|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity Risk Management and Strategy
We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.
We design and assess our cybersecurity program based on the NIST Cybersecurity Framework (CSF). This framework provides us with a common language and structure for identifying, assessing, and managing cybersecurity risks across our organization. We do not claim to comply with the standards or specifications by using this framework. It is a guide to help us manage the cybersecurity risks that are relevant to our business.
Our cybersecurity program is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas. To this end, we have implemented a cybersecurity program that includes the following key elements:
We have not identified any cybersecurity incidents that have materially affected our operations, business strategy, results of operations, or financial condition. We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. For more information, see the section titled “Risk Factors— Our information technology systems, or those of our third-party CROs, CMOs or other contractors or consultants, may fail or suffer security breaches, which could result in a material disruption of setmelanotide development programs, regulatory investigations, enforcement actions and lawsuits.”
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
We design and assess our cybersecurity program based on the NIST Cybersecurity Framework (CSF). This framework provides us with a common language and structure for identifying, assessing, and managing cybersecurity risks across our organization. We do not claim to comply with the standards or specifications by using this framework. It is a guide to help us manage the cybersecurity risks that are relevant to our business.
Our cybersecurity program is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas. To this end, we have implemented a cybersecurity program that includes the following key elements:
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (the “Committee”) oversight of cybersecurity risks. The Committee oversees management’s implementation of our cybersecurity program.
The Committee receives periodic reports from management on our cybersecurity program and risks. In addition, management updates the Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential. The Committee reports to the full Board regarding its activities and risk management functions, including those related to cybersecurity. Board members receive presentations on cybersecurity risk and strategy from our Senior Cybersecurity Manager, as part of the Board’s continuing education on topics that impact public companies.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Audit Committee (the “Committee”)
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (the “Committee”) oversight of cybersecurity risks. The Committee oversees management’s implementation of our cybersecurity program.
The Committee receives periodic reports from management on our cybersecurity program and risks. In addition, management updates the Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential. The Committee reports to the full Board regarding its activities and risk management functions, including those related to cybersecurity. Board members receive presentations on cybersecurity risk and strategy from our Senior Cybersecurity Manager, as part of the Board’s continuing education on topics that impact public companies.
|Cybersecurity Risk Role of Management [Text Block]
|
The Senior Cybersecurity Manager, with the help of our IT and Legal team is responsible for assessing and managing our material risks from cybersecurity threats. This position has the primary responsibility for our overall cybersecurity risk management program and supervises both our internal personnel and our retained external cybersecurity consultants. The current Senior Cybersecurity Manager has extensive information security and program management experience and has held past positions as a virtual CISO for a wide range of organizations.
Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel and other information obtained from governmental, public, or private sources, including external consultants engaged by us, and alerts and reports produced by security tools deployed in the IT environment.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|Senior Cybersecurity Manager
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
The Senior Cybersecurity Manager, with the help of our IT and Legal team is responsible for assessing and managing our material risks from cybersecurity threats. This position has the primary responsibility for our overall cybersecurity risk management program and supervises both our internal personnel and our retained external cybersecurity consultants. The current Senior Cybersecurity Manager has extensive information security and program management experience and has held past positions as a virtual CISO for a wide range of organizations.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Senior Cybersecurity Manager, with the help of our IT and Legal team is responsible for assessing and managing our material risks from cybersecurity threats. This position has the primary responsibility for our overall cybersecurity risk management program and supervises both our internal personnel and our retained external cybersecurity consultants. The current Senior Cybersecurity Manager has extensive information security and program management experience and has held past positions as a virtual CISO for a wide range of organizations.
Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel and other information obtained from governmental, public, or private sources, including external consultants engaged by us, and alerts and reports produced by security tools deployed in the IT environment.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef