party
−Removed: service providers to perform a variety of functions, such as outsourced business critical functions, clinical research, professional services,
−Removed: SaaS platforms, cloud-based infrastructure, encryption and other functions.
−Removed: We have certain vendor management processes designed to help
−Removed: to manage cybersecurity risks associated with our use of these providers.
−Removed: Depending on the nature of the services provided, and the sensitivity
−Removed: and quantity of information processed, our vendor management process may include reviewing the cybersecurity practices of such provider,
−Removed: contractually imposing obligations on the provider related to the services they provide and/or the information they process, conducting
−Removed: security assessments, conducting on-site inspections, requiring their completion of written questionnaires regarding their services and
−Removed: data handling practices, and conducting periodic re-assessments during their engagement.
+Added: service providers to perform a variety of functions, such as outsourced business critical functions, clinical research, professional
+Added: services, SaaS platforms, cloud-based infrastructure, encryption and other functions.
+Added: We have certain vendor management processes designed
+Added: to help to manage cybersecurity risks associated with our use of these providers.
+Added: Depending on the nature of the services provided, and
+Added: the sensitivity and quantity of information processed, our vendor management process may include reviewing the cybersecurity practices
+Added: of such provider, contractually imposing obligations on the provider related to the services they provide and/or the information they
+Added: process, conducting security assessments, conducting on-site inspections, requiring their completion of written questionnaires regarding
+Added: their services and data handling practices, and conducting periodic re-assessments during their engagement.
We have not experienced any material cybersecurity
3 unchanged sentences
of our internal controls and processes, which are designed to help protect our systems and data, and the information they contain.
−Removed: carry insurance in amounts that we believe are reasonable for our business that provides protection against potential losses arising from
−Removed: a cybersecurity incident.
−Removed: However, there is no assurance that our insurance coverage will cover or be sufficient to cover all losses or
−Removed: claims that may arise from a cybersecurity incident.
+Added: carry insurance in amounts that we believe are reasonable for our business that provides protection against potential losses arising
+Added: from a cybersecurity incident.
+Added: However, there is no assurance that our insurance coverage will cover or be sufficient to cover all losses
+Added: or claims that may arise from a cybersecurity incident.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.