Loading...
Loading...
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
Item 1A. Risk Factors
We operate in a rapidly changing environment that involves a number of risks which could materially affect our business, financial condition or future results, some of which are beyond our control. In addition to the other information set forth in this Quarterly Report on Form 10-Q, the risks and uncertainties that we believe are most important for you to consider are discussed in Part I-Item 1A under the heading Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2023, as filed with the Securities and Exchange Commission (SEC) on February 22, 2024. The risk factors set forth below are risk factors containing changes, which may be material, from the risk factors previously disclosed in Item 1A of our Annual Report on Form 10-K for the fiscal year ended December 31, 2023, as filed with the SEC.
We have incurred significant losses since our inception. We expect to continue to incur losses over the next several years and may never achieve or maintain profitability.
We are a clinical development-stage biopharmaceutical company. In November 2013, we merged with Sonkei Pharmaceuticals, Inc. (Sonkei), and, in February 2014, we acquired Mind-NRG Sarl (Mind-NRG), which were also clinical development-stage biopharmaceutical companies. Investment in biopharmaceutical product development is highly speculative because it entails substantial upfront capital expenditures and significant risk that any potential product candidate will fail to demonstrate adequate effect or an acceptable safety profile, gain regulatory approval or become commercially viable. We have no products approved for commercial sale and have not generated any revenue from product sales to date, and we may never generate product revenue or achieve profitability. As of JuneSeptember 30, 2024, we had an accumulated deficit of approximately $413.6391.1 million.
In August 2022, we submitted a New Drug Application (NDA) with the U.S. Food and Drug Administration (FDA) for our lead product candidate, roluperidone, for the treatment of negative symptoms in schizophrenia. The FDA subsequently notified us that they would not accept the file for review, issuing a refusal to file letter (RTF) in October 2022. In December 2022, following a Type A meeting held on November 30, 2022, the FDA confirmed the RTF remained in effect with respect to our NDA for roluperidone. On May 1, 2023, we announced that the FDA filed our NDA for roluperidone on April 27, 2023. The decision to file the NDA followed our request for formal dispute resolution and appeal of the October 2022 RTF. On May 8, 2023, we received confirmation from the FDA that the NDA for roluperidone has been assigned a standard review classification, and that the FDA has assigned a Prescription Drug User Fee Act (PDUFA) goal date of February 26, 2024. The FDA advised that it identified potential review issues that had been previously cited in the RTF decision letter, which included those discussed at the Type C meeting in March 2022.
On February 26, 2024, the FDA issued a Complete Response Letter (the CRL) to our NDA for roluperidone for the treatment of negative symptoms in schizophrenia. The CRL provided that the FDA had completed its review of the NDA and had determined that it could not approve the NDA in its present form. Specifically, the FDA cited the following clinical deficiencies: (i) although one study (MIN-101C03) demonstrated statistical significance on the primary efficacy endpoint, it is insufficient on its own to establish substantial evidence of effectiveness; (ii) the NDA submission lacks data on concomitant antipsychotic administration; (iii) the NDA submission lacks data needed to establish that the change in negative symptoms of schizophrenia with roluperidone treatment was clinically meaningful; and (iv) the submitted safety database included an inadequate number of subjects exposed to roluperidone at the proposed dose (64 mg) for at least 12 months. To address these deficiencies, the FDA stated that we must submit at least one additional positive, adequate, and well-controlled study to support the safety and effectiveness of roluperidone for the treatment of negative symptoms. We must also provide additional data to demonstrate the safety and efficacy of roluperidone co-administered with antipsychotic medications, to support that observed effect on negative symptoms with roluperidone treatment corresponds to a clinically meaningful change, and to demonstrate the long-term safety of the proposed dose. See the section titled Item 2. Managements Discussion and Analysis of Financial Condition and Results of OperationsClinical and Regulatory UpdatesComplete Response Letter for more information. While we have continued to have interactions with the FDA since receiving the CRL, with the goal of addressing questions raised in the CRL, there can be no assurances that we will obtain approval for roluperidone in a timely manner, on favorable terms, or at all. As a result, the regulatory approval process for roluperidone in the United States is highly uncertain. If we do not obtain approval of roluperidone in the United States, or if the approval is delayed, it would have a
22
material adverse impact on our business. Even if we are able to obtain approval, the expense and time to do so could adversely impact our ability to successfully commercialize roluperidone or conduct our other business operations and our financial condition could be materially harmed.
