CVRx, Inc. 10-K Cybersecurity GRC - 2024-02-09

Page last updated on April 11, 2024

CVRx, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-02-09 16:04:22 EST.

Filings

10-K filed on 2024-02-09

CVRx, Inc. filed an 10-K at 2024-02-09 16:04:22 EST
Accession Number: 0001558370-24-000932

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity Risk management and strategy We rely on our information technology to operate our business and provide our Barostim Therapy to patients. We have policies and processes designed to protect our information technology systems, some of which are managed by third parties, and resolve issues in a timely manner in the event of a cybersecurity threat or incident. As part of our broader risk management framework, we have identified the potential cybersecurity risks to our business. We have designed our business applications and hosting services to minimize the impact that cybersecurity incidents could have on our business and have identified back-up systems where appropriate. We seek to further mitigate cybersecurity risks through a combination of monitoring and detection activities, use of anti-malware applications, employee training, quality audits and communication and reporting structures, among other processes. We have an incident response plan in place that outlines containment, eradication and recovery plans in the event of a cybersecurity threat or incident. We engage a third-party consultant to assist us with designing controls and our cybersecurity risk management framework. We are also engaging with a third party to perform penetration testing. We also retain third parties to assist with the monitoring and detection of cybersecurity threats and responding to any cybersecurity threats or incidents. 71 Table of Contents With respect to third parties that manage or use our information technology or data, we obtain reports to assess the security of their systems and processes. We engage in ongoing monitoring of all third-party providers to ensure compliance with our cybersecurity standards. We have not encountered cybersecurity threats or incidents that have had a material impact on our business. Governance Our Board of Directors recently assigned specific oversight responsibility for cybersecurity to our Audit Committee, which also oversees our general risk management. The Audit Committee reviews and discusses with management our policies, practices and risks related to information security and cybersecurity. Our chief financial officer has primary responsibility for assessing, monitoring and managing cybersecurity risks. Leaders of our information technology and device engineering, together with members of our finance team, comprise our Cybersecurity Committee, which meets to assess cybersecurity risks and identify new risks and assess our risk management framework on a quarterly basis. Among the members of this committee are employees who are knowledgeable about our products and systems, have prior experience managing cybersecurity risks, and maintain an active Certified Information Systems Security Professional certification. Our chief financial officer provides an update to the Audit Committee on any risks related to cybersecurity on a quarterly basis. Our incident response plan includes notifying the Audit Committee, and then the Board of Directors, of any material threats or incidents that arise.


Company Information

NameCVRx, Inc.
CIK0001235912
SIC DescriptionSurgical & Medical Instruments & Apparatus
TickerCVRX - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Emerging growth company
Fiscal Year EndDecember 30