5 unchanged sentences
Depending on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our IT Assets, which include implementing policies and guidelines governing the individual use and protection of IT Assets by employees, employee training, and leveraging the capability of third -party service providers to support our internal cybersecurity processes.
−Removed: These processes are aligned with standard industry frameworks, such as the National Institute of Standards and Technology, Committee of Sponsoring Organizations, International Organization for Standardization 27001, and other industry standards.
−Removed: We have also implemented a well-established information security incident response plan, which is designed to escalate cybersecurity incidents, depending on the circumstances, to appropriate stakeholders as defined by internal standard operating procedures.
+Added: These processes are aligned with the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) and the Center for Internet Security Critical Security Controls (CIS Controls).
+Added: We have implemented and maintain a documented information security incident response plan that is based on the NIST CSF and CIS Controls and is designed to support the identification, escalation, response to, and recovery from cybersecurity incidents in accordance with defined internal procedures and governance processes.
+Added: The incident response plan is periodically reviewed and tested, and incidents are escalated to appropriate internal stakeholders based on the nature and potential impact of the event.
We continue to monitor proposed cybersecurity disclosure rules from the SEC and alter our procedures accordingly.
−Removed: To further improve the effectiveness of our information security processes, we engage third -party service organizations to monitor the Company’s information technology (IT) environment, conduct evaluations of the effectiveness of our security controls and provide aggregate monthly reports to our corporate IT Security Team regarding the results of such third -party assessments, training and vulnerability testing, data security posture, material cybersecurity risks and areas of improvement.
−Removed: Risks from cybersecurity threats have not materially affected or are currently viewed as not reasonably likely to materially affect us, our business strategy, results of operations or financial condition.
+Added: To further improve the effectiveness of our information security processes, we engage third -party service organizations to support monitoring aspects of the Company’s information technology (IT) environment and perform assessments of certain security controls, and provide aggregate, informational monthly reports to our corporate IT Security Team regarding the results of such third -party assessments, training and vulnerability testing, data security posture, identified material cybersecurity risks and areas of improvement.
+Added: Risks from cybersecurity threats have not materially affected us to date and, based on management's current assessment, are not reasonably likely to materially affect us, our business strategy, results of operations or financial condition.
However, the scope and impact of any future cybersecurity incidents cannot be predicted and there can be no assurance that our information security program will be effective in preventing material cybersecurity incidents in the future.
1 unchanged sentence
Risk Factors in this Annual Report on Form 10 -K, including the risk factor captioned “ Our internal information technology systems, or those of our third -party CROs, CMOs, or other contractors or consultants, may fail or suffer security breaches, which could result in a material disruption of our drug candidates ’ development programs and our commercialization of any products for which we receive regulatory approval .”
−Removed: The Board and our Chief Executive Officer is responsible for oversight of the Company’s overall risk management program, including as to cybersecurity related risks, while management is responsible for the day-to-day risk management processes.
+Added: The Board and our Chief Executive Officer are responsible for oversight of the Company’s overall risk management program, including as to cybersecurity related risks, while management is responsible for the day-to-day risk management processes.
The Board receives regular reports from our Chief Executive Officer, Chief Financial Officer and other members of management, regarding material cybersecurity threats and risks, effectiveness of our information security processes and status of ongoing cybersecurity initiatives and strategies.
1 unchanged sentence
Our Vice President of IT has over 25 years of experience in IT systems, including cybersecurity risk management and incident response, and holds multiple industry-recognized certifications.
−Removed: Our Vice President of IT receives regular reports from the corporate IT Security Team, together with information provided by our third-party service organizations that monitor the Company’s IT environment, regarding the Company’s material cybersecurity threats and risks and the processes the Company has implemented to address them, which are reported to the Chief Financial Officer.
−Removed: We maintain corporate and executive space in Morrisville, North Carolina, New York, New York, and Edison, New Jersey.
+Added: Our Vice President of IT receives regular reports from the corporate IT Security Team, together with information provided by our third-party service organizations that support monitoring of aspects of the Company’s IT environment, regarding the Company’s material cybersecurity threats and risks and the processes the Company has implemented to address them, which information is reported, as appropriate, to the Chief Financial Officer.
+Added: We maintain corporate and executive space in Morrisville, North Carolina and New York, New York.
We are also currently leasing small office space in Boca Raton, Florida.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.