1 unchanged sentence
Cybersecurity
−Removed: Our Board of Directors, in coordination with the Audit Committee of the Board of Directors (the Audit Committee), is responsible for overseeing our risk management and information technology programs of which cybersecurity is a critical element.
−Removed: Management is responsible for the administration of our cybersecurity policies, standards, procedures and practices.
−Removed: Our cybersecurity policies, standards, procedures, and practices are based on the Center for Internet Security (CIS) Critical Security Controls, a framework for companies to establish and evaluate cybersecurity policies, procedures and practices.
−Removed: We seek to address material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of our information systems or the information that we collect and store, by assessing, identifying and managing cybersecurity issues as they arise.
+Added: The Company’s management maintains a cybersecurity program, with direct oversight from the Audit Committee (the “Audit Committee”) of the Board of Directors (the “Board”), to manage information, data, technology security, and procedures and practices.
+Added: The cybersecurity program is informed in part by the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), which provides guidance to help identify, assess, and manage cybersecurity risks relevant to the Company’s business.
+Added: The Company seeks to address material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of the Company’s information systems and the information that it collects and stores, by assessing, identifying and managing cybersecurity issues as they arise.
+Added: Consistent with this approach, the Company applies cybersecurity practices informed by a Zero Trust-aligned security philosophy that emphasizes continuous verification, least-privilege access, and risk-based controls across its information systems.
Cybersecurity Risk Management and Strategy
−Removed: Our cybersecurity risk management strategy focuses on several issues:
−Removed: Identification and Reporting:
−Removed: We have implemented a comprehensive approach to assessing, identifying and managing material cybersecurity threats and incidents.
−Removed: Our program includes controls and procedures to timely identify, classify and escalate certain cybersecurity incidents to provide management visibility and allow for direction from management as to the public disclosure and reporting of material incidents in a timely manner.
−Removed: Technical Safeguards:
−Removed: We implement current information technologies to support our cybersecurity practices.
−Removed: These technologies are designed to protect our information systems from cybersecurity threats and include email and internet protection, firewall and network security, intrusion detection and prevention systems, anti-malware endpoint detection and response, security event monitoring and alerting, high availability and replication, system configuration and asset management, backup and restoration processes, vulnerability and patch management, identity and access management and data encryption.
−Removed: These technologies and controls are continuously evaluated and improved through vulnerability assessments and cybersecurity threat intelligence, as well as audits by third-party specialists and certifications.
−Removed: Incident Response and Recovery Planning:
−Removed: We have established and maintain a comprehensive incident response plan, designed to address our response to a cybersecurity incident.
−Removed: Our cross-functional members comprise the incident response team to respond and disclose material incidents.
−Removed: The incident response plan defines pre-incident activities and preparation, classification of incidents, response team internal and external contacts, process flow of the response team, escalation of incidents to outside entities and law enforcement and frequency of review of the incident response plan.
−Removed: We conduct regular tabletop exercises (i.e., discussion-based simulations) to test these plans and ensure personnel are familiar with their roles in a response scenario.
+Added: The Company maintains a cross-functional, enterprise-wide cybersecurity risk management program that is integrated into its overall risk management framework and operating processes.
+Added: Cybersecurity risks are evaluated alongside other enterprise risks as part of the Company’s broader risk assessment activities, including consideration of their potential impact on the Company’s business operations, financial condition, results of operations, and reputation.
+Added: Senior management is actively involved in identifying, assessing, and managing cybersecurity risks, and the Board, primarily through the Audit Committee, provides oversight of these risks.
+Added: Identification and Escalation of Cybersecurity Risks :
+Added: The Company maintains processes and controls designed to identify, assess, and manage cybersecurity threats and incidents that could be material.
+Added: These processes are intended to enable the timely identification, classification, and escalation of cybersecurity incidents to appropriate levels of management based on the nature, severity, and potential impact of the incident.
+Added: Management is informed of cybersecurity incidents through defined escalation protocols, which facilitate coordination among information technology, legal, finance, and other relevant functions and support management’s evaluation of incident severity, response actions, and disclosure considerations.
+Added: Significant cybersecurity risks and incidents are reported to the Audit Committee, as appropriate, and the Audit Committee provides oversight of management’s response and remediation efforts.
+Added: Cybersecurity Controls and Monitoring :
+Added: The Company’s cybersecurity program includes administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of the Company’s information systems.
+Added: These safeguards are supported by ongoing monitoring activities, vulnerability assessments, and cybersecurity threat intelligence, and are periodically evaluated through internal reviews and independent third-party assessments.
+Added: The results of these activities are reviewed by management and used to inform enhancements to the Company’s cybersecurity risk management practices.
+Added: Incident Response and Recovery :
+Added: The Company maintains an incident response and recovery plan designed to guide the Company’s response to cybersecurity incidents.
