Spyre Therapeutics, Inc. - (SYRE)

10-K Filing Date: February 29, 2024
ITEM 1C. CYBERSECURITY

In the ordinary course of our business, we collect, use, store, and transmit digitally confidential, sensitive, proprietary, personal, and health-related information. The secure maintenance of this information and our information technology systems is important to our operations and business strategy. To this end, we have implemented processes using the cybersecurity risk framework published by the National Institute of Standards and Technology ("NIST") designed to assess, identify, and manage risks from potential unauthorized occurrences on or through our information technology systems that may result in adverse effects on the confidentiality, integrity, and availability of these systems and the data residing therein. These processes are managed and monitored by a dedicated information technology team, which is led by our Senior Vice President, Operations and our Vice President, Information Technology ("IT"), and include mechanisms, controls, technologies, systems, and other processes designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable information technology environment. Specific measures include regular penetration and vulnerability testing, data recovery testing, security audits, and ongoing risk assessments. We conduct due diligence on and audits of key technology vendors, contract research organizations (CROs), and other third-party contractors and suppliers. Additionally, we conduct periodic employee training that covers cyber and information security, among other topics. We also regularly consult with outside advisors and experts. Their assistance helps us assess, identify, and manage cybersecurity risks, anticipate future threats and trends, and understand their potential impact on our risk environment.

Our Vice President, Information Technology, who reports directly to our Senior Vice President, Operations, has over 25 years of experience managing information technology and cybersecurity matters and is certified as Certified Information Systems Security Professional. Together with our Senior Vice President, Operations and the other members of our senior leadership team, our Vice President, Information Technology is responsible for assessing and managing cybersecurity risks. We consider cybersecurity, along with other significant risks that we face, within our overall enterprise risk management framework. In the last fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, but we face certain ongoing cybersecurity risks threats that, if realized, are reasonably likely to materially affect us. Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors,” under the heading “Our internal information technology systems, or those of any of our CROs, manufacturers, other contractors or consultants, third party service providers, or potential future collaborators, may fail or suffer security or data privacy breaches or other unauthorized or improper access to, use of, or destruction of our proprietary or confidential data, employee data or personal data, which could result in additional costs, loss of revenue, significant liabilities, harm to our brand and material disruption of our operations.”

The Board of Directors, as a whole and at the committee level, has oversight for the most significant risks facing us and for our processes to identify, prioritize, assess, manage, and mitigate those risks. The Audit Committee, which is comprised solely of independent directors, has been designated by our Board to oversee cybersecurity risks. The Audit Committee receives regular updates on cybersecurity and information technology matters and related risk exposures from our Vice President, Information Technology, as well as other members of the senior leadership team. The Board also receives updates from management and the Audit Committee on cybersecurity risks on at least an annual basis.