We expect to continue to incur significant losses for the foreseeable future, and we expect these losses to increase as we continue our research and development of, and/or seek regulatory approvals for, roluperidone and other potential product candidates. If any of our product candidates fail in clinical trials or do not obtain regulatory approval, or if any of our product candidates, if approved, fail to achieve market acceptance, we may never generate revenue or become profitable. Even if we achieve profitability in the future, we may not be able to sustain profitability in subsequent periods. Failure to become and remain profitable may adversely affect the market price of shares of our common stock and our ability to raise capital and continue operations. We may encounter unforeseen expenses, difficulties, complications, delays and other unknown factors that may adversely affect our business. The size of our future net losses will depend, in part, on the rate of future growth of our expenses and our ability to generate revenues. Our prior losses and expected future losses have had and will continue to have an adverse effect on our results of operations, financial position and working capital.
We will require additional capital to finance our operations, which may not be available to us on acceptable terms, or at all. Failure to obtain this necessary capital when needed may force us to delay, limit or terminate our product development efforts or other operations.
Our operations and the historic operations of Sonkei and Mind-NRG have consumed substantial amounts of cash since inception. As of JuneSeptember 30, 2024, we had cash, cash equivalents, and restricted cash of $31.026.6 million. We believe that our existing cash, cash equivalents, and restricted cash will be sufficient to meet our cash commitments for at least the next 12 months after the date that our interim condensed financial statements are issued. The process of drug development can be costly, and the timing and outcomes of clinical trials are uncertain. The assumptions upon which we have based our estimates are routinely evaluated and may be subject to change. The actual amount of our expenditures will vary depending upon a number of factors, including, but not limited to, the design, timing and duration of future clinical trials, the progress of our research and development programs, the infrastructure to support a commercial enterprise, the cost of a commercial product launch, and the level of financial resources available.
We will require additional capital to continue advancing the development, regulatory approval process and potential commercialization of roluperidone and other potential product candidates that we may develop in the future. Because the length of time and activities associated with successful development of product candidates are highly uncertain, we are unable to estimate with certainty the actual funds we will require for development and any approved marketing and commercialization activities. Additional capital may not be available in sufficient amounts or on reasonable terms, if at all, and our ability to raise additional capital may be adversely impacted by global economic conditions, including the recent disruptions to and volatility in the credit and financial markets in the U.S. and worldwide resulting from the COVID-19 pandemic, geopogeopolitical conflicts, such as the war in Ukraine and hostilities in the Middle East, and other factors. Our future funding requirements, both short and long-term, will depend on many factors, including:
the initiation, progress, timing, costs and results of pre-clinical studies and clinical trials for our product candidates and future product candidates we may develop;
the outcome, timing and cost of seeking and obtaining regulatory approvals from the European Commission, FDA, and comparable foreign regulatory authorities, including the potential for such authorities to require that we perform more studies than those that we currently expect;
the cost to establish, maintain, expand and defend the scope of our intellectual property portfolio, including the amount and timing of any payments we may be required to make, or that we may receive, in connection with licensing, preparing, filing, prosecution, defense and enforcement of any patents or other intellectual property rights;
the effect of competing technological and market developments;
market acceptance of any approved product candidates;
the costs of acquiring, licensing or investing in additional businesses, products, product candidates and technologies; and
the cost of establishing sales, marketing and distribution capabilities for our product candidates for which we may receive regulatory approval and that we determine to commercialize ourselves or in collaboration with our partners.
If we are unable to raise additional capital in sufficient amounts or on terms acceptable to us, we may have to delay, limit or terminate the development or commercialization of one or more of our product candidates or other operations, including potentially discontinue operations altogether. In addition, when we need to secure additional financing, such additional fundraising efforts may divert our management from our day-to-day activities, which may adversely affect our ability to develop and commercialize our product
23
candidates. Any of these events could significantly harm our business, financial condition and prospects, and our stockholders could lose all or part of their investment in our company.