+Added: The plan defines roles and responsibilities, escalation and reporting protocols, coordination with internal and external stakeholders, and post-incident review processes.
+Added: A cross-functional incident response team, led by the Company’s head of Information Technology and including representatives from finance, legal, human resources, corporate communications, and executive leadership, supports the execution of the plan.
+Added: Management monitors incident response efforts and determines whether any cybersecurity incident is material and requires disclosure, and provides updates to the Audit Committee regarding significant incidents and remediation efforts, as appropriate.
Third-Party Risk Management :
−Removed: We maintain a comprehensive, risk-based approach to identifying and overseeing material cybersecurity threats presented by third parties, including vendors, service providers, contractors, consultants and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a material cybersecurity incident affecting those third-party systems, including any outside auditors or consultants who advise on our cybersecurity systems.
−Removed: Third parties are regularly assessed to determine the need for cybersecurity auditing based on risk evaluation.
−Removed: Education and Awareness:
−Removed: We provide regular, mandatory training and assessment for all levels of employees regarding cybersecurity threats as a means to equip our employees with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes, and practices.
−Removed: We conduct periodic assessment and testing of our policies, standards, processes, and practices including audits by independent third-party specialists in a manner intended to address cybersecurity threats and events.
−Removed: Policies are reviewed and revised on a frequent basis for relevance and to maintain compliance.
−Removed: The results of such assessments, audits, and reviews are evaluated by management and reported to the Audit Committee, and we adjust our cybersecurity policies, standards, processes, and practices as necessary based on the information provided by these assessments, audits, and reviews.
−Removed: The Board, in coordination with the Audit Committee, oversees our risk management and information technology programs, including the management of cybersecurity threats.
−Removed: The Audit Committee receives regular presentations and reports on developments in the cybersecurity space, including risk management practices, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends, and information security issues encountered by our peers and third parties.
−Removed: The Audit Committee also receives prompt and timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well as ongoing updates regarding any such risk.
−Removed: On an annual basis, the Audit Committee discusses our approach to overseeing cybersecurity threats with our head of Information Technology (IT) and other members of senior management.
−Removed: Xencor's head of IT has 33 years of experience and has managed information technology in complex environments for 20 years.
−Removed: In coordination with senior management, including the CFO, the head of IT works collaboratively across the Company to implement a program designed to protect our information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with our incident response and recovery plans.
−Removed: Cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents support the success of our cybersecurity program.
−Removed: Ongoing communications with these teams are designed to keep the head of IT and senior management informed about the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee when appropriate.
+Added: The Company assesses and manages cybersecurity risks associated with third-party service providers as part of the Company’s overall cybersecurity risk management program.
+Added: Third parties are evaluated using a risk-based approach that considers their access to the Company’s systems and data and the criticality of the services provided.
+Added: Based on assessed risk levels, the Company applies oversight measures commensurate with the level of risk, which may include contractual requirements, assessments, audits, or other assurance activities.
+Added: Training, Assessment, and Continuous Improvement :
+Added: The Company provides regular cybersecurity training and awareness programs for employees designed to promote the identification and reporting of cybersecurity threats and reinforce the Company’s information security policies and practices.
+Added: The Company also conducts periodic reviews, testing, and independent assessments of its cybersecurity program.
+Added: The results of these activities are evaluated by management, reported to the Audit Committee, and used to inform ongoing enhancements to the Company’s cybersecurity risk management strategy.
+Added: The Board, in coordination with the Audit Committee, oversees the Company’s risk management and information technology programs, including the management of cybersecurity risks.
+Added: The Audit Committee receives regular reports and presentations regarding cybersecurity matters, including the Company’s risk management practices, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends, and information security issues encountered by the Company, its peers, and third parties.
+Added: The Audit Committee also receives updates regarding significant cybersecurity risks and incidents, as appropriate.
+Added: On a quarterly basis, the Audit Committee discusses the Company’s approach to cybersecurity risk oversight with members of senior management.
+Added: The Company’s head of Information Technology, who has over 30 years of relevant experience in information security, in coordination with senior management, including the Chief Financial Officer, is responsible for managing the Company’s cybersecurity risk management program.
+Added: The head of Information Technology works collaboratively across the Company to implement and maintain processes designed to protect the Company’s information systems from cybersecurity threats and to respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
+Added: Cross-functional teams throughout the Company support the cybersecurity program by addressing cybersecurity risks and responding to incidents, and provide relevant information to the head of Information Technology and senior management, who report significant cybersecurity matters to the Audit Committee , as appropriate.
Material Effects of Cybersecurity Incidents
−Removed: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition.
+Added: Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected the Company’s business strategy, results of operations, or financial condition, and are not reasonably likely to materially affect the Company’s business strategy, results of operations, or financial condition.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.