MEDICINOVA INC - (MNOV)

10-K Filing Date: February 15, 2024
Item 1C. Cybersecurity

We continue to augment the capabilities of our people, processes, and technologies in order to address our cybersecurity risks. Our cybersecurity risks, and the controls designed to mitigate those risks, are integrated into our overall risk management governance and are reviewed yearly by our Board of Directors.

Risk Management and Strategy

As of December 31, 2023, we have implemented a set of comprehensive cybersecurity and data protection policies and procedures. Risks from cybersecurity threats are regularly evaluated as a part of our broader risk management activities and as a fundamental component of our internal control system. Our employees and contractors receive annual cybersecurity awareness trainings, including specific topics related to social engineering and email frauds. We have capable employees and consultants with significant expertise in cybersecurity related to our industry. We invest in advanced technologies for continuous cybersecurity monitoring across our information technology environment which are designed to prevent, detect, and minimize cybersecurity attacks, as well as alert management of such attacks.

Our Information Technology General Controls are firmly established based on recognized industry standards and cover areas such as risk management, data backup, and disaster recovery. We have utilized an outsourced information technology consultant to reduce and monitor security threats and vulnerabilities and respond to all cybersecurity incidents affecting us, including prompt escalation and communication of major security incidents to senior business leadership and our Board of Directors.

Governance

Our Board of Directors is responsible for overseeing our cyber security risk management and strategy. Our senior leadership, including our Chief Executive Officer and Chief Financial Officer, regularly meets with and provides periodic briefings to our Board of Directors regarding our cybersecurity risks and activities, including any recent cybersecurity incidents and related responses, cybersecurity systems testing, activities of third parties, and the like.

67


 

Cybersecurity Threat Disclosure

To date, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect the Company.

For further discussion of cybersecurity risks, please see Item 1A, "Risk Factors".