3 unchanged sentences
The secure maintenance of this information and our information technology systems is important to our operations and business strategy.
−Removed: To this end, we have implemented processes designed to assess, identify, and manage risks from potential unauthorized occurrences on or through our information technology systems that may result in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing therein.
+Added: To this end, we have implemented processes designed
+Added: to help assess, identify, and manage risks from potential unauthorized occurrences on or through our information technology systems that may result in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing therein.
These processes are managed and monitored by dedicated information technology resources, including both company and consultant personnel, and led by our Chief Business Officer.
−Removed: The processes include mechanisms, controls, technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable information technology environment.
+Added: The processes include mechanisms, controls, technologies, systems, and other processes designed to help prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and help maintain a stable information technology environment.
For example, we conduct penetration and vulnerability testing, data recovery testing, security audits, and ongoing risk assessments of our IT environment.
4 unchanged sentences
We consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework evaluated at least quarterly.
−Removed: In the last fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect us.
+Added: Since the beginning of the last fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect us.
Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors,” under the heading “Our information technology systems, or those used by our CROs or other contractors or consultants, may fail or suffer security breaches, which could materially and adversely affect our business.”
−Removed: The Board of Directors, as whole and at the committee level, has oversight for the most significant risks facing us and on our processes to identify, prioritize, assess, manage, and mitigate those risks.
+Added: The Board of Directors, as whole and at the committee level, has oversight for the most significant risks facing us and on our processes to help identify, prioritize, assess, manage, and mitigate those risks.
The Audit Committee, which is comprised solely of independent directors, reviews cybersecurity risks.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.