XML 78 R26.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We have processes for assessing, identifying and managing cybersecurity risks, which are built into our information technology function and are designed to provide protection for our information assets and operations from internal and external cyber threats, including protecting employee and patient information from unauthorized access or attack, as well as secure our networks and systems. These processes include physical, procedural and technical safeguards, response plans, regular tests on our systems, incident simulations and routine reviews of our policies and procedures to identify risks and enhance our practices. As part of our overall risk mitigation strategy, we maintain cyber insurance coverage; however, such insurance may not be sufficient in type or amount to cover us against claims related to security breaches, cyber-attacks and other related breaches. We have engaged external parties, including consultants, computer security firms and risk management, and legal and governance experts, to enhance our cybersecurity oversight. We also employ processes to identify material risks from cybersecurity threats associated with our use of third-party service providers.
Based on an assessment using the previously described risk mitigation strategy, we do not believe there are currently any risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. See “Our internal computer systems and those of our collaborators, CROs, CDMOs contractors, consultants and other third parties are vulnerable to cyber attacks, cyber intrusions and security breaches, which could not only materially disrupt our business operations and result in the loss of confidential information, but could also damage the integrity of our clinical trials, impact our regulatory filings, compromise our ability to protect our intellectual property, and subject us to regulatory actions that could result in significant fines or other penalties” in Part I, Item 1A. “Risk Factors” for additional information.
In an effort to deter and detect cyber threats, we periodically provide our workforce, including all employees and contingent staff, with a privacy, data protection, cybersecurity and incident response, and prevention education and awareness program, which includes annual and supplemental training covering a range of timely and relevant topics. Past topics have included social engineering, phishing, password protection, confidential data protection, asset use, and mobile security. This education and awareness program functions to educate employees on the importance of reporting all incidents immediately. In addition, we perform monthly phishing test campaigns to reinforce identification and reporting training. We automatically assign online reinforcement training upon initial phish test failure and may follow-up one-on-one as needed, including providing additional training. We also use technology-based tools to mitigate cybersecurity risks and to bolster our employee-based cybersecurity programs. Lastly, we perform annual penetration tests conducted by independent, third-party cybersecurity firms and ongoing vulnerability assessments conducted by the internal security team
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We have processes for assessing, identifying and managing cybersecurity risks, which are built into our information technology function and are designed to provide protection for our information assets and operations from internal and external cyber threats, including protecting employee and patient information from unauthorized access or attack, as well as secure our networks and systems. These processes include physical, procedural and technical safeguards, response plans, regular tests on our systems, incident simulations and routine reviews of our policies and procedures to identify risks and enhance our practices.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our Audit Committee of our board of directors, or the Audit Committee, provides direct cybersecurity risk oversight, and provides regular updates to the board of directors regarding such oversight. The Audit Committee receives quarterly updates from management and the Cybersecurity Board, as discussed in further detail below, regarding cybersecurity matters, and is notified between such updates regarding significant new cybersecurity risks, threats or incidents. We also provide updates to the full board of directors regarding cybersecurity risks, threat landscape and risks, as appropriate.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Audit Committee of our board of directors, or the Audit Committee, provides direct cybersecurity risk oversight, and provides regular updates to the board of directors regarding such oversight.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee receives quarterly updates from management and the Cybersecurity Board, as discussed in further detail below, regarding cybersecurity matters, and is notified between such updates regarding significant new cybersecurity risks, threats or incidents. We also provide updates to the full board of directors regarding cybersecurity risks, threat landscape and risks, as appropriate.
Cybersecurity Risk Role of Management [Text Block] We have a cross-functional Cybersecurity Board led by our Senior Vice President, Information Technology Systems & Security, or SVP ITSS, serving as the chair and consisting of executive-level and non-executive level leaders, including among others, our chief financial officer and general counsel. This board is responsible for reviewing, engaging and making decisions related to the execution and continuous improvement of cybersecurity strategy, processes and governance impacting our information systems, employees, partners and patients. Our SVP, ITSS, leads the operational oversight of company-wide cybersecurity strategy, policy, standards and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] We have a cross-functional Cybersecurity Board led by our Senior Vice President, Information Technology Systems & Security, or SVP ITSS, serving as the chair and consisting of executive-level and non-executive level leaders, including among others, our chief financial officer and general counsel.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our SVP, ITSS, is an experienced senior leader with more than 25 years of experience in information technology within the pharmaceutical industry leading a team of employees and consultants with a breadth of experience including security management experience along with Certified Information Systems Security Professional, or CISSP certification.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] This board is responsible for reviewing, engaging and making decisions related to the execution and continuous improvement of cybersecurity strategy, processes and governance impacting our information systems, employees, partners and patients. Our SVP, ITSS, leads the operational oversight of company-wide cybersecurity strategy, policy, standards and processes and works across relevant departments to assess and help prepare us and our employees to address cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true