23
We cannot give any assurance that any of our product candidates will receive regulatory approval in a timely manner or at all, which is necessary before they can be commercialized.
The regulatory approval process is expensive and the time required to obtain approval from the European Commission (following the opinion of the Committee of Medicinal Products for Human Use of the European Medicines Agency (EMA)), FDA or other comparable regulatory authorities in other jurisdictions to sell any product is uncertain and may take years.
Whether regulatory approval will be granted is unpredictable and depends upon numerous factors, including the substantial discretion of the regulatory authorities. Moreover, the filing of an application for regulatory approval, including an NDA, or Biologics License Application (BLA), a Marketing Authorization Application (MAA) in the EEA, or comparable foreign regulatory applications for approval, requires a payment of a significant user fee upon submission. The filing of applications for regulatory approval of our product candidates may be delayed due to our lack of financial resources to pay such user fee.
If, following submission, our application is not accepted for substantive review or approved, the EMA, FDA or other comparable foreign regulatory authorities may require that we conduct additional clinical or pre-clinical trials, provide additional data, manufacture additional validation batches or develop additional analytical tests methods before they will reconsider our application. On October 14, 2022, we received a refusal-to-file communication from the FDA for our NDA submission for roluperidone, our lead product candidate, which decision was confirmed by the FDA in a subsequent Type A meeting. On April 27, 2023, the FDA filed our NDA for roluperidone following our request for formal dispute resolution and appeal of the refusal-to-file letter. On May 8, 2023, we received confirmation from the FDA that our NDA for roluperidone had been assigned a standard review classification and a PDUFA goal date of February 26, 2024. The FDA also advised that it identified potential review issues that had been previously cited in the RTF decision letter, which included those discussed at the Type C meeting in March 2022. See the section titled Item 2. Managements Discussion and Analysis of Financial Condition and Results of OperationsClinical and Regulatory UpdatesType C Meeting for more information. On February 26, 2024, the FDA issued a CRL to our NDA for roluperidone. See the section titled Item 2. Managements Discussion and Analysis of Financial Condition and Results of OperationsClinical and Regulatory UpdatesComplete Response Letter for more information. See also the risk factor above titled We have incurred significant losses since our inception. We expect to continue to incur losses over the next several years and may never achieve or maintain profitability. As a result of the CRL, we potentially need additional studies. Additional studies and data would impose increased costs and delays in the regulatory approval process, which may require us to expend more resources than we have available. In addition, the EMA, FDA or other comparable foreign regulatory authorities may not consider any additional required trials, data or information that we perform or provide to be sufficient, or we may decide, or be required, to abandon the program.
Moreover, policies, regulations, or the type and amount of pre-clinical and clinical data necessary to gain approval may change during the course of a product candidates clinical development and may vary among jurisdictions. It is possible that none of our existing product candidates or any of our future product candidates will ever obtain regulatory approval, even if we expend substantial time and resources seeking such approval.
Our product candidates could fail to receive regulatory approval for many reasons, including the following:
The EMA, FDA or other regulatory authorities may disagree with the design or implementation of our clinical trials.
We may be unable to demonstrate to the satisfaction of the EMA, the European Commission, the FDA or other comparable regulatory authorities that a product candidate is safe and effective for its proposed indication.
The results of clinical trials may not meet the level of statistical significance required by the EMA, the European
Commission, FDA or other regulatory authorities for approval.
We may be unable to demonstrate that a product candidates clinical and other benefits outweigh any safety risks.
The EMA, the European Commission, the FDA or other regulatory authorities may disagree with our interpretation of data from pre-clinical studies or clinical trials.
The data collected from clinical trials of our product candidates may not be sufficient to support an NDA or other submission or to obtain regulatory approval in the United States or elsewhere.
The national competent authorities of EU Member States, FDA or other regulatory authorities may fail to approve the manufacturing processes or facilities of third-party manufacturers with which we contract for clinical and commercial supplies.
24
The approval policies or regulations of the European Commission, FDA or other regulatory authorities may significantly change in a manner rendering our clinical data insufficient for approval.
