FENNEC PHARMACEUTICALS INC. 10-K Cybersecurity GRC - 2024-03-29

Page last updated on April 11, 2024

FENNEC PHARMACEUTICALS INC. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-03-29 16:14:02 EDT.

Filings

10-K filed on 2024-03-29

FENNEC PHARMACEUTICALS INC. filed an 10-K at 2024-03-29 16:14:02 EDT
Accession Number: 0001558370-24-004383

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersec urity Cybersecurity Risk Management and Strategy We, through our third -party service provider that manages our information technology systems and networks, have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information. Our cybersecurity risk management program includes a cybersecurity incident response plan. Our security policies and processes are based on industry best practices and are revisited regularly to ensure their appropriateness based on risk, threats and current technological capabilities. We regularly assess our threat landscape and monitor our systems and other technical security controls, maintain information security policies and procedures, including a breach response plan, ensure maintenance of backup and protective systems, and engage with a Managed Service Provider who has a team of security personnel managing our efforts and initiatives. We review System and Organization Controls 1 (SOC 1 Type II) certifications where relevant from key third party partners and other service providers with access to information assets at least annually. 63 Table of Contents We maintain Information Systems Incident Management Standards that are intended to ensure information security events and weaknesses associated with information systems are communicated and acted on in a timely manner. Our internal controls and procedures address cybersecurity and include processes intended to ensure that security breaches are reported to appropriate personnel and, if warranted, analyzed for potential disclosure. While we have experienced cybersecurity attacks, such attacks to date have not materially affected the Company or our business strategy, results of operations, or financial condition. Our cybersecurity risk management program includes: risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader enterprise IT environment designated team members are responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents and Maintain insurance coverage that is intended to address certain aspects of cybersecurity risks. To date, there have not been any cybersecurity threats that have materially affected the Company. Cybersecurity Governance Our Board considers cybersecurity risk as part of its risk oversight function and oversees our cybersecurity and other information technology risks and management s implementation of our cybersecurity risk management program. Our Board receives periodic reports from management on our cybersecurity risks. In addition, management updates the Board and the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential. Our management team, including our Chief Financial Officer, is responsible for assessing and managing our material risks from cybersecurity threats. Our Chief Financial Officer has primary responsibility for our overall cybersecurity risk management program and supervises our retained provider of IT services and external cybersecurity consultants. Our Chief Financial Officer has experience supervising and managing company security and privacy departments. Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from external security personnel threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us and alerts and reports produced by security tools deployed in the IT environment. 64 Table of Contents


Company Information

NameFENNEC PHARMACEUTICALS INC.
CIK0001211583
SIC DescriptionBiological Products, (No Diagnostic Substances)
TickerFENC - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndDecember 30