XML 20 R10.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management, Strategy, and Governance
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

ITEM 1C. CYBERSECURITY

Governance Related to Cybersecurity Risks

Our Board of Directors (the “Board”) holds overall oversight responsibility for the Company’s strategy and risk management, including in relation to cybersecurity risks. Our Board exercises its oversight function through the Audit Committee, which oversees the management of risk exposure across various areas, including data security risks, in accordance with its charter. The Audit Committee receives quarterly reports from our Chief Information Officer (“CIO”) on the status of the Company’s cybersecurity program, including measures implemented to monitor and address cybersecurity risks and threats, as appropriate.

The Company has an enterprise risk management committee (“ERMC”) that is composed of senior management, including the CIO and other senior executives. The ERMC monitors and oversees risk areas that could have a high impact on the business, and cybersecurity is currently one of the ERMC’s priority focus areas. The ERMC reports on our top identified risks and steps to address those risks to the full Board on a semi-annual basis.

At the management level, our Senior Director of Cyber Security and IT Risk Management is primarily responsible for leading our cybersecurity strategy for assessing and managing material risks from cybersecurity threats. He has over 20 years of cybersecurity experience across a wide array of industries, specializing in enterprise security strategy, regulatory compliance and building high-performing cyber programs that support global business operations. Our Senior Director of Cyber Security and IT Risk Management reports directly to our CIO, who is a member of our leadership team and reports to our Chief Financial Officer. Our current CIO has over 29 years of global IT leadership experiences across diverse industries and has spent the last 15 years in the Life Sciences and Health Care sectors. He is responsible for driving the organizations technology strategy, driving innovation, optimizing IT operations, protecting the company's assets, and optimizing business productivity. He is accountable for setting the directional security strategy and continuous improvement plans. He brings a wealth of experience leading and partnering with legal, compliance and audit teams, and leading cybersecurity and enterprise risk management teams.

We also work with a managed security service provider to monitor for vulnerabilities and threats. The service provider has the authority to take remedial actions for critical and high vulnerabilities, which are reported to the Cyber Security and Risk Management Team, and where appropriate, to the CIO and other members of senior management. We engage employees in our cybersecurity efforts through quarterly mandatory security and awareness training as well as monthly simulated phishing campaigns. We also conduct specific training and tabletop exercises for key personnel involved in cybersecurity risk management.

Cybersecurity Risk Management and Strategy

We maintain a cybersecurity program, which is informed by industry standards, that includes processes for identification, assessment, and management of cybersecurity risks and which is integrated into our larger enterprise-wide risk management program. We conduct periodic risk assessments, including support from external vendors, to assess our cyber program, identify areas of enhancement, and develop strategies for the mitigation of cyber risks. We also conduct regular security penetration testing and have established a vulnerability management process supported by security testing, to treat identified security risks based on severity. Third parties that access, process, collect, share, create, store, transmit or destroy our information or have access to our systems may have additional contractual controls.

Our Cyber Security and Risk Management Team is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity risks through various means, including leveraging managed security service providers and other

third-party security software and technology services. In addition, we institute processes and technologies for the monitoring of security alerts from internal parties and external resources, including from information security research sources. We also have implemented processes and technologies for network monitoring and data loss prevention.

We do not believe that risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected us, our business strategy, results of operations or financial condition. There is no guarantee that future incidents will not have a material impact on our business strategy, results of operations, or financial condition in the future. Refer to Part I, Item 1A, “Risk Factors,” included in this Annual Report on Form 10-K for more information.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

We maintain a cybersecurity program, which is informed by industry standards, that includes processes for identification, assessment, and management of cybersecurity risks and which is integrated into our larger enterprise-wide risk management program. We conduct periodic risk assessments, including support from external vendors, to assess our cyber program, identify areas of enhancement, and develop strategies for the mitigation of cyber risks. We also conduct regular security penetration testing and have established a vulnerability management process supported by security testing, to treat identified security risks based on severity. Third parties that access, process, collect, share, create, store, transmit or destroy our information or have access to our systems may have additional contractual controls.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Our Board of Directors (the “Board”) holds overall oversight responsibility for the Company’s strategy and risk management, including in relation to cybersecurity risks. Our Board exercises its oversight function through the Audit Committee, which oversees the management of risk exposure across various areas, including data security risks, in accordance with its charter. The Audit Committee receives quarterly reports from our Chief Information Officer (“CIO”) on the status of the Company’s cybersecurity program, including measures implemented to monitor and address cybersecurity risks and threats, as appropriate.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board of Directors (the “Board”) holds overall oversight responsibility for the Company’s strategy and risk management, including in relation to cybersecurity risks.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board exercises its oversight function through the Audit Committee, which oversees the management of risk exposure across various areas, including data security risks, in accordance with its charter.
Cybersecurity Risk Role of Management [Text Block]

The Company has an enterprise risk management committee (“ERMC”) that is composed of senior management, including the CIO and other senior executives. The ERMC monitors and oversees risk areas that could have a high impact on the business, and cybersecurity is currently one of the ERMC’s priority focus areas. The ERMC reports on our top identified risks and steps to address those risks to the full Board on a semi-annual basis.

At the management level, our Senior Director of Cyber Security and IT Risk Management is primarily responsible for leading our cybersecurity strategy for assessing and managing material risks from cybersecurity threats. He has over 20 years of cybersecurity experience across a wide array of industries, specializing in enterprise security strategy, regulatory compliance and building high-performing cyber programs that support global business operations. Our Senior Director of Cyber Security and IT Risk Management reports directly to our CIO, who is a member of our leadership team and reports to our Chief Financial Officer. Our current CIO has over 29 years of global IT leadership experiences across diverse industries and has spent the last 15 years in the Life Sciences and Health Care sectors. He is responsible for driving the organizations technology strategy, driving innovation, optimizing IT operations, protecting the company's assets, and optimizing business productivity. He is accountable for setting the directional security strategy and continuous improvement plans. He brings a wealth of experience leading and partnering with legal, compliance and audit teams, and leading cybersecurity and enterprise risk management teams.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The ERMC reports on our top identified risks and steps to address those risks to the full Board on a semi-annual basis.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]

At the management level, our Senior Director of Cyber Security and IT Risk Management is primarily responsible for leading our cybersecurity strategy for assessing and managing material risks from cybersecurity threats. He has over 20 years of cybersecurity experience across a wide array of industries, specializing in enterprise security strategy, regulatory compliance and building high-performing cyber programs that support global business operations. Our Senior Director of Cyber Security and IT Risk Management reports directly to our CIO, who is a member of our leadership team and reports to our Chief Financial Officer. Our current CIO has over 29 years of global IT leadership experiences across diverse industries and has spent the last 15 years in the Life Sciences and Health Care sectors. He is responsible for driving the organizations technology strategy, driving innovation, optimizing IT operations, protecting the company's assets, and optimizing business productivity. He is accountable for setting the directional security strategy and continuous improvement plans. He brings a wealth of experience leading and partnering with legal, compliance and audit teams, and leading cybersecurity and enterprise risk management teams.

Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]

Our Cyber Security and Risk Management Team is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity risks through various means, including leveraging managed security service providers and other

third-party security software and technology services.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true