24
Even if we obtain approval for a particular product, regulatory authorities may approve that product for fewer or more limited indications, including more limited patient populations, than we request, may require that contraindications, warnings, or precautions be included in the product labeling, including a boxed warning, may grant approval contingent on the performance of costly post-marketing clinical trials or other post-market requirements, including risk evaluation and mitigation strategies (REMS) or comparable foreign strategies, or may approve a product candidate with a label that does not include the labeling claims necessary or desirable for the successful commercialization of that product. Any of the foregoing could materially harm the commercial prospects for our product candidates.
Our common stock may be delisted from The Nasdaq Capital Market which could negatively impact the price of our common stock, liquidity and our ability to access the capital markets.
Our common stock is currently listed on The Nasdaq Capital Market under the symbol NERV. The listing standards of The Nasdaq Capital Market provide that a company, in order to qualify for continued listing, must maintain a minimum stock price of $1.00 and satisfy standards relative to minimum stockholders equity, minimum market value of publicly held shares and various additional requirements. If Nasdaq delists our securities from trading on its exchange for failure to meet the listing standards, we and our stockholders could face significant negative consequences including:
limited availability of market quotations for our securities;
a determination that the common stock is a penny stock which would require brokers trading in the common stock to adhere to more stringent rules, possibly resulting in a reduced level of trading activity in the secondary trading market for shares of common stock;
a limited amount of analyst coverage, if any; and
a decreased ability to issue additional securities or obtain additional financing in the future.
Delisting from The Nasdaq Capital Market could also result in other negative consequences, including the potential loss of confidence by suppliers, customers and employees, the loss of institutional investor interest and, fewer business development opportunities and potential liabilities arising from stockholder litigation or other disputes.
As previously reported, on April 10, 2024, we received a deficiency letter from Nasdaq notifying us that for the last 31 consecutive business days, the market value of listed securities (MVLS requirement) for our common stock had been below the minimum MVLS requirement of $35 million pursuant to Nasdaq Listing Rule 5550(b)(2) (the Rule). In accordance with the listing rules of Nasdaq, we have beenwere provided with a grace period of 180 calendar days, or until October 7, 2024, to regain compliance. If
As previously reported, on October 8, 2024, we do not regain received a second written notice from Nasdaq indicating that, based upon our continued non-compliance within the grace period, we expect that Rule, the staff of Nasdaq would provide notice thahad determined to delist our securities are subject to delisting.
Whilefrom The Nasdaq Capital Market unless we will continue to monitor our market value of litimely request a hearing before a Nasdaq Hearings Panel (the Panel). As a result, we have timely requested securities and consider available options to regaina hearing before the Panel, which had the effect of staying the delisting action pending the compliance with the MVLS requirements, which may include applying foretion of the hearing and the expiration of an y additional extension ofperiod granted by the compliance period or appealiPanel following the hearing. Under the Nasdaq Listing to a Nasdaq Hearings Panel, thRules, the Panel has the discretion to grant a further extension not to exceed April 5, 2025. Notwithstanding, there can be no assurance that we the Panel will be able to regrant us a further extension or that we will ultimately regain compliance with the MVLSall applicable requirements for otherwise maintain compliance with the othercontinued listing on The Nasdaq listing requirementsCapital Market.
In particular, our share price may continue to decline for a number of reasons, including many that are beyond our control. See the risk factor captioned The market price of our stock may be volatile, and you could lose all or part of your investment, described in our Annual Report on Form 10-K for the year ended December 31, 2023.
If we fail to comply with the continued listing standards of The Nasdaq Capital Market, we may seek to list our common stock on the NYSE American or on a regional stock exchange or, if one or more broker-dealer market makers comply with applicable requirements, the over-the-counter (OTC) market. Listing on such other market or exchange could reduce the liquidity of our common stock. If our common stock were to trade in the OTC market, an investor would find it more difficult to dispose of, or to obtain accurate quotations for the price of, the common stock. Delisting of the common stock could depress our stock price, substantially limit liquidity of our common stock and materially adversely affect our ability to raise capital on terms acceptable to us, or at all. Further, delisting of the common stock would likely result in the common stock becoming a penny stock under the Exchange Act.
