|
Cybersecurity Risk Management, Strategy, and Governance
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
ITEM 1C. CYBERSECURITY
Cyber Risk Management and Strategy
We have adopted cybersecurity risk management activities and processes that are informed by and incorporate elements of recognized industry standards, such as the National Institute of Standards and Technology Cybersecurity Framework, and that are designed to identify, assess, and mitigate critical risks from cybersecurity threats. We have, for example, implemented a process to monitor for potential critical risks from cybersecurity threats using automated tools. To support our cybersecurity risk management efforts, we leverage a managed service provider that provides ongoing support for the protection of our information technology infrastructure.
We have an employee security awareness training program that is designed to raise awareness of cybersecurity threats across functions, as well as to encourage consideration of cybersecurity risks across our company. As part of this employee training program, we periodically conduct phishing simulations designed to raise employee awareness of such risks.
We have also implemented a process to assess and review the cybersecurity practices of certain third-party vendors and service providers that may be critical to the operations of our business and who have access to our information systems or store our confidential clinical trial data, including, as appropriate, through review of System and Organization Controls reports and security questionnaires and the inclusion of cybersecurity requirements in relevant contracts.
As part of our cybersecurity risk management, we have adopted an incident response plan that has been designed to identify and manage significant events that may impact our information technology infrastructure, including those arising from or related to cybersecurity threats.
We have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition; however, like other companies in our industry, we and our third-party vendors may, from time to time, experience threats and security incidents relating to our and our third-party vendors’ information systems and infrastructure. For more information, please see “Risk Factors.”
Cybersecurity Governance
We leverage the support of third-party information technology and security providers for the maintenance of our cybersecurity risk management processes, including the day-to-day oversight of the assessment and management of cybersecurity risks. These third-party providers directly report to, and meet periodically with, our Senior Vice President of Finance and Administration to discuss and review our cybersecurity risk management processes.
Our board of directors has delegated oversight of our company’s cybersecurity risk management to our audit committee. The audit committee, pursuant to the audit committee charter, is responsible for reviewing our company’s information security and technology risks (including cybersecurity), including high-level review of the threat landscape facing our company and our company’s strategy to mitigate cybersecurity risks and potential breaches. We have a process for our Senior Vice President of Finance and Administration and/or our Chief Financial Officer, as appropriate, to provide periodic updates to the audit committee on the status of our cybersecurity program and on an as needed basis.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
We leverage the support of third-party information technology and security providers for the maintenance of our cybersecurity risk management processes, including the day-to-day oversight of the assessment and management of cybersecurity risks. These third-party providers directly report to, and meet periodically with, our Senior Vice President of Finance and Administration to discuss and review our cybersecurity risk management processes.
Our board of directors has delegated oversight of our company’s cybersecurity risk management to our audit committee. The audit committee, pursuant to the audit committee charter, is responsible for reviewing our company’s information security and technology risks (including cybersecurity), including high-level review of the threat landscape facing our company and our company’s strategy to mitigate cybersecurity risks and potential breaches. We have a process for our Senior Vice President of Finance and Administration and/or our Chief Financial Officer, as appropriate, to provide periodic updates to the audit committee on the status of our cybersecurity program and on an as needed basis.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|
Our board of directors has delegated oversight of our company’s cybersecurity risk management to our audit committee. The audit committee, pursuant to the audit committee charter, is responsible for reviewing our company’s information security and technology risks (including cybersecurity), including high-level review of the threat landscape facing our company and our company’s strategy to mitigate cybersecurity risks and potential breaches. We have a process for our Senior Vice President of Finance and Administration and/or our Chief Financial Officer, as appropriate, to provide periodic updates to the audit committee on the status of our cybersecurity program and on an as needed basis.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|We have a process for our Senior Vice President of Finance and Administration and/or our Chief Financial Officer, as appropriate, to provide periodic updates to the audit committee on the status of our cybersecurity program and on an as needed basis.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef