Information Security Risk

Issue Date:August 20, 2026

 

Information Security Risk

 

To implement sustainable development and protect the Company's confidential information and customer privacy, the Company established the “Information Security Management Committee” in 2012. The committee is responsible for formulating information security policies and establishing communication mechanisms to effectively prevent data theft, tampering, loss, or leakage. In addition to ensuring the confidentiality, integrity, and availability of information, the Company also complies with the ISO/IEC 27001 standard and other relevant information security regulations. 

 

Information Security Management Committee

 

The Company established the “Information Security Management Committee” in December 2012. The committee is responsible for reviewing information security governance policies, overseeing the implementation of information security management, establishing a comprehensive information security protection mechanism, enhancing employee awareness of information security, and conducting regular assessments of information security risks. Since 2020, the committee has reported its implementation status to the Board of Directors annually.

 

The committee is chaired by the Vice President or a person appointed by the Company's President (hereinafter referred to as the Committee Chair). Members consist of first-level supervisors from each department who assist the Chairperson in managing operations and maintenance. Each department's management representative is responsible for supervising and managing tasks related to the committee within their respective units. Additionally, the committee has established a Risk Management and Business Continuity Team, an Incident Response Team, and a Documentation Team. (For the organizational structure, please refer to the diagram on the right.)
 

Information Security Policy

 

The Company formulates the following information security policies based on ISO 27001 and NIST standards, and in accordance with internal management needs:

  • Each unit under the Information Management Center maintains an inventory of relevant information assets and designates asset owners. Risk assessments are conducted based on asset classification. For risks exceeding acceptable levels, appropriate risk management measures are implemented to effectively mitigate risks, and various control measures are continuously enforced. 

  • Personnel must undergo necessary assessments before employment and sign relevant operational regulation documents. Upon transfer or resignation, all assigned information assets must be returned. Both new and current employees are required to participate in information security training to enhance awareness and understanding of information protection.

  • Access control protocols and rules for carrying items in and out of the company buildings and information security control zones must be strictly followed.

  • Employees are strictly prohibited from privately installing network equipment that connects the external network to the Company's internal network. Firewalls, demilitarized zones (DMZ), and necessary security facilities must be established for both internal and external networks. Critical equipment should have proper backup or monitoring mechanisms to maintain availability. Employees' personal computers must have antivirus software installed and virus definitions regularly updated. The use of unauthorized software is prohibited.

  • Employees are responsible for safeguarding and properly using their individual accounts, passwords, and access privileges. System administrators must regularly review and verify user permissions. Data from critical systems must be backed up regularly, and recovery tests must be conducted.

  • Security controls should be incorporated in the initial phase of system development. For outsourced development, enhanced controls and contractual information security requirements must be enforced.

  • If an employee encounters an information security incident, it must be reported immediately and handled according to the Information Security Incident Handling Procedure to prevent escalation. Cooperation with responsible departments is required to resolve the issue.

  • Employees must follow proper review and verification procedures in daily operations to ensure data accuracy. Supervisors are responsible for ensuring compliance with information security policies and strengthening employees' awareness of information security and relevant regulations.

  • The Company reviews its information security policies regularly to respond to changes in regulations, technologies, and business needs. The Information Security Management Committee adjusts objectives accordingly to ensure the effectiveness of information security practices.

  • If, due to business requirements, the introduction of new technologies, or shortages in manpower or equipment, it is deemed necessary after evaluation to outsource development or maintenance services, or to obtain external manpower resources or equipment, such arrangements shall be implemented in accordance with the “Information Outsourcing and Project Management Procedure”. The process flow is illustrated below:

 

 

Information Security Incident Reporting Channels

 

If employees of the Company, application system administrators, or personnel of outsourced vendors identify any suspected information security vulnerabilities or incidents, they shall immediately report them via the “Complaint Channel for Stakeholders and Employees' Violations of Professional Ethics” mailbox. The information security contact person of the relevant unit shall then complete an “Information Security Incident Report Form” and report the incident to the “Incident Response Team”. The reporting process is illustrated below:

 

 

Information Security Risk Identification
  • Policy: Based on the four major control categories and 93 control measures of ISO/IEC 27001, we strengthen information security across six key areas: network security, host security, application system security, equipment security, operations analysis, and information security management. The risk mitigation process is systematized and data-driven to establish a defense-in-depth architecture for enhancing overall information security strength.

  • Annual Targets: Annual information security management targets are set, with evaluation metrics tailored to each target. Using data- driven indicators and standardized procedures, we identify non-compliant or significant risk issues, propose improvement measures, and include them in follow-up tracking.

  • Vulnerability Scanning: To respond to the rapidly evolving cyber threats, we regularly conduct vulnerability scans on systems supporting our services. All detected vulnerabilities are fully resolved within three months.

Information Asset Inventory Process

 

 

 

 

Information Security Risk Identification Process

 

 

Information Security Education and Training
  • Information Security Training: Organized the Group’s mandatory information security training courses for the second half of 2025, including “Information Security Awareness, Policies, and Defensive Concepts” and “Phishing and Impersonation Scams”. Employees were required to complete the full course videos and achieve a score of 80 or above on the post-training assessment in order to complete the courses, with a total of 3,604 employees completing the training. Additional courses included “Welcome Aboard: Information Security for New Employees”, “Good Information Security Practices”, “Email-Based Social Engineering Attacks”, and “Network Information Security and Computer Usage Guidelines”, with a total of 5,641 training attendances.

  • Security Announcements: Information security awareness announcements were issued periodically to remind employees of relevant risks, to prevent recurrence that could cause operational losses for the Company. In 2025, a total of 7 such announcements were made.

 

 

 

 Information Security Measures
  • Established a defense-in-depth information security architecture to enhance protection across six major aspects: network security, host security, application system security, equipment security, operations analysis, and information security management.

  • Strengthened the information security protection architecture by upgrading the forensic analysis platform to ensure no vulnerabilities exist in the defense system.

  • Maintained real-time synchronization with international threat intelligence centers, continuously updated threat intelligence, and utilized a proactive alert analysis engine to effectively block malicious connections and actively hunt suspicious behavior. This is further supported by information security experts conducting forensic investigations to enhance hacker defense capabilities.

  • In response to updates of externally provided service systems, since 2020, the Company has conducted at least one platform vulnerability scan and one social engineering drill each year. In 2025, two email social engineering drills were conducted for all employees across the Company.