Arcturus Therapeutics Holdings Inc. 10-K Cybersecurity GRC - 2024-03-14

Page last updated on April 11, 2024

Arcturus Therapeutics Holdings Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-03-14 09:09:33 EDT.

Filings

10-K filed on 2024-03-14

Arcturus Therapeutics Holdings Inc. filed an 10-K at 2024-03-14 09:09:33 EDT
Accession Number: 0000950170-24-031156

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cyber security Risk management and strategy We recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data. Managing Material Risks & Integrated Overall Risk Management We have implemented tools, processes and strategies to promote a company-wide culture of cybersecurity risk management. This ensures that cybersecurity considerations are an integral part of our decision-making processes at every level. Our IT Department works closely with our leadership and key operating personnel to evaluate and address cybersecurity risks in alignment with our business objectives and operational needs. Engage Third-parties on Risk Management Due to the complexity and evolving nature of cybersecurity threats, we engage with a range of external experts, including but not limited to cybersecurity assessors, consultants, and auditors to evaluate and test our risk management systems. These partnerships enable us to leverage specialized knowledge and insights, to help ensure our cybersecurity strategies and processes remain at the forefront of industry best practices. Our collaborations with these third-parties includes regular audits, threat assessments, 24-hour monitoring, and consultation on security enhancements. Oversee Third-party Risk Because we are aware of the risks associated with third-party service providers, we conduct thorough security assessments of all third-party providers before engagement to ensure compliance with industry cybersecurity standards and frameworks. This includes assessments performed by our Executive Director of IT, who oversees the Company’s cybersecurity function. Risks from Cybersecurity Threats We have not encountered cybersecurity challenges that have materially impaired our operations or financial standing. Governance We have implemented standard operating procedures to define the channels by which cybersecurity threats are communicated to the Company’s Board of Directors (the Board ). This ensures that The Board has oversight and effective governance in managing risks associated with cybersecurity threats. Board of Directors Oversight The Audit Committee of the Board (the Audit Committee ) is central to the Board s oversight of cybersecurity risks and bears the primary responsibility for this domain. The Audit Committee is composed of board members with diverse expertise including, risk management, and finance, equipping them to oversee cybersecurity risks effectively. The Audit Committee receives briefings on cybersecurity risks from the Executive Director of IT or the Chief Legal Officer as described below in Management s Role Managing Risk. Management s Role Managing Risk 78 The Executive Director of IT and the Chief Legal Officer ( CLO ) play a pivotal role in informing the Audit Committee on cybersecurity risks. They provide briefings to the Audit Committee on a regular basis, with a minimum frequency of once per year. These briefings encompass a broad range of topics, including: Current cybersecurity landscape and emerging threats Status of ongoing cybersecurity initiatives and strategies Incident reports and learnings from any cybersecurity events and Compliance with regulatory requirements and industry standards. Risk Management Personnel Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with the Executive Director of IT and the Associate Director of IT Infrastructure and Security. Our IT Leadership team oversees our governance programs, tests our compliance with standards, remediates known risks, stays informed of significant developments in the cybersecurity domain, and leads our employee training program. Monitor Cybersecurity Incidents The Executive Director of IT is continually informed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques. This ongoing knowledge acquisition is crucial for the effective prevention, detection, mitigation, and remediation of cybersecurity incidents. In cooperation with the Executive Director of IT, the Associate Director of IT Infrastructure and Security implements and oversees processes for the regular monitoring of our information systems. This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities. In the event of a cybersecurity incident, the Executive Director of IT is equipped with a well-defined incident response plan. This plan includes immediate actions to mitigate the impact and long-term strategies for remediation and prevention of future incidents. Reporting to Board of Directors The Executive Director of IT, in his capacity, regularly informs the Chief Financial Officer (CFO) and Chief Legal Officer (CLO) of all aspects related to cybersecurity risks and incidents. This ensures that the highest levels of management are kept abreast of the cybersecurity posture and potential risks facing us. Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the Board, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues. See Item 1A Risk Factors Risks Related to Business Operations and Industry.


Company Information

NameArcturus Therapeutics Holdings Inc.
CIK0001768224
SIC DescriptionPharmaceutical Preparations
TickerARCT - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndDecember 30