|
Cybersecurity Risk Management, Strategy and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity.
Strategy and Oversight
We have implemented and maintain various information security processes designed to identify, assess and manage material risks from cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, and data related to our clinical studies and employees, or our information systems and the data contained therein.
We retain a Chief Information Consultant to collaborate with the company, including the Chief Financial Officer, and Executive Leadership Team, to help identify, assess and manage the company’s cybersecurity threats and risks. This group identifies and assesses risks from cybersecurity threats by monitoring and evaluating our threat environment using various methods including, for example, automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and actors, and evaluating threats reported to us. We also use a third-party security management vendor to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats.
Depending on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our information systems, including, for example, incident detection and response policy, route risk assessments, data encryption, network security controls, data segregation, access controls, physical security, asset management, tracking and disposal, systems monitoring, penetration testing, and cybersecurity insurance. As part of our information security program, we provide mandatory periodic training for all employees on how to identify potential cybersecurity risks and protect our resources and information. This training is supplemented by firmwide testing initiatives, including periodic phishing tests.
Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes. For example, the Chief Information Consultant works with management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business. In addition, our Chief Financial Officer evaluates material risks from cybersecurity threats and, as appropriate, reports to the Audit Committee of the Board of Directors, which evaluates our overall enterprise risk.
To date, we do not believe that known risks from cybersecurity threats, including as a result of any previous cybersecurity incidents that we are aware of, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition. However, we can give no assurance that we have detected or protected against all such cybersecurity incidents or threats. For a description of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Part I. Item 1A. Risk Factors in this Annual Report on Form 10-K, including the risk factor titled “We depend on our information systems and those of our third-party collaborators, service providers, contractors or consultants, which may fail or suffer cybersecurity incidents that could result in a material disruption of our development programs or loss of data and have a material adverse effect on our reputation, business, financial condition or results of operations.”
Governance
Our Board addresses our cybersecurity risk management as part of its general oversight function. The Audit Committee is responsible for overseeing our cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats. Our cybersecurity risk assessment and management processes are implemented and maintained by our Chief Financial Officer who oversees the work performed by our Chief Information Consultant.
Our Chief Financial Officer is responsible for hiring appropriate consultants, helping to integrate cybersecurity risk considerations into our overall risk management strategy and communicating key priorities to relevant personnel. Our Chief Financial Officer, with support from our Chief Information Consultant, is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
The Audit Committee receives periodic reports from our Chief Financial Officer concerning our significant cybersecurity threats and risks and the processes we have implemented to address them. The Audit Committee also receives various reports, summaries or presentations related to cybersecurity threats, risk and mitigation. The Chief Financial Officer also promptly informs and updates the Board about any information security incidents that may pose significant risk to our Company.
The Chief Financial Officer has over 20 years of operations and leadership experience, including experience in information technology strategy and execution. The Chief Information Consultant has over 20 years of experience managing and securing technology infrastructure.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Governance
Our Board addresses our cybersecurity risk management as part of its general oversight function. The Audit Committee is responsible for overseeing our cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats. Our cybersecurity risk assessment and management processes are implemented and maintained by our Chief Financial Officer who oversees the work performed by our Chief Information Consultant.
Our Chief Financial Officer is responsible for hiring appropriate consultants, helping to integrate cybersecurity risk considerations into our overall risk management strategy and communicating key priorities to relevant personnel. Our Chief Financial Officer, with support from our Chief Information Consultant, is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
The Audit Committee receives periodic reports from our Chief Financial Officer concerning our significant cybersecurity threats and risks and the processes we have implemented to address them. The Audit Committee also receives various reports, summaries or presentations related to cybersecurity threats, risk and mitigation. The Chief Financial Officer also promptly informs and updates the Board about any information security incidents that may pose significant risk to our Company.
The Chief Financial Officer has over 20 years of operations and leadership experience, including experience in information technology strategy and execution. The Chief Information Consultant has over 20 years of experience managing and securing technology infrastructure.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Audit Committee is responsible for overseeing our cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Chief Financial Officer evaluates material risks from cybersecurity threats and, as appropriate, reports to the Audit Committee of the Board of Directors, which evaluates our overall enterprise risk.
|Cybersecurity Risk Role of Management [Text Block]
|Audit Committee receives periodic reports from our Chief Financial Officer concerning our significant cybersecurity threats and risks and the processes we have implemented to address them. The Audit Committee also receives various reports, summaries or presentations related to cybersecurity threats, risk and mitigation. The Chief Financial Officer also promptly informs and updates the Board about any information security incidents that may pose significant risk to our Company.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Chief Financial Officer is responsible for hiring appropriate consultants, helping to integrate cybersecurity risk considerations into our overall risk management strategy and communicating key priorities to relevant personnel. Our Chief Financial Officer, with support from our Chief Information Consultant, is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
The Chief Financial Officer has over 20 years of operations and leadership experience, including experience in information technology strategy and execution. The Chief Information Consultant has over 20 years of experience managing and securing technology infrastructure.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Audit Committee receives periodic reports from our Chief Financial Officer concerning our significant cybersecurity threats and risks and the processes we have implemented to address them. The Audit Committee also receives various reports, summaries or presentations related to cybersecurity threats, risk and mitigation. The Chief Financial Officer also promptly informs and updates the Board about any information security incidents that may pose significant risk to our Company.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef