We anticipate that we will need to increase our insurance coverage when we begin clinical trials and if we successfully commercialize any product candidate. Insurance coverage is increasingly expensive. We may not be able to maintain insurance coverage at a reasonable cost or in an amount adequate to satisfy any liability that may arise.
Our internal computer and information technology systems, or those of our third-party vendors, collaborators, contractors, consultants or other third parties, may fail, become unavailable, or suffer security incidents or data breaches, loss or leakage of data and other disruptions, which could result in a material disruption of our product development programs, compromise confidential, sensitive or personal information related to our business or prevent us from accessing critical information, potentially exposing us to liability or otherwise adversely affecting our business.
Our internal computer and information technology systems and those of our current and any future third-party vendors, collaborators, contractors, consultants or other third parties, are vulnerable to damage or interruption from, among other things, computer viruses, computer hackers, social engineering attacks (including phishing attacks), ransomware, malware, social engineering, service interruptions, system malfunction, malicious code, employee theft, fraud, misconduct or misuse, denial-of-service attacks, sophisticated nation-state and nation-state-supported actors, wrongful conduct by insider employees or vendors, unauthorized access, natural disasters, terrorism, war and telecommunication and electrical failures. While we seek to protect our information technology systems from system failure, accident and cybersecurity incidents or data breaches, we and our third-party vendors, like other companies in our industry, have in the past and may in the future experience cybersecurity incidents which could result in a disruption of our development programs and our business operations, whether due to a loss of our trade secrets or other proprietary, personal or confidential information or other disruptions. For example, the loss of clinical trial data from future clinical trials could result in delays in our regulatory approval efforts and significantly increase our costs to recover or reproduce the data.
Controls employed by our information technology department and other third parties could prove inadequate, and our ability to monitor such third parties’ data security practices is limited. Due to applicable laws, rules, regulations and standards or contractual obligations, we may be held responsible for any information security failure or cybersecurity attack attributed to our third-party vendors as they relate to the information we share with them.
If we were to experience a cybersecurity incident, data breach, or other security event relating to our information systems or data, the costs, time and effort associated with the investigation, remediation and potential notification of the breach to counterparties, regulators and data subjects could be material. We may incur significant costs in an effort to detect and prevent security incidents or data breaches, and we may face increased costs and requirements to expend substantial resources in the event of an actual or perceived security incident or data breach. In addition, techniques used to sabotage or to obtain unauthorized access to networks in which data is stored or through which data is transmitted change frequently, become more complex over time and generally are not recognized until launched against a target. The risk of a cybersecurity incident, data breach, or other security event, particularly through cyberattacks including supply chain attacks such as SolarWinds or cyber intrusion, including by computer hackers, foreign governments, and cyber terrorists, has generally increased as the number, intensity, and sophistication of attempted attacks and intrusions from around the world have increased. As a result, we and our third-party vendors may be unable to anticipate these techniques or implement adequate preventative measures quickly enough to prevent either an electronic intrusion into our systems or services or a compromise of critical information. We cannot guarantee that we will be able to detect or prevent any such incidents, and our remediation efforts may not be successful or timely. Our efforts to improve security and protect data from compromise may also identify previously undiscovered instances of data breaches or other cybersecurity incidents. If we do not allocate and effectively manage the resources necessary to build and sustain the proper technology and cybersecurity infrastructure, we could suffer significant business disruption, including transaction errors, supply chain or manufacturing interruptions, processing inefficiencies, data loss or the loss of or damage to intellectual property or other proprietary, personal or confidential information.
To the extent that any cybersecurity incident, data breach, or other security event were to result in a loss of, or damage to, our or our third-party vendors’, collaborators’, contractors’, consultants’ or other third parties’ data, including personal information, or applications or inappropriate disclosure, loss, destruction or alteration of, or access to, confidential, personal or proprietary information, we would be required to notify affected stakeholders and could incur significant liability including litigation exposure, substantial penalties and fines, we could become the subject of regulatory action, inquiry or investigation, our competitive position could be harmed, we could incur significant reputational damage and the further development and commercialization of any product candidates we may develop could be delayed. Any of the above could have a material adverse effect on our business, financial condition, results of operations or prospects.