October 27th, 2023
Dear client
We are deeply saddened and concerned by the recent violence and tragic loss of life in the Middle East. Our thoughts continue to be with all those affected. Our primary focus is to evaluate the evolving situation and ensure, to the best of our abilities, the smooth progress of any ongoing trials in the region and that patients continue to be supported in their participation. We have a crisis management team in place who is responsible for managing the evaluation and subsequent actions that Clario takes in response to any impacts and potential impacts that this crisis may lead to. They are evaluating the business across a number of key areas which include:
Logistics
We are in regular contact with our logistics partners. There are some within our network that have suspended or partially suspended operations within Israel. However, our expansive network of partners allows us to remain fully operational at this time. It is anticipated that, should an invasion into Gaza occur, this may well impact our couriers’ ability to safely import and export shipments to and from sites within Israel. The extent of this is unknown, but should this occur, your Project Managers/Account Team will keep you full informed and this website will be updated accordingly. We encourage you to remain engaged directly with your Clario Team to understand the level of risk associated with your study. They are equipped with a full breakdown of site participation within Israel and will be able to advise you quickly on this.
Return Shipments
At this time return shipments are also operational, but could be impacted if the situation evolves. Our recommendation would be to reconcile any inventory expected to be returned and complete those shipments at your earliest convenience to minimize any potential impact to sites at a later stage.
Data Transmission & Trial Management
It is expected that local data transmission services may be subject to disruption during a conflict of this nature and magnitude. Clario does not rely upon any infrastructure or personnel within Israel, so our ability to receive and process data is not impacted. Across all our service lines, our Project Management teams will support you through operational strategies in the event of temporary or permanent loss of connectivity. Additionally, our eCOA platform operates with offline capabilities, enabling data to be stored on devices until an internet connection is established, at which point it will be transmitted.
We are yet to observe any significant impact in data transmission within Israel. We encourage you to engage with your CRO partners and Clario Project Manager to support management of any sites and/or patients that may become affected.
Cyber Security
Clario’s Cybersecurity program aligns to globally recognized security frameworks such as ISO 27001 & NIST CSF and is further bolstered through guidance from other organizations such as H-ISAC, and CISA. To date, this program has been effective and no concerns relating to our services and infrastructure have materialized from the ongoing regional situation. Some examples of how we secure our products as well as our own infrastructure include:
1 Product Architecture:
- Due to the nature of Clario products’ architecture and design, there are no direct site connections to Clario’s network, infrastructure, or databases rendering the chances of a site incident impacting Clario hosted data remote. Clario protects its hosted product systems and platforms via a multi-layered approach involving network, endpoint, identity, and data security practices and technologies.
- When a reported clinical site suffers a data breach or compromise to its networks, Clario follows a process to review and identify impact, if any, to clinical data and systems Clario hosts, taking appropriate measures to respond to such incidents.
- Clario performs Security Impact Assessments for all internet-facing applications, which includes testing the applications against common security risks and applying remediation where necessary.
2 24x7x365 Security Monitoring and Response:
- Clario infrastructure for all internet-facing clinical applications is monitored 24x7x365 by Clario’s security platform and Security Operations Centre (SOC). The SOC receives threat intelligence reports from our security partners.
- Our continuous 24x7x365 network and server endpoint monitoring system captures all security events in a Security Information and Event Monitoring (SIEM) platform. From this system, our security operations team identifies and evaluates security events and develops and executes appropriate remediation steps.
- The Clario Security Operations Team stays abreast of cyber activity in the region and if needed, applies a heightened focus on cybersecurity.
3 Detect, prioritize and remediate known exploitable vulnerabilities:
- Clario frequently scans its infrastructure for vulnerabilities.
- Clario has a risk-based vulnerability management program that identifies, prioritizes, and remediates vulnerabilities based on risk factors such as asset critical, vulnerability exploitability, and threat intelligence.
Trial Continuity
In the event where patient activity or site enrollment is impacted, we do expect that sponsors will look to other countries to make up the required patient populations necessary for their protocol. Doing this through active countries on the trial will be the most efficient solution. However, if you decide to open a new country on your trials, Clario can support this through our current change management practices, and we ask that you communicate with us, early-on, any potential strategies you are considering so that we can proactively advise on solutions and any experiences we are seeing across other active trials.
Next Steps:
Our response team are meeting daily to monitor the situation and progress any actions that are taking place. There is also an internal triage distribution list established internally to allow any client questions to be centrally managed by the response team. Should you have any questions, please ensure that you communicate them to your Project Manager/Account Team.