Eledon Pharmaceuticals, Inc. 10-K Cybersecurity GRC - 2024-03-28

Page last updated on April 11, 2024

Eledon Pharmaceuticals, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-03-28 16:30:53 EDT.

Filings

10-K filed on 2024-03-28

Eledon Pharmaceuticals, Inc. filed an 10-K at 2024-03-28 16:30:53 EDT
Accession Number: 0000950170-24-038091

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity. Strategy and Oversight We have implemented and maintain various information security processes designed to identify, assess and manage material risks from cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, and data related to our clinical studies and employees, or our information systems and the data contained therein. We retain a Chief Information Consultant to collaborate with the company, including the Chief Financial Officer, and Executive Leadership Team, to help identify, assess and manage the company s cybersecurity threats and risks. This group identifies and assesses risks from cybersecurity threats by monitoring and evaluating our threat environment using various methods including, for example, automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and actors, and evaluating threats reported to us. We also use a third-party security management vendor to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats. Depending on the environment, we implement and maintain various technical, physical, and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our information systems, including, for example, incident detection and response policy, route risk assessments, data encryption, network security controls, data segregation, access controls, physical security, asset management, tracking and disposal, systems monitoring, penetration testing, and cybersecurity insurance. As part of our information security program, we provide mandatory periodic training for all employees on how to identify potential cybersecurity risks and protect our resources and information. This training is supplemented by firmwide testing initiatives, including periodic phishing tests. Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes. For example, the Chief Information Consultant works with management to prioritize our risk management processes and mitigate cybersecurity threats that are more likely to lead to a material impact to our business. In addition, our Chief Financial Officer evaluates material risks from cybersecurity threats and, as appropriate, reports to the Audit Committee of the Board of Directors, which evaluates our overall enterprise risk. To date, we do not believe that known risks from cybersecurity threats, including as a result of any previous cybersecurity incidents that we are aware of, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations or financial condition. However, we can give no assurance that we have detected or protected against all such cybersecurity incidents or threats. For a description of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Part 1. Item 1A. Risk Factors in this Annual Report on Form 10-K, including the risk factor titled We depend on our information systems and those of our third-party collaborators, service providers, contractors or consultants. Our information systems, or those of our third-party collaborators, service providers, contractors or consultants, may fail or suffer cybersecurity incidents, which could result in a material disruption of our development programs or loss of data or compromise the privacy, security, integrity or confidentiality of sensitive information related to our business and have a material adverse effect on our reputation, business, financial condition or results of operations. 46 Table of Contents Governance Our Board addresses our cybersecurity risk management as part of its general oversight function. The Audit Committee is responsible for overseeing our cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats. Our cybersecurity risk assessment and management processes are implemented and maintained by our Chief Financial Officer who oversees the work performed by our Chief Information Consultant. Our Chief Financial Officer is responsible for hiring appropriate consultants, helping to integrate cybersecurity risk considerations into our overall risk management strategy and communicating key priorities to relevant personnel. Our Chief Financial Officer, with support from our Chief Information Consultant, is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports. The Audit Committee receives periodic reports from our Chief Financial Officer concerning our significant cybersecurity threats and risks and the processes we have implemented to address them. The Audit Committee also receives various reports, summaries or presentations related to cybersecurity threats, risk and mitigation. The Chief Financial Officer also promptly informs and updates the Board about any information security incidents that may pose significant risk to our Company. The Chief Financial Officer has over 20 years of operations and leadership experience, including experience in information technology strategy and execution. The Chief Information Consultant has over 20 years of experience managing and securing technology infrastructure.


Company Information

NameEledon Pharmaceuticals, Inc.
CIK0001404281
SIC DescriptionPharmaceutical Preparations
TickerELDN - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndDecember 30