9 unchanged sentences
The CIRP identifies the individuals responsible for developing, maintaining, and following procedures related to cybersecurity incident response, including escalation protocols.
−Removed: We also engage external third-party consultants to provide services, such as penetration testing, which is conducted on an annual basis, and periodic vulnerability assessments.
+Added: We also engage external third-party consultants to provide services, such as penetration testing, which is conducted on an annual basis, along with ongoing vulnerability scans.
These consultants also perform annual assessments of our cybersecurity program, which involve, among other things, review of our IT security measures and processes for alignment with the NIST Cybersecurity Framework and provision of threat intelligence regarding emerging risks to our information systems.
3 unchanged sentences
We may, from time to time, experience threats to and security incidents related to our data systems but we do not believe they are reasonably likely to materially affect our business strategy, results of operations or financial condition.
−Removed: For more information, please see the risk factors entitled “Our internal computer systems, or those used by our third-party CROs or other contractors or consultants, may fail or suffer security breaches or other unauthorized or improper access, which could result in a material disruption of the development programs of our product candidates” and “Security incidents, loss of data or modification of information, and other disruptions could compromise information related to our business or prevent us from accessing critical information, result in a significant disruption of our activities and expose us to liability, which could adversely affect our business and our reputation” in Item 1A- Risk Factors in this Annual Report.
+Added: For more information, please see the risk factors entitled “Our internal computer systems, or those used by our third-party CROs or other contractors or consultants, may fail or suffer cybersecurity incidents, data breaches or other unauthorized or improper access, which could result in a material disruption of the development programs of our product candidates” and “Cybersecurity incidents, loss of data or modification of information, and other disruptions could compromise information related to our business or prevent us from accessing critical information, result in a significant disruption of our activities and expose us to liability, which could adversely affect our business and our reputation” in Item 1A- Risk Factors in this Annual Report on Form 10-K.
Our Head of Information Technology and Security, or Head of IT, has primary responsibility for day-to-day management of our cybersecurity risk management program, including leading a dedicated team of information technology professionals to monitor cybersecurity risks on behalf of TScan.
2 unchanged sentences
If an incident arises, the Head of IT notifies our Chief Legal and Compliance Officer, and Chief Financial Officer, who will raise issues to those charged with governance, as appropriate.
+Added: Our board of directors, as a whole and through its committees, is responsible for our overall enterprise risk management program, which incorporates as an element our cybersecurity risk management program.
Our audit committee, a subcommittee of our board of directors, has been delegated responsibility for oversight of cybersecurity risk management, which includes reviewing our cybersecurity and other information, technology risks, controls and procedures, including our plans to mitigate and respond to cybersecurity risks.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.