25
We are subject to stringent and evolving U.S. and foreign laws, regulations and rules, contractual obligations, policies, industry standards, and other obligations related to data privacy and security. Our actual or perceived failure to comply with such obligations could lead to regulatory investigations or actions; litigation (including class claims) and mass arbitration demands; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; and other adverse business consequences.
In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, process) personal data and other sensitive data, including proprietary and confidential business data, trade secrets, intellectual property, data we collect about trial participants in connection with clinical trials, sensitive third-party data, and employee data. Our data processing activities may subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements, and other obligations relating to data privacy and security.
In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, and consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act). For example, the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH), imposes specific requirements relating to the privacy, security, and transmission of individually identifiable health information. In the past few years, numerous U.S. statesincluding California, Virginia, Colorado, Connecticut, and Utahhave enacted comprehensive privacy laws that impose certain obligations on covered businesses, including providing specific disclosures in privacy notices and affording residents with certain rights concerning their personal data. As applicable, such rights may include the right to access, correct, or delete certain personal data, and to opt-out of certain data processing activities, such as targeted advertising, profiling, and automated decision-making. The exercise of these rights may impact our business and ability to provide our products and services. Certain states also impose stricter requirements for processing certain personal data, including sensitive information, such as conducting data privacy impact assessments. These state laws allow for statutory fines for noncompliance. For example, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CPRA) (collectively, CCPA) applies to personal data of consumers, business representatives, and employees who are California residents, requires businesses to provide specific disclosures in privacy notices and honor requests of California residents to exercise certain privacy rights, such as those noted below. The CCPA provides for fines of up to $7,500 per intentional violation and allows private litigants affected by certain data breaches to recover significant statutory damages. Although the CCPA and other state laws exempt some data processed in the context of clinical trials, these developments further complicate compliance efforts and increase legal risk and compliance costs for us and the third parties with whom we work.
In addition, data privacy and security laws have been proposed at the federal, state, and local levels in recent years, which could further complicate compliance efforts, and we expect more states to pass similar laws in the future.
Outside the United States, an increasing number of laws, regulations, and industry standards apply to data privacy and security, including the European Unions General Data Protection Regulation (EU GDPR) and the United Kingdoms GDPR (UK GDPR) (collectively, GDPR), which impose strict requirements for processing personal data. Violators of these laws face significant penalties. For example, under the GDPR, companies may face temporary or definitive bans on data processing and other corrective actions; fines of up to 20 million Euros under EU GDPR / 17.5 million pounds sterling under the UK GDPR or, in each case, 4% of annual global revenue, whichever is greater; or private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests.
The Swiss Federal Act on Data Protection, or the FADP, also applies to the collection and processing of personal data, including health-related information, by companies located in Switzerland, or in certain circumstances, by companies located outside of Switzerland. Compliance with the FADP and its revised ordinances may result in an increase of costs of compliance, risks of noncompliance and penalties for noncompliance.
In the ordinary course of business, we may transfer personal data from Europe and other jurisdictions to the United States or other countries. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the European Economic Area (EEA) and the United Kingdom (UK) have significantly restricted the transfer of personal data to the United States and other countries whose privacy laws it believes are inadequate. Other jurisdictions may adopt similarly stringent interpretations of their data localization and cross-border data transfer laws. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EEA standard contractual clauses, the UKs International Data Transfer Agreement / Addendum, and the EU-U.S. Data Privacy Framework and the UK extension thereto (which allows for transfers to relevant U.S.-based organizations who self-certify compliance and participate in the Framework), these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States.
26
If there is no lawful manner for us to transfer personal data from the EEA, the UK or other jurisdictions to the United States, or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including increased exposure to regulatory actions, substantial fines, and injunctions against processing or transferring personal data, as well as other adverse consequences. In particular we may be unable to import personal data to the United States, which could significantly and negatively impact our business operations, including by limiting our ability to conduct clinical trial activities in Europe and elsewhere; limiting our ability to collaborate with parties that are subject to such cross-border data transfer or localization laws; or requiring us to increase our personal data processing capabilities and infrastructure in foreign countries at significant expense. Additionally, companies that transfer personal data out of the EEA and UK to other jurisdictions, particularly to the United States, are subject to increased scrutiny from regulators, individual litigants, and activist groups. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers out of Europe for allegedly violating the GDPRs cross-border data transfer limitations.
