Page last updated on February 19, 2026
ARDELYX, INC. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2026-02-19 16:05:34 EST.
Filings
10-K filed on 2026-02-19
ARDELYX, INC. filed a 10-K at 2026-02-19 16:05:34 EST
Accession Number: 0001437402-26-000013
Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!
Item 1C. Cybersecurity.
ITEM 1C. CYBERSECURITY Cybersecurity Risk Management and Strategy We maintain a comprehensive cybersecurity risk management program designed to protect the confidentiality, integrity and availability of our systems and information. We design, assess and benchmark our program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework. This does not imply that we meet any particular technical standards, specifications or requirements, only that we use NIST as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. Our cybersecurity risk management program is integrated into our overall risk management program, and shares common methodologies, reporting channels and governance processes that apply across the risk management program, in areas such as legal, compliance, strategic, operational and financial risk. 53 Table of Co n t e n t s Key elements of our cybersecurity program include but are not limited to the following: - risk assessments designed to help identify material risks from cybersecurity threats to our critical systems and information; - a security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls and (3) our response to cybersecurity incidents; - the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes; - cybersecurity awareness training of our employees, including incident response personnel and senior management; - a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents; and - a third-party risk management process for key service providers based on our assessment of their criticality to our operations and respective risk profile, suppliers and vendors that have access to our critical systems and information based on our assessment of their criticality to our operations and respective risk profile. We have not experienced any cybersecurity incidents that have materially affected our operations, business strategy, financial condition or results of operations. We face risks from cybersecurity threats that, if realized are reasonably likely to materially affect us, including our operations, business strategy, results of operations or financial condition. For more information, see the section titled "Risk Factors- We and our collaborators, CROs and other contractors and consultants depend on information technology systems, and any failure of these systems could harm our business. Security breaches, loss of data, and other disruptions could compromise sensitive information related to our business or prevent us from accessing critical information and expose us to liability, which could adversely affect our business, results of operations and financial condition ." Cybersecurity Governance Our board of directors considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit and Compliance Committee (Audit Committee) oversight of cybersecurity risks, including oversight of management's implementation of our cybersecurity risk management program, maintains a strategic role in coordinating cyber risk initiatives and policies, and confirming their efficacy. The Audit Committee receives annual reports from management on our cybersecurity posture. In addition, management updates the Committee where it deems appropriate regarding any cybersecurity incidents it considers to be significant or potentially significant. The Audit Committee reports to the full board of directors regarding its activities, including those related to cybersecurity. The board of directors also receives periodic briefings from management on our cybersecurity program. The board members receive presentations on cybersecurity topics from our Chief Information Officer, internal security personnel or external experts as part of the board of directors' continuing education on topics that impact public companies. Our cybersecurity risk management program operates through a structured governance framework with oversight at multiple organizational levels. The IT Steering Committee, comprised of our Chief Information Officer, Chief Financial Officer and other members of management, meets quarterly to provide strategic oversight on technology investments, risk management and cybersecurity initiatives. The Audit Committee maintains independent oversight through quarterly reviews of security maturity, incidents and strategic investments. Ongoing governance includes monthly executive dashboards, Sarbanes-Oxley IT controls monitoring and annual security tabletop exercises. Our Chief Information Officer leads the program day-to-day, supervising internal cybersecurity personnel and external consultants, supported by cross-functional leadership with decades of combined experience in cybersecurity and risk management across commercial biotechnology organizations. Our Chief Information Officer has over 25 years of experience in overseeing cybersecurity and risk management. Our management team takes steps to stay informed about and monitor efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us and alerts and reports produced by security tools deployed in our IT environment. 54 Table of Co n t e n t s
Company Information
| Name | ARDELYX, INC. |
| CIK | 0001437402 |
| SIC Description | Pharmaceutical Preparations |
| Ticker | ARDX - Nasdaq |
| Website | |
| Category | Large accelerated filer |
| Fiscal Year End | December 31 |