XML 79 R10.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management, Strategy, and Governance
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Item 1C. Cybersecurity.

We recognize the importance of maintaining the trust and confidence of our patients, our collaborators, our business partners, our investors, and our employees and understand how key it is to maintain their confidence in our ability to properly protect and manage our information technology systems, infrastructure and data as part of that trust and confidence. In order to achieve this, our management team and our Board of Directors are actively involved in the oversight of our cybersecurity program as part of our approach to risk management.

For a description of the risks from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under Part I. Item 1A. Risk Factors in this Annual Report on Form 10-K, including "We are dependent on the efficient and uninterrupted operation of our information technology systems, and those systems, or those of our third-party service providers, may be impacted by security incidents, cyberattacks, loss of data and other disruptions, which could adversely impact our business."

Governance

Our cybersecurity risk assessment and management processes are implemented and maintained by certain management, including our Senior Director of Information Technology, who has more than two decades of information technology and information technology leadership experience. Our Senior Director of Information Technology, under the supervision of our Chief Financial Officer, manages and monitors our cybersecurity risk (including that presented by our information technology service providers) and is responsible for the day-to-day management of our cybersecurity program, including processes relating to the assessment, identification, prevention, detection, mitigation and remediation of cybersecurity threats and incidents. Our Senior Director of Information Technology is responsible for informing our Chief Financial Officer of relevant cybersecurity risks including, as relevant, the prevention, detection, mitigation and remediation of cybersecurity incidents. Our Chief Financial Officer has over two decades of management experience, including oversight over information technology and cybersecurity matters.

Our Board of Directors, with the assistance of the Audit Committee, has oversight for the cybersecurity risks facing us and for our processes designed to identify, prioritize, assess, manage, and mitigate those risks. As part of its oversight responsibilities, the Audit Committee receives periodic updates from management regarding cybersecurity risks, including the Company’s cybersecurity posture, significant threats, and relevant incidents, if any.

Risk management and strategy

We depend on the functioning, availability and security of our information systems, including financial, data processing, communications and operating systems. Several information systems, such as software applications and cloud platforms, are provided by third parties. Our cybersecurity risk framework is designed to allow us to identify, assess and manage the cybersecurity risks we face in relation to our systems and the information we process.

As part of our framework, we maintain certain processes designed to assess, identify and manage risks. For example, we maintain an incident management and response process under which significant cybersecurity threats and incidents are escalated to appropriate management and, where appropriate, reported to the Audit Committee; use manual and automated processes that are designed to monitor relevant information systems for vulnerabilities, threats and incidents; manage and take certain actions designed to address incidents that may occur; and take actions designed to remediate certain vulnerabilities identified in relevant environments. We employ an array of data security technologies, processes, and methods across our infrastructure designed to help protect our systems and sensitive information from unauthorized access. We work with information technology consultants who provide advice and expertise on monitoring evolving industry practices. Our cybersecurity processes also include employee cybersecurity awareness activities and administrative and technical controls designed to help protect the confidentiality, integrity and availability of our information systems and data.

Our assessment and management of material risks from cybersecurity threats are integrated into the Company’s overall risk management processes. For example, certain management executives, including our Senior Director of Information Technology and Chief Financial Officer, evaluate material risks from cybersecurity threats in connection with our overall business objectives and report such evaluations to the Audit Committee of the board of directors as appropriate, which then evaluates our overall enterprise risks.

In addition to the third parties above, we use additional third-party service providers to perform a variety of functions throughout our business, such as enterprise and employee management platforms, labs, contract research organizations, contract manufacturing organizations, and supply chain resources. Depending on the nature of the services provided, the sensitivity of the information systems and data at issue, and the identity of the provider, we take steps designed to address cybersecurity risks that such service providers may present to us, such as conducting diligence into such service providers’ cybersecurity practices and risk profiles and, where appropriate, implementing contractual protections and ongoing oversight designed to mitigate cybersecurity risks associated with those service providers.

To date, we have not identified any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business strategy, results of operations or financial condition.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We work with information technology consultants who provide advice and expertise on monitoring evolving industry practices. Our cybersecurity processes also include employee cybersecurity awareness activities and administrative and technical controls designed to help protect the confidentiality, integrity and availability of our information systems and data.Our assessment and management of material risks from cybersecurity threats are integrated into the Company’s overall risk management processes
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Governance

Our cybersecurity risk assessment and management processes are implemented and maintained by certain management, including our Senior Director of Information Technology, who has more than two decades of information technology and information technology leadership experience. Our Senior Director of Information Technology, under the supervision of our Chief Financial Officer, manages and monitors our cybersecurity risk (including that presented by our information technology service providers) and is responsible for the day-to-day management of our cybersecurity program, including processes relating to the assessment, identification, prevention, detection, mitigation and remediation of cybersecurity threats and incidents. Our Senior Director of Information Technology is responsible for informing our Chief Financial Officer of relevant cybersecurity risks including, as relevant, the prevention, detection, mitigation and remediation of cybersecurity incidents. Our Chief Financial Officer has over two decades of management experience, including oversight over information technology and cybersecurity matters.

Our Board of Directors, with the assistance of the Audit Committee, has oversight for the cybersecurity risks facing us and for our processes designed to identify, prioritize, assess, manage, and mitigate those risks. As part of its oversight responsibilities, the Audit Committee receives periodic updates from management regarding cybersecurity risks, including the Company’s cybersecurity posture, significant threats, and relevant incidents, if any.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our Board of Directors, with the assistance of the Audit Committee, has oversight for the cybersecurity risks facing us and for our processes designed to identify, prioritize, assess, manage, and mitigate those risks.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] As part of its oversight responsibilities, the Audit Committee receives periodic updates from management regarding cybersecurity risks, including the Company’s cybersecurity posture, significant threats, and relevant incidents, if any.
Cybersecurity Risk Role of Management [Text Block]

Our cybersecurity risk assessment and management processes are implemented and maintained by certain management, including our Senior Director of Information Technology, who has more than two decades of information technology and information technology leadership experience. Our Senior Director of Information Technology, under the supervision of our Chief Financial Officer, manages and monitors our cybersecurity risk (including that presented by our information technology service providers) and is responsible for the day-to-day management of our cybersecurity program, including processes relating to the assessment, identification, prevention, detection, mitigation and remediation of cybersecurity threats and incidents. Our Senior Director of Information Technology is responsible for informing our Chief Financial Officer of relevant cybersecurity risks including, as relevant, the prevention, detection, mitigation and remediation of cybersecurity incidents. Our Chief Financial Officer has over two decades of management experience, including oversight over information technology and cybersecurity matters.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our cybersecurity risk assessment and management processes are implemented and maintained by certain management, including our Senior Director of Information Technology, who has more than two decades of information technology and information technology leadership experience.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Financial Officer has over two decades of management experience, including oversight over information technology and cybersecurity matters.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our Senior Director of Information Technology, under the supervision of our Chief Financial Officer, manages and monitors our cybersecurity risk (including that presented by our information technology service providers) and is responsible for the day-to-day management of our cybersecurity program, including processes relating to the assessment, identification, prevention, detection, mitigation and remediation of cybersecurity threats and incidents
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true