In addition to data privacy and security laws, we are contractually subject to data privacy and security obligations, including industry standards adopted by industry groups and may become subject to new data privacy and security obligations in the future. For example, certain privacy laws require our customers to impose specific contractual restrictions on their service providers. We publish privacy policies, marketing materials and other statements, such as compliance with certain certifications or self-regulatory principles, regarding data privacy and security. If these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators or other adverse consequences.
Obligations related to data privacy and security (and consumers data privacy expectations) are quickly changing, becoming increasingly stringent, and creating uncertainty. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or conflict among jurisdictions. Preparing for and complying with these obligations requires us to devote significant resources. These obligations may necessitate changes to our information technologies, systems, and data processing practices and to those of any third parties that process personal data on our behalf.
We may at times fail (or be perceived to have failed) in our efforts to comply with our data privacy and security obligations. Moreover, despite our efforts, our personnel or third parties with whom we work may fail to comply with such obligations, which could negatively impact our business operations and compliance posture. For example, any failure by a third-party processor to comply with applicable law, regulations, or contractual obligations could result in adverse effects, including proceedings against us by governmental entities or others.
If we or the third parties with whom we work fail, or are perceived to have failed, to address or comply with applicable data privacy and security obligations, we could face significant consequences, including but not limited to: government enforcement actions (e.g., investigations, fines, penalties, audits, inspections, and similar); litigation (including class-action claims) and mass arbitration demands; additional reporting requirements and/or oversight; bans on processing personal data; orders to destroy or not use personal data; and imprisonment of company officials. In particular, plaintiffs have become increasingly more active in bringing privacy-related claims against companies, including class claims and mass arbitration demands. Some of these claims allow for the recovery of statutory damages on a per violation basis, and, if viable, carry the potential for monumental statutory damages, depending on the volume of data and the number of violations. Any of these events could have a material adverse effect on our reputation, business, or financial condition, including but not limited to: loss of customers; interruptions or stoppages in our business operations (including, as relevant, clinical trials); inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or revision or restructuring of our operations.
If our information technology systems, or those of third parties with whom we work, or our data are or were compromised, we could experience adverse consequences resulting from such compromise, including but not limited to regulatory investigations or actions; litigation; fines and penalties; disruptions of our business operations; reputational harm; loss of revenue or profits; and other adverse consequences.
In the ordinary course of our business, we and the third parties with whom we work process proprietary, confidential, and sensitive data, including personal data (such as health-related data and data related to clinical trials), intellectual property, and trade secrets (collectively, sensitive information).
Cyberattacks, malicious internet-based activity, online and offline fraud, and other similar activities threaten the confidentiality, integrity, and availability of our sensitive information and information technology systems, and those of the third parties with whom we work. Such threats are prevalent, continue to rise, are increasingly difficult to detect, and come from a variety of sources, including traditional computer hackers, threat actors, hacktivists, organized criminal threat actors, personnel (such as through theft or misuse), sophisticated nation states, and nation-state-supported actors. Some actors now engage and are expected to continue to
27
engage in cyber-attacks, including without limitation nation-state actors for geopolitical reasons and in conjunction with military conflicts and defense activities. During times of war and other major conflicts, we and the third parties with whom we work may be vulnerable to a heightened risk of these attacks, including retaliatory cyber-attacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell and distribute our goods and services. We and the third parties with whom we work may be subject to a variety of evolving threats, including but not limited to social-engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake, and phishing attacks), malicious code (such as viruses and worms), malware (including as a result of advanced persistent threat intrusions), denial-of-service attacks, credential stuffing, personnel misconduct or error, ransomware attacks, supply-chain attacks, software bugs, server malfunctions, software or hardware failures, loss of data or other information technology assets, adware, telecommunications failures, earthquakes, fires, floods, attacks enhanced or facilitated by AI, and other similar threats.
