Cybersecurity Risk Management and Strategy Disclosure |
12 Months Ended |
|---|---|
Jun. 30, 2026 | |
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] |
We operate in the biotechnology industry, where the protection of sensitive information and the continuity of our operations are critical. We are subject to cybersecurity risks which could adversely affect our business, financial condition, or results of operations. We maintain a risk-based cybersecurity program designed to identify, assess, and mitigate cybersecurity threats. Our program incorporates applicable industry standards and is managed through a cross-functional approach involving our Information Technology, legal, compliance, and other relevant teams. It is overseen by our chief information officer, which is responsible for the day-to-day management of cybersecurity risks and the implementation of our information security program and incident response plans.
Our risk management activities include periodic assessments, vulnerability testing, and tabletop exercises, as well as regular engagement with third-party experts to perform independent security assessments. We have expanded employee training and phishing simulations, and we conduct ongoing monitoring of access to our systems, including oversight of third-party vendors and service providers. The results of assessments and reviews are reported to senior management and the Audit Committee, and our policies and controls are updated as necessary.
We have experienced cybersecurity incidents in the past and continue to encounter cybersecurity threats in the ordinary course of business. To date, none of these incidents or threats have had a material adverse effect on our business, financial condition, results of operations or cash flows. Although we maintain cybersecurity measures designed to protect our information systems, including employee training and vendor oversight, cybersecurity threats continue to evolve, and our measures may not be sufficient to prevent, detect, contain or remediate all cybersecurity incidents. The increasing availability and sophistication of artificial intelligence technologies may increase the frequency, scale and effectiveness of cyberattacks, including phishing, social-engineering, impersonation, malware and other attacks, and may increase the risk of unauthorized access to, disclosure of or misuse of our or third parties’ data. Our use of, or reliance on third-party providers that use, artificial intelligence technologies may also create additional risks relating to data privacy, confidentiality, security, accuracy, intellectual property, regulatory compliance and third-party claims. A future cybersecurity incident, including an incident involving our third-party service providers, could disrupt our operations; compromise, destroy, alter or result in unauthorized access to our systems or data; result in regulatory inquiries, legal claims, remediation costs or contractual liabilities; and materially adversely affect our business, financial condition, results of operations, cash flows or reputation.
Risk Management and Strategy
As part of our overall risk management framework, our cybersecurity program takes a comprehensive, layered approach to identifying, preventing and mitigating cybersecurity threats and incidents. This includes implementing controls and escalation procedures to ensure that significant incidents are promptly communicated to management for timely decision-making regarding public disclosure and regulatory reporting.
We deploy multiple technical safeguards designed to protect our information systems, including firewalls, intrusion prevention and detection systems, anti-malware tools, access controls, and ongoing monitoring. These safeguards are evaluated and enhanced through regular vulnerability assessments, penetration testing and ongoing cybersecurity threat intelligence.
During calendar year 2026, we adopted internal procedures and guidelines relating to the responsible and secure use of artificial intelligence tools within the Company. In connection with these efforts, we implemented an enterprise artificial intelligence tool within our Microsoft 365 environment, which operates based on existing organizational access permissions and is intended to support AI-enabled work within the Company’s secured enterprise environment.
We maintain formal incident response and recovery plans that define our procedures for addressing cybersecurity incidents. These plans are tested, updated, and refined on a regular basis to ensure readiness.
We apply a risk-based approach to managing cybersecurity risks posed by third parties, including vendors, contract research organizations, service providers and other external users of our systems. This approach includes assessment and oversight of cybersecurity risks associated with third-party systems that, if compromised, could negatively impact our business operations. |
| Cybersecurity Risk Management Processes Integrated [Flag] | true |
| Cybersecurity Risk Management Processes Integrated [Text Block] | Our risk management activities include periodic assessments, vulnerability testing, and tabletop exercises, as well as regular engagement with third-party experts to perform independent security assessments. We have expanded employee training and phishing simulations, and we conduct ongoing monitoring of access to our systems, including oversight of third-party vendors and service providers. The results of assessments and reviews are reported to senior management and the Audit Committee, and our policies and controls are updated as necessary. |
| Cybersecurity Risk Management Third Party Engaged [Flag] | true |
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] | A future cybersecurity incident, including an incident involving our third-party service providers, could disrupt our operations; compromise, destroy, alter or result in unauthorized access to our systems or data; result in regulatory inquiries, legal claims, remediation costs or contractual liabilities; and materially adversely affect our business, financial condition, results of operations, cash flows or reputation. |
| Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] | The results of assessments and reviews are reported to senior management and the Audit Committee, and our policies and controls are updated as necessary. |
| Cybersecurity Risk Role of Management [Text Block] |
Governance
The Audit Committee of our Board oversees our risk management process, including the management of risks from cybersecurity threats. Until August 31, 2026, our cybersecurity program was managed internally by qualified internal personnel. Effective as of September 2026, we engaged an external service provider to provide chief information officer services, including responsibility for the day-to-day administration of our cybersecurity program. The external service provider has expertise in information security and cybersecurity and supports our management of cybersecurity risks, implementation of our information security program and incident response planning. The external service provider reports to the Audit Committee on cybersecurity matters. The Audit Committee receives periodic reports and presentations addressing cybersecurity risks, recent developments, evolving standards, results of vulnerability assessments, findings from third-party and independent reviews, current threat intelligence, technological trends, and relevant developments regarding security considerations arising with respect to our peers and third parties. According to our procedures, the Audit Committee is promptly informed of any cybersecurity incident that meets established reporting thresholds and receives ongoing updates until the matter is fully resolved. |
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |