13 unchanged sentences
is apprised of cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
−Removed: The full Board
−Removed: retains oversight of cybersecurity because of its importance.
−Removed: In the event of an incident, we intend to follow our detailed incident
−Removed: response playbook, which outlines the steps to be followed from incident detection to mitigation, recovery, and notification, including
−Removed: notifying functional areas (e.g., legal), as well as senior leadership and the Board, as appropriate.
−Removed: Our Cybersecurity consultant has
−Removed: extensive information technology and program management experience.
−Removed: We have implemented a governance structure and processes to assess,
−Removed: identify, manage, and report cybersecurity risks.
+Added: The full Board retains
+Added: oversight of cybersecurity because of its importance.
+Added: In the event of an incident, we intend to follow our detailed incident response
+Added: playbook, which outlines the steps to be followed from incident detection to mitigation, recovery, and notification, including notifying
+Added: functional areas (e.g., legal), as well as senior leadership and the Board, as appropriate.
+Added: Our Cybersecurity consultant has extensive
+Added: information technology and program management experience.
+Added: We have implemented a governance structure and processes to assess, identify,
+Added: manage, and report cybersecurity risks .
As a biotechnology company, we must comply with
−Removed: extensive regulations, including requirements imposed by the Food and Drug Administration related to adequately safeguarding patient
−Removed: information and reporting cybersecurity incidents to the SEC.
−Removed: We work with our cybersecurity consultant on assessing cybersecurity risk
−Removed: and on policies and practices aimed at mitigating these risks.
+Added: extensive regulations, including requirements imposed by the Food and Drug Administration related to adequately safeguarding patient information
+Added: and reporting cybersecurity incidents to the SEC.
+Added: We work with our cybersecurity consultant on assessing cybersecurity risk and on policies
+Added: and practices aimed at mitigating these risks.
We believe we are positioned to meet the requirements of the SEC.
−Removed: to following SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which
−Removed: we believe enhance our ability to identify and manage cybersecurity risks.
+Added: In addition to following
+Added: SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe
+Added: enhance our ability to identify and manage cybersecurity risks.
Third parties also play a role in our cybersecurity.
−Removed: third-party services to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting
−Removed: on best practices to address new challenges.
−Removed: Assessing, identifying, and managing cybersecurity related risks are factored into our overall
−Removed: business approach.
−Removed: We rely heavily on our vendors and suppliers to deliver our products
−Removed: and services, and a cybersecurity incident at a supplier, subcontractor or business partner could materially adversely impact us.
−Removed: that our subcontractors report cybersecurity incidents to us so that we can assess the impact of the incident on us.
−Removed: Notwithstanding the
−Removed: extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could
−Removed: have a material adverse effect on us.
+Added: We engage third-party
+Added: services to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best
+Added: practices to address new challenges.
+Added: Assessing, identifying, and managing cybersecurity related risks are factored into our overall business
+Added: We rely heavily on our vendors and suppliers to
+Added: deliver our products and services, and a cybersecurity incident at a supplier, subcontractor or business partner could materially adversely
+Added: We require that our subcontractors report cybersecurity incidents to us so that we can assess the impact of the incident on
+Added: Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity
+Added: incident that could have a material adverse effect on us.
The costs related to cybersecurity threats or disruptions may not be fully insured.
−Removed: Factors” for a discussion of cybersecurity risks.
+Added: See “Risk Factors” for a discussion of cybersecurity risks.
Our principal address is 4300 El Camino Real,
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.