RxSight, Inc. 10-K Cybersecurity GRC - 2024-02-28

Page last updated on July 16, 2024

RxSight, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-02-28 16:10:44 EST.

Filings

10-K filed on 2024-02-28

RxSight, Inc. filed a 10-K at 2024-02-28 16:10:44 EST
Accession Number: 0000950170-24-022073

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecur ity Governance One of the key functions of our board of directors is informed oversight of our risk management process, including risks from cybersecurity threats. Our board of directors administers its cybersecurity risk oversight function directly as a whole, as well as through the Audit Committee pursuant to its charter. Our Audit Committee is primarily responsible for monitoring and assessing strategic risk exposure and receives periodic updates from management at Audit Committee meetings regarding cybersecurity threat risks and management’s strategies to manage the same, and our management is responsible for the day-to-day management of the material risks we face. Our Audit Committee reports to the board of directors regarding its activities, including with respect to cybersecurity risk oversight as appropriate, on a quarterly basis. Risk Management and Strategy We have established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats and have processes for monitoring and assessing strategic risk exposures and reporting to the Audit Committee and board of directors. We regularly assess material risks from cybersecurity threats, including any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or any information residing within our IT infrastructure. We conduct periodic risk assessments to identify cybersecurity threats that may affect information systems that may be vulnerable to cybersecurity threats. These risk assessments include identification of reasonably foreseeable internal and external risks and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks. Following these risk assessments, if necessary, we implement and maintain reasonable safeguards to minimize identified risks and regularly monitor the effectiveness of our safeguards. We devote significant resources, including engaging experienced consultants and designate senior-level information technology management (“IT management”) to manage the risk assessment and mitigation process. Personnel tasked with managing cybersecurity risks periodically report to senior management and the Audit Committee. We use automated tools and trained personnel to maintain real-time threat monitoring and 24x7 alerting of all of our IT infrastructure and endpoints. We leverage various software tools, internal personnel and consultants to identify, triage, escalate and remediate threats. In the event of a security incident, we follow communication protocols to alert senior-level management as to the nature and severity of the threat while leveraging consultants and forensic tools to contain, document and mitigate the threat. As part of our overall risk management system, IT management monitors and tests our safeguards and trains our employees on these safeguards. Personnel at all levels and departments are made aware of our cybersecurity policies and risks through communication and trainings. We have engaged, and expect to continue to engage, consultants, or other third parties in connection with our risk assessment processes. These providers assist us in designing and implementing our cybersecurity policies and procedures, as well as monitoring and testing the design of our processes. To oversee and identify risks from cybersecurity threats associated with our use of third-party service providers we expect them to implement and maintain reasonable security measures in connection with their work with us, and to promptly report any suspected breach of its security measures that may affect us. For additional information regarding whether any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect our company, including our business strategy, results of operations, or financial condition, please refer to Item 1A, “Risk Factors,” in this report, including the risk factor entitled “We may experience a significant disruption in our information technology systems or breaches of data security” and “Unauthorized third parties may seek to access our devices or other products and services, or related devices, products, and services, and modify or use them in a way inconsistent with our FDA clearances and approvals, which may create risks to users.” As of the date of this report, we do not believe that we have experienced a material cybersecurity incident. 82


Company Information

NameRxSight, Inc.
CIK0001111485
SIC DescriptionOphthalmic Goods
TickerRXST - Nasdaq
Website
CategoryLarge accelerated filer
Smaller reporting company
Fiscal Year EndDecember 30