In particular, ransomware attacks, including by organized criminal threat actors, nation-states, and nation-state-supported actors, are becoming increasingly prevalent and severe and can lead to significant interruptions in our operations, ability to provide our products or services, loss of data and income, reputational harm, and diversion of funds. Extortion payments may alleviate the negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to, for example, applicable laws or regulations prohibiting such payments. Future or past business transactions (such as acquisitions or integrations) could expose us to additional cybersecurity risks and vulnerabilities, as our systems could be negatively affected by vulnerabilities present in acquired or integrated entities systems and technologies. Furthermore, we may discover security issues that were not found during due diligence of such acquired or integrated entities, and it may be difficult to integrate companies into our information technology environment and security program. Remote work has become more common and has increased risks to our information technology systems and data, as more of our employees utilize network connections, computers and devices outside our premises or network, including working at home, while in transit and in public locations.
We rely upon third-party service providers and technologies to operate critical business systems to process sensitive information in a variety of contexts, including, without limitation, third-party providers of cloud-based infrastructure, encryption and authentication technology, employee email, content delivery to customers, and other functions. We also share or receive sensitive information with or from third parties. Our ability to monitor these third parties information security practices is limited, and these third parties may not have adequate information security measures in place. While we may be entitled to damages if our third-party service providers or the third parties with whom we work fail to satisfy their privacy or security-related obligations to us, any award may be insufficient to cover our damages, or we may be unable to recover such award. In addition, supply-chain attacks have increased in frequency and severity, and we cannot guarantee that third parties infrastructure in our supply chain or that of the third parties with whom we work have not been compromised.
While we have implemented security measures designed to protect against security incidents, there can be no assurance that these measures, or those of the third parties with whom we work, will be effective. For example, an external contractor experienced a cyberattack in 2019, which resulted in a disruption to patient recruitment in our Phase 3 clinical trial of roluperidone. We take steps designed to detect, mitigate, and remediate vulnerabilities in our information systems (such as our hardware and/or software, including that of third parties with whom we work), but we may not be able to detect and remediate all such vulnerabilities including on a timely basis. Further, we may experience delays in developing and deploying remedial measures and patches designed to address identified vulnerabilities. Vulnerabilities could be exploited and result in a security incident.
Any of the previously identified or similar threats could cause a security incident or other interruption that could result in unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure of, or access to our sensitive information or our information technology systems, or those of the third parties with whom we work. A security incident or other interruption could disrupt our ability (and that of third parties with whom we work) to provide our services. We may expend significant resources or modify our business activities (including our clinical trial activities) to try to protect against security incidents. Certain data privacy and security obligations may require us to implement and maintain specific security measures, industry-standard or reasonable security measures to protect our information technology systems and sensitive information.
Applicable data privacy and security obligations may require us to notify relevant stakeholders, including affected individuals, customers, regulators, and investors, of security incidents, or to implement other requirements, such as providing credit monitoring. Such disclosures and compliance with such requirements are costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences. If we (or a third party with whom we work) experience a security incident or are perceived to have experienced a security incident, we may experience adverse consequences. These consequences may include: government enforcement actions (for example, investigations, fines, penalties, audits, and inspections); additional reporting requirements and/or oversight; restrictions on processing sensitive information (including personal data); litigation (including class claims); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; diversion of management attention; interruptions in our operations (including availability of data); financial loss; and other similar harms. Security incidents and attendant consequences may negatively impact our ability to grow and operate our business or disrupt our ability to develop and provide our
28
products and services. In addition to experiencing a security incident, third parties may gather, collect, or infer sensitive information
28
about us from public sources, data brokers, or other means that reveals competitively sensitive details about our organization and could be used to undermine our competitive advantage or market position. Additionally, our sensitive information could be leaked, disclosed, or revealed as a result of or in connection with our employees, personnels, or vendors use of generative AI technologies.
Our contracts may not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our data privacy and security obligations. We cannot be sure that our insurance coverage will be adequate or sufficient to protect us from or to mitigate liabilities arising out of our privacy and security practices, that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims.