Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
105
Item 1C. Cyb ersecurity.
Cyber Risk Management and Strategy
We have adopted processes for assessing, identifying, and managing cybersecurity risks, that are integrated into our overall enterprise management framework, built into our information technology function and are designed to help protect our information assets and operations from internal and external cybersecurity threats, protect employee and clinical trial information from unauthorized access or attack, as well as secure our networks and systems. Such processes include physical, procedural, and technical safeguards, and periodic review of our procedures in an effort to identify risks and refine our practices. To support our internal resources, we leverage external tools and resources, including a managed service provider that provides ongoing support for the protection of our information technology infrastructure.
We have an employee security awareness program, required upon onboarding and on an annual basis thereafter, that is designed to raise awareness of cybersecurity threats across functions. As part of this employee training program, we periodically conduct phishing tests. We have also implemented a process to assess and review the cybersecurity practices of certain third-party vendors and service providers that may be critical to the operations of our business and who have access to our information systems including, as appropriate, through the inclusion of cybersecurity requirements in our contracts.
We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition; however, like other companies in our industry, we and our third-party vendors may, from time to time, experience threats and security incidents relating to our and our third-party vendors’ information systems. For more information, see “ Risk Factors–Risks related to our dependence on third parties–Our information technology systems, or those used by our CROs or other contractors or consultants, may fail or suffer security breaches, which could adversely affect our business. ”
Governance Related to Cybersecurity Risks
Our audit committee of the board of directors, (the “Audit Committee”), is responsible for overseeing cybersecurity risk, pursuant to the Audit Committee charter, and periodically updates our board of directors on such matters . The Audit Committee receives periodic updates from management regarding cybersecurity matters, and we have a process for the Audit Committee to be notified between such updates in the event of any significant new cybersecurity threats or incidents.
Management is responsible for the operational oversight of company-wide cybersecurity strategy, policy, and standards across relevant departments to assess and help prepare us to address cybersecurity risks . Our Senior Manager of Information Technology reports to our Chief Financial and Operating Officer and oversees the day-to-day implementation and management of our cybersecurity program. Our Senior Manager of Information Technology has approximately 20 years of experience in information technology and regularly reports to executive management, the company’s disclosure committee, and the Audit Committee on cyber matters, as appropriate .
Item 2. P roperties.
Our corporate headquarters is presently located in Waltham, Massachusetts, where we lease and occupy 16,801 square feet of office space. The initial term of the lease expires on November 1, 2027, with an option to extend the lease for an additional three years thereafter.
We believe that our leased premises will be sufficient for our needs for the foreseeable future. To meet the future needs of our business, we may lease additional or alternate space, and we believe suitable additional or alternative space will be available in the future on commercially reasonable terms.
Item 3. Le gal Proceedings.
From time to time, we may become involved in litigation or other legal proceedings. We are not currently a party to any litigation or legal proceedings that, in the opinion of our management, are probable to have a material adverse effect on our business. Regardless of outcome, litigation can have an adverse impact on our business, financial condition, results of operations and prospects because of defense and settlement costs, diversion of management resources and other factors.
106
Item 4. Mine Safety Disclosures.
Not applicable.
107
PART II
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.