2 unchanged sentences
Risk Management and Strategy
+Added: We use, store, and process data related to research programs, clinical trials, intellectual property, employees and third-party partners.
We have developed and maintain an information security program designed to assess, identify, and manage risks from cybersecurity threats.
2 unchanged sentences
We engage security technology vendors to assist with detecting potential threats to our information assets.
−Removed: In addition, we have implemented a cybersecurity third party risk management process to assess mission and business critical third parties for cyber risks and to assist the business in making risk-informed technology product and services decisions.
+Added: In addition, we have implemented a cybersecurity third-party risk management process to assess mission and business critical third-party vendors for cyber risks and to assist the business in making risk-informed technology product and services decisions.
Our practice is to perform due diligence, including the completion of security questionnaires and risk assessments, as appropriate, on third-parties who maintain material data or information to help us evaluate and verify third-party information security capabilities.
−Removed: Our process designed to detect and respond to cybersecurity incidents that may represent a threat to the confidentiality, integrity or availability of our information assets is based on industry standards and best practices of peer companies.
+Added: Our process is designed to detect and respond to cybersecurity incidents that may represent a threat to the confidentiality, integrity or availability of our information assets is based on industry standards and best practices of peer companies.
Our technology, procedures and key vendors with security responsibilities are designed to help contain, eradicate and recover from cybersecurity incidents in a timely manner.
Senior management is informed about incidents that may have a significant impact on the business.
−Removed: Incidents are reviewed once they are resolved, and policies and controls are updated to help mitigate gaps.
+Added: Cybersecurity risks are reviewed by management through cross-functional collaboration among IT, Legal and Finance, with oversight by the Audit Committee.
We have not identified risks from known cybersecurity threats or past incidents that have materially affected or are reasonably likely to materially affect us.
3 unchanged sentences
Our Audit Committee has specific oversight of risk management, including risks from cybersecurity threats.
−Removed: Our Executive Director of IT is responsible for developing, implementing, and maintaining our cybersecurity risk management policies and procedures.
−Removed: The individual currently serving in the role of Executive Director of IT has over thirty years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance and risk management within complex and international business verticals such as pharmaceutical/biotech, technology, semiconductor and telecom.
−Removed: The Executive Director of IT reports to our Chief Human Resources Officer and provides periodic cybersecurity updates to the Audit Committee of our Board of Directors on at least an annual basis .
+Added: Our Head of IT is responsible for developing, implementing, and maintaining our cybersecurity risk management policies and procedures.
+Added: The Head of IT, reporting to our Chief Human Resources Officer, has over thirty years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance and risk management within complex and international pharmaceutical and biotech companies.
+Added: The Head of IT provides periodic cybersecurity updates to the Audit Committee and our Board of Directors on at least an annual basis .
Our incident response process contemplates that the executive team will notify the Audit Committee of our Board of Directors of any material cybersecurity incident.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.