Singular Genomics Systems, Inc. - (OMIC)

10-K Filing Date: March 18, 2024
Item 1C. Cybersecurity

Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of our risk management program, including cybersecurity and other information technology risks. The Audit Committee receives periodic reports from management on our cybersecurity risks. In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as any incidents with lesser impact potential. The Audit Committee reports to the full Board regarding its activities, including those related to cybersecurity.

Our management team, including each of our Chief Financial Officer, Head of IT and General Counsel, is responsible for assessing and managing our material risks from cybersecurity threats. The team has primary responsibility for our overall cybersecurity risk management program and supervises our internal cybersecurity personnel. Our management team’s cumulative experience includes many years of experience managing cybersecurity risks including serving in similar roles leading and overseeing cybersecurity programs at other companies.

Our management team supervises efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants; and alerts and reports produced by security tools deployed in the information technology environment.

We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity and availability of our critical systems and information. Our cybersecurity risk management program includes a cybersecurity incident response plan. We design and assess our program based on the Center for Internet Security (“CIS”) Controls. While this does not imply that we meet any particular technical standards, specifications or requirements, we use the CIS Controls framework as a guide to help us identify, assess and manage cybersecurity risks relevant to our business.

Our cybersecurity risk management program is integrated into our overall enterprise risk management program, and shares common reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, operational and financial risk areas. Our cybersecurity risk management program includes: (i) risk assessments designed to help identify material cybersecurity risks to our critical systems, information, products, services and our broader enterprise information technology environment; (ii) full-time internal subject matter experts and a service desk with extensive security knowledge and skill responsible for managing our cybersecurity risk assessment processes, our security controls and our response to cybersecurity incidents; (iii) the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls; (iv) cybersecurity awareness training of our employees; and (v) a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents.

We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations or financial condition.