|
Cybersecurity Risk Management, Strategy, and Governance Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Item 1C. Cybersecurity
Risk management and strategy
We have implemented a risk-based approach designed to identify, assess and manage cybersecurity threats that could materially affect our business and information systems. We attempt to identify and assess risks from cybersecurity threats by evaluating our threat environment using various methods including, for example: maintaining manual and automated tools, subscribing to reports and services that identify cybersecurity threats, evaluating threats reported to us, and completing third-party cybersecurity threat assessments.
We use cybersecurity consultants and penetration testing firms in an effort to identify, assess, and manage material risks from cybersecurity threats. We use third-party service providers in various elements to our business operations such as data hosting providers. To help manage cybersecurity risks associated with our use of third-party service providers, we primarily engage with industry-preferred service providers, and we also contractually require service providers with access to personal, confidential, or proprietary information to maintain data security controls and practices.
For a description of the risks from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under Part 1. Item 1A. Risk Factors in this Annual Report on Form 10-K, including “Cybersecurity risks and the failure to maintain the security, confidentiality, integrity, or availability of our information technology systems or data, and those maintained on our behalf, could lead to adverse consequences that materially adversely affect our business, including, without limitation, regulatory investigations or actions, a material interruption to our operations, including clinical trials, damage to our reputation and/or subject us to costs, loss of customers or sales, fines and penalties or lawsuits.”
Governance
Our board of directors addresses our cybersecurity risk management as part of its general oversight function. The audit committee is responsible for advising on our cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats.
Our cybersecurity risk assessment and risk management processes are managed by certain members of our management, including our CFO (who has prior experience in strategic business operations). Our CFO has supervisory responsibility over IT and cybersecurity functions. Our management is responsible for helping to integrate cybersecurity risk considerations into our overall risk management strategy, helping prepare for and respond to cybersecurity incidents, and reviewing security assessments and other security-related reports. Our incident response team is responsible for remediating cybersecurity incidents of which they are notified.
We maintain a cybersecurity policy, reviewed with our audit committee, which is designed to address cybersecurity risks to us (including by escalating certain cybersecurity incidents to members of management and the board of the audit committee, in each case depending on the circumstances). We also maintain incident response procedures designed to assist us in responding to cybersecurity incidents.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
Our cybersecurity risk assessment and risk management processes are managed by certain members of our management, including our CFO (who has prior experience in strategic business operations). Our CFO has supervisory responsibility over IT and cybersecurity functions. Our management is responsible for helping to integrate cybersecurity risk considerations into our overall risk management strategy, helping prepare for and respond to cybersecurity incidents, and reviewing security assessments and other security-related reports. Our incident response team is responsible for remediating cybersecurity incidents of which they are notified.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our board of directors addresses our cybersecurity risk management as part of its general oversight function. The audit committee is responsible for advising on our cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our board of directors addresses our cybersecurity risk management as part of its general oversight function.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our CFO has supervisory responsibility over IT and cybersecurity functions. Our management is responsible for helping to integrate cybersecurity risk considerations into our overall risk management strategy, helping prepare for and respond to cybersecurity incidents, and reviewing security assessments and other security-related reports. Our incident response team is responsible for remediating cybersecurity incidents of which they are notified.
|Cybersecurity Risk Role of Management [Text Block]
|
Our cybersecurity risk assessment and risk management processes are managed by certain members of our management, including our CFO (who has prior experience in strategic business operations). Our CFO has supervisory responsibility over IT and cybersecurity functions. Our management is responsible for helping to integrate cybersecurity risk considerations into our overall risk management strategy, helping prepare for and respond to cybersecurity incidents, and reviewing security assessments and other security-related reports. Our incident response team is responsible for remediating cybersecurity incidents of which they are notified.
We maintain a cybersecurity policy, reviewed with our audit committee, which is designed to address cybersecurity risks to us (including by escalating certain cybersecurity incidents to members of management and the board of the audit committee, in each case depending on the circumstances). We also maintain incident response procedures designed to assist us in responding to cybersecurity incidents.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The audit committee is responsible for advising on our cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Our cybersecurity risk assessment and risk management processes are managed by certain members of our management, including our CFO (who has prior experience in strategic business operations).
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|Our incident response team is responsible for remediating cybersecurity incidents of which they are notified.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef