7 unchanged sentences
We partner with external cybersecurity vendors to enact a layered defense approach with controls deployed that seek to meet the requirements of the NIST Cybersecurity Framework.
−Removed: Our Chief Financial Officer has served as a biotechnology executive for 20 years, whose responsibilities have included direct oversight of his companies’ cybersecurity risks.
−Removed: Our Senior Director, Head of IT has served as an Information Technology professional for over ten years and has held senior IT positions across several companies including a large pharmaceutical company.
+Added: Our Chief Financial Officer has served as a biotechnology executive for over 20 years, whose responsibilities have included direct oversight of his companies’ cybersecurity risks.
+Added: Our Senior Director, Head of IT has served as an Information Technology professional for over fifteen years and has held senior IT positions across several companies including a large pharmaceutical company.
We have established policies and processes for assessing, identifying, and managing material risk from cybersecurity threats, and have integrated these processes into our overall risk management systems and processes.
2 unchanged sentences
In the event of a major security incident, we have established an escalation path for stakeholder notification and remediation efforts, and major incidents are immediately escalated to the Head of IT, Chief Financial Officer, and Chief Operations Officer.
−Removed: In 2024, we proactively conducted a thorough and robust cybersecurity assessment, performed by an external cybersecurity partner, to evaluate our risks and identify key areas to improve our cybersecurity posture.
−Removed: We have implemented processes when evaluating third-party service providers, for example by reviewing available audit reports including the System and
−Removed: Organization Controls (SOC 2) reports and requesting disclosure of any previous cybersecurity events.
−Removed: We also perform quality audits of certain regulated vendors, which includes an assessment of the vendor’s information technology system and associated controls.
+Added: In 2024, an external partner conducted a robust cybersecurity assessment to evaluate our risk profile.
+Added: We are leveraging these insights to strengthen our key defenses and continuously mature our security posture.
+Added: We have implemented processes when evaluating third-party service providers, for example by reviewing available audit reports including the System and Organization Controls (SOC 2) reports and requesting disclosure of any previous cybersecurity events.
+Added: We also perform quality audits of our regulated vendors, which includes an assessment of the vendor’s information technology system and associated controls.
Additionally, we conduct periodic risk assessments to identify and monitor against potential cybersecurity threats and incidents, as well as assess for any changes in our business practices that may affect our cybersecurity position.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.