If we fail to comply with environmental, health and safety laws and regulations, we could become subject to fines or penalties or incur costs that could have a material adverse effect on our business.
We are subject to numerous environmental, health and safety laws and regulations, including those governing laboratory procedures and the handling, use, storage, treatment and disposal of hazardous materials and wastes. From time to time and in the future, our operations may involve the use of hazardous and flammable materials, including chemicals and biological materials, and may also produce hazardous waste products. Even if we contract with third parties for the disposal of these materials and wastes, we cannot completely eliminate the risk of contamination or injury resulting from these materials. In the event of contamination or injury resulting from our use of hazardous materials, we could be held liable for any resulting damages, and any liability could exceed our resources. We also could incur significant costs associated with civil or criminal fines and penalties for failure to comply with such laws and regulations.
We maintain workers’ compensation insurance to cover us for costs and expenses that we may incur due to injuries to our employees resulting from the use of hazardous materials, but this insurance may not provide adequate coverage against potential liabilities. Moreover, we do not currently maintain insurance for environmental liability or toxic tort claims that may be asserted against us.
In addition, we may incur substantial costs in order to comply with current or future environmental, health and safety laws and regulations. Current or future environmental laws and regulations may impair our research, development or production efforts, which could adversely affect our business, financial condition, results of operations or prospects. In addition, failure to comply with these laws and regulations may result in substantial fines, penalties or other sanctions.
Our internal computer systems, or those of our contract research organizations or other contractors or consultants, may fail or suffer cybersecurity incidents, which could result in a material disruption of our product development programs, and could subject us to liability.
We utilize information technology systems and networks to process, transmit and store electronic information in connection with our business activities. As the use of digital technologies has increased, cyber incidents, including deliberate attacks and attempts to gain unauthorized access to computer systems and networks, have increased in frequency and sophistication. In particular, ransomware attacks, including those from organized criminal threat actors, nation-states and nation-state supported actors, are becoming increasingly prevalent and severe and can lead to significant interruptions, delays, or outages in our operations, loss of data, including sensitive customer information, loss of income, significant extra expenses to restore data or systems, reputational loss and the diversion of funds. To alleviate the negative impact of a ransomware attack, it may be preferable to make payments to the threat actor(s), but we may be unwilling or unable to do so, including, for example, if applicable laws or regulations prohibit such payments. Finally, developments in artificial intelligence and machine learning provide threat actors with the capability to use more sophisticated means to attack our systems and may exacerbate cybersecurity risk. These threats pose a risk to the security of our systems and networks and the confidentiality, availability and integrity of our data. There can be no assurance that we will be successful in preventing cyber-attacks or successfully mitigating their effects.
Despite the implementation of security measures, our internal computer systems and those of our contract research organizations and other contractors and consultants are vulnerable to damage or disruption from hacking, computer viruses, malware, including ransomware, software bugs, unauthorized access, natural disasters, terrorism, war, and telecommunication, equipment and electrical failures. We have measures in place that are designed to prevent, and if necessary, to detect and respond to such cybersecurity incidents and breaches of privacy and security mandates. Our measures to prevent, respond to, and minimize such risks may be unsuccessful. While we have not, to our knowledge, experienced any significant system failure, accident or material cybersecurity incident to date, if such an event were to occur and cause interruptions in our operations or the operations of those third parties with which we contract, it could result in a material disruption of our programs and our business operations, as well as our financial condition. For example, the loss of clinical trial data from completed or ongoing clinical trials for any of our current or future product candidates could result in delays in our development and regulatory approval efforts and significantly increase our costs to recover or reproduce the data. Such a loss could also expose us to regulatory enforcement, civil liability and reputational damage. To the extent that any disruption or cybersecurity incident results in a loss of or damage to our data or applications, or inappropriate disclosure or theft of confidential or proprietary information, in addition to incurring liability, the further development of any product candidates could be delayed or our competitive position could be compromised. Additionally, such disruptions or cybersecurity incidents could result in enforcement actions by U.S. or foreign regulatory authorities, regulatory penalties, and other legal liabilities such as but not limited to private litigation, the incurrence of significant remediation costs, disruptions to our development programs, business operations and collaborations, diversion of management efforts and damage to our reputation, all of which could harm our business and operations.