Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
We have developed and implemented a cybersecurity risk management program that is designed to assess, identify, and manage material risks from cybersecurity threats and to protect the security, confidentiality, integrity and availability of our critical systems and information. These processes are managed and monitored by our information technology team, which is led by our Vice President, Information Technology & Facilities, and include mechanisms, controls, technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting our data and information technology environment. For example, we conduct cybersecurity audits, and ongoing risk assessments, including due diligence on and audits of our key technology vendors, CROs, and other contractors and suppliers. We also conduct periodic employee trainings on cyber and information security, among other topics. In addition, we consult with outside advisors and experts, when appropriate, to assist with assessing, identifying, and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the Company’s risk environment.
Our Vice President, Information Technology & Facilities , who reports directly to the Chief Operating Officer and has over 15 years of experience managing information technology and cybersecurity matters, together with our senior leadership team, is responsible for assessing and managing cybersecurity risks. We consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework that is overseen by our Audit Committee of our board of directors and our board of directors. In the last fiscal year, we have not experienced any cybersecurity incidents that resulted in a material effect on our business strategy, results of operations, or financial condition, but we cannot provide assurance that we will not be materially affected in the future by such risks or any future material incidents See “Risk Factors” for additional information on cybersecurity risks we face.
88
Our Audit Committee has been designated by our Board to oversee cybersecurity risks. The Audit Committee receives biannual updates on cybersecurity and information technology matters and related risk exposures from members of the senior leadership team. The Board also receives updates from management and the Audit Committee on cybersecurity risks on at least an annual basis.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.