5 unchanged sentences
We perform risk assessments relating to cybersecurity and technology risks at least annually.
−Removed: Our cybersecurity risk management program has been developed based on industry standards, including those published by the National Institute of Standards and Technology (“NIST”).
+Added: Our cybersecurity risk management program has been developed based on industry standards, including those published by the National Institute of Standards and Technology, or NIST.
Highlights of the program include:
4 unchanged sentences
• Security awareness training for employees to identify cybersecurity concerns and take appropriate actions;
+Added: • A managed security services provider, or MSSP, that monitors our environment at all times and collaborates with our internal cybersecurity team in areas including investigation of anomalies, incident response, vulnerability management, and threat intelligence;
• Evaluating our program’s effectiveness by performing regular internal and third-party assessments of our controls, including external penetration testing and consultation on security enhancements.
3 unchanged sentences
Management’s oversight is performed through an IT Strategy Committee, a subset of executive management including our Chief Financial Officer, or CFO, and Chief Legal Officer, and relevant functional expertise, including our Senior Vice President, Information Systems, or SVP, IS.
−Removed: Our SVP, IS, is the primary member of the IT Steering Committee charged with responsibility for assessing, monitoring and managing our cybersecurity risks .
−Removed: With over 20 years of experience in information technology strategy and operations, his background includes extensive experience as an IT executive at various companies.
+Added: Our SVP, IS, is the primary member of the IT Strategy Committee charged with responsibility for assessing, monitoring and managing our cybersecurity risks .
+Added: With over 20 years of experience in information technology strategy and operations, his background includes extensive experience as an IT executive at various life sciences companies.
At least annually, the SVP, IS, and the CFO provide a comprehensive report to the Audit Committee regarding cybersecurity risk assessments, planned enhancements to our cyber security program , and incident reports and remediation, if any .
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.