13 unchanged sentences
is apprised of cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
−Removed: The full Board retains
−Removed: oversight of cybersecurity because of its importance.
−Removed: In the event of an incident, we intend to follow our detailed incident response
−Removed: playbook, which outlines the steps to be followed from incident detection to mitigation, recovery, and notification, including notifying
−Removed: functional areas (e.g., legal), as well as senior leadership and the Board, as appropriate.
−Removed: Our Cybersecurity consultant has extensive
−Removed: information technology and program management experience.
−Removed: We have implemented a governance structure and processes to assess, identify,
−Removed: manage, and report cybersecurity risks .
+Added: The full Board
+Added: retains oversight of cybersecurity because of its importance.
+Added: In the event of an incident, we intend to follow our detailed incident
+Added: response playbook, which outlines the steps to be followed from incident detection to mitigation, recovery, and notification, including
+Added: notifying functional areas (e.g., legal), as well as senior leadership and the Board, as appropriate.
+Added: Our Cybersecurity consultant has
+Added: extensive information technology and program management experience.
+Added: We have implemented a governance structure and processes to assess,
+Added: identify, manage, and report cybersecurity risks
As a biotechnology company, we must comply with
−Removed: extensive regulations, including requirements imposed by the Food and Drug Administration related to adequately safeguarding patient information
−Removed: and reporting cybersecurity incidents to the SEC.
−Removed: We work with our cybersecurity consultant on assessing cybersecurity risk and on policies
−Removed: and practices aimed at mitigating these risks.
+Added: extensive regulations, including requirements imposed by the Food and Drug Administration related to adequately safeguarding patient
+Added: information and reporting cybersecurity incidents to the SEC.
+Added: We work with our cybersecurity consultant on assessing cybersecurity risk
+Added: and on policies and practices aimed at mitigating these risks.
We believe we are positioned to meet the requirements of the SEC.
−Removed: In addition to following
−Removed: SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe
−Removed: enhance our ability to identify and manage cybersecurity risks.
+Added: to following SEC guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which
+Added: we believe enhance our ability to identify and manage cybersecurity risks.
Third parties also play a role in our cybersecurity.
−Removed: We engage third-party
−Removed: services to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting on best
−Removed: practices to address new challenges.
−Removed: Assessing, identifying, and managing cybersecurity related risks are factored into our overall business
−Removed: We rely heavily on our vendors and suppliers to
−Removed: deliver our products and services, and a cybersecurity incident at a supplier, subcontractor or business partner could materially adversely
−Removed: We require that our subcontractors report cybersecurity incidents to us so that we can assess the impact of the incident on
−Removed: Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity
−Removed: incident that could have a material adverse effect on us.
−Removed: The costs related to cybersecurity threats or disruptions may not be fully insured.
+Added: third-party services to conduct evaluations of our security controls, whether through penetration testing, independent audits, or consulting
+Added: on best practices to address new challenges.
+Added: Assessing, identifying, and managing cybersecurity related risks are factored into our overall
+Added: business approach.
+Added: We rely heavily on our vendors and suppliers
+Added: to deliver our products and services, and a cybersecurity incident at a supplier, subcontractor or business partner could materially
+Added: adversely impact us.
+Added: We require that our subcontractors report cybersecurity incidents to us so that we can assess the impact of the
+Added: incident onus.
+Added: Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating
+Added: a cybersecurity incident that could have a material adverse effect on us.
+Added: The costs related to cybersecurity threats or disruptions may
+Added: not be fully insured.
See “Risk Factors” for a discussion of cybersecurity risks.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.