XML 45 R8.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management, Strategy and Governance
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Item 1C. Cybersecurity.

(a)
Cybersecurity Risk Management Strategy

We have developed our cybersecurity risk management program (Cybersecurity Framework), including a cybersecurity incident response plan, based on the National Institute of Standards and Technology Cybersecurity Framework’s (NIST CSF) principles: Identify, Protect, Detect, Respond, and Recover, and our Cybersecurity Framework is intended to address current vulnerabilities and anticipate future cybersecurity threats and risks to our cyber ecosystem. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.

Our Cybersecurity Framework is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas.

Our cybersecurity risk management program includes:

assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader enterprise IT environment;
a security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;
the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls;
cybersecurity awareness training for our employees, incident response personnel, and senior management;
a cybersecurity incident response process that includes procedures for responding to cybersecurity incidents; and
a risk evaluation of our service providers, suppliers, and vendors of critical systems during contracting.

We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. There can be no assurance, however, that our cybersecurity risk management program and processes, including our policies, controls or procedures, will be fully implemented, complied with or effective in protecting our systems and information. For more information, see Part I, Item 1A, “Risk Factors—Risks Related to the Operation of Our Business—Significant disruptions of our information technology systems or data security incidents could result in significant financial, legal, regulatory, business and reputational harm to us” of this Annual Report.

(b)
Cybersecurity Governance

Our board of directors considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of cybersecurity and other information technology risks. The Audit Committee oversees management’s implementation of our cybersecurity risk management strategy.

The Audit Committee receives periodic reports from management, including our IT Governance Team, on our cybersecurity risks. In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.

Our cybersecurity risk management and strategy processes are overseen by our IT Governance Team, which includes senior leadership across Finance, Project Management and Information Technology, Regulatory and Quality, and Legal, supported by external technical advisors. The IT Governance Team is responsible for assessing and managing cybersecurity risks, overseeing the implementation of our information security policies and procedures, and supervising the prevention, detection, mitigation, and remediation of cybersecurity incidents in accordance with our IT governance framework.

Our Senior Vice President of Program Management and Head of Information Technology has over 25 years of experience leading technology‑enabled programs and cross‑functional teams in biotechnology and other regulated environments. He provides executive oversight of our enterprise information systems and IT governance activities, integrating cybersecurity considerations into broader operational risk management, compliance, and business continuity processes.

Our Chief Financial Officer and Chief Operating Officer has over 20 years of experience in financial management, business operations, and corporate strategy, with extensive experience overseeing internal controls and enterprise governance. As part of our enterprise risk management framework, our Chief Financial Officer and Chief Operating Officer provides executive oversight of the cybersecurity risk management program, including supervision of third‑party service providers, escalation of cybersecurity matters to executive management, and reporting, as appropriate, to the Audit Committee.

To support execution of its cybersecurity program, we engage an outsourced managed service provider (the MSP) to provide day‑to‑day operational support for our information technology environment. The MSP operates under the direction of our management and supports the implementation of cybersecurity policies, controls, and incident response procedures, including ongoing monitoring, detection, remediation, and recovery activities consistent with our established cybersecurity framework. The MSP’s personnel includes experienced information technology and cybersecurity professionals with relevant industry certifications and experience in enterprise systems administration, security operations, and business continuity support.

We maintain formal information security policies, an incident response plan, and a designated incident response team, which are overseen by the IT Governance Team. Cybersecurity incidents are escalated through management in accordance with these procedures and, where appropriate, reported to the Audit Committee for matters involving material cybersecurity risk.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

Our Cybersecurity Framework is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our board of directors considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of cybersecurity and other information technology risks.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]

Our board of directors considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of cybersecurity and other information technology risks. The Audit Committee oversees management’s implementation of our cybersecurity risk management strategy.

Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]

The Audit Committee receives periodic reports from management, including our IT Governance Team, on our cybersecurity risks. In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential.

Our Senior Vice President of Program Management and Head of Information Technology has over 25 years of experience leading technology‑enabled programs and cross‑functional teams in biotechnology and other regulated environments. He provides executive oversight of our enterprise information systems and IT governance activities, integrating cybersecurity considerations into broader operational risk management, compliance, and business continuity processes.

Cybersecurity Risk Role of Management [Text Block]

Our cybersecurity risk management and strategy processes are overseen by our IT Governance Team, which includes senior leadership across Finance, Project Management and Information Technology, Regulatory and Quality, and Legal, supported by external technical advisors. The IT Governance Team is responsible for assessing and managing cybersecurity risks, overseeing the implementation of our information security policies and procedures, and supervising the prevention, detection, mitigation, and remediation of cybersecurity incidents in accordance with our IT governance framework.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The IT Governance Team is responsible for assessing and managing cybersecurity risks, overseeing the implementation of our information security policies and procedures, and supervising the prevention, detection, mitigation, and remediation of cybersecurity incidents in accordance with our IT governance framework.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]

Our Senior Vice President of Program Management and Head of Information Technology has over 25 years of experience leading technology‑enabled programs and cross‑functional teams in biotechnology and other regulated environments. He provides executive oversight of our enterprise information systems and IT governance activities, integrating cybersecurity considerations into broader operational risk management, compliance, and business continuity processes.

Our Chief Financial Officer and Chief Operating Officer has over 20 years of experience in financial management, business operations, and corporate strategy, with extensive experience overseeing internal controls and enterprise governance. As part of our enterprise risk management framework, our Chief Financial Officer and Chief Operating Officer provides executive oversight of the cybersecurity risk management program, including supervision of third‑party service providers, escalation of cybersecurity matters to executive management, and reporting, as appropriate, to the Audit Committee.

Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] As part of our enterprise risk management framework, our Chief Financial Officer and Chief Operating Officer provides executive oversight of the cybersecurity risk management program, including supervision of third‑party service providers, escalation of cybersecurity matters to executive management, and reporting, as appropriate, to the Audit Committee.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true