GOVERNANCE Corporate Governance

1. Information and Communication Security Policy

1-1. Information assets shall be properly protected against unauthorised access so that their confidentiality is not compromised.
1-2. Information assets shall be kept in the correct environment and with the correct transmission tools to safeguard their integrity.
1-3. The availability of information asset processing equipment shall be ensured in order to ensure the sustainability of the Company's critical business operations.
1-4.Achieve the following three objectives through the management cycle mechanism of Plan-Do-Check-Act (PDCA):
  • Information assets shall be appropriately protected to prevent unauthorized access and ensure the confidentiality is not compromised.
  • The preservation environment and transmission tools of information assets shall be accurate to ensure their integrity.
  • The availability of information asset processing equipment shall be ensured to support the continued and stable operation of critical business functions.
Planning Phase — To promote compliance with ISO 27001 certification requirements, implement information security control mechanisms into relevant systems and procedures, and integrate them into operations across core systems, support systems, and infrastructure systems.
Execution Phase — Leverage the group’s bargaining power to introduce cybersecurity control systems (MDR, endpoint management, antivirus). Internally establish relevant operational regulations and SOPs, and conduct cybersecurity drills and protection procedures.
Checking Phase — Monitor the effectiveness of information security management, introduce external audit resources to perform vulnerability scans and penetration testing to verify the effectiveness of security mechanisms.
Action Phase — Continuously review and optimize information security mechanisms to reduce gaps between objectives and actual outcomes. Establish disciplinary standards for personnel who violate information security policies.


2. Specific management solutions
2-1. Access control should be implemented in important computer rooms and regular inspections should be conducted to ensure that the equipment is functioning properly and is not infringed upon.
2-2. When logging into the company's personal computers and systems, an account/password is required. Additionally, passwords must be changed every three months. Users are also required to operate application systems within the authorized scope of their accounts. For important account permissions, an annual audit is conducted to minimize the risk of data leaks. Accounts that have not undergone a password change will be locked, and users must reapply for permissions through the 'Information Permission Addition/Change Request Form'."
2-3. Network firewalls and anti-virus software should be installed, and virus codes should be updated regularly to ensure the security of information assets and transmission.
2-4. Important information should be categorized and backed up regularly, and backup and recovery tests of computer system data should be conducted regularly every year to ensure that the impact on the company's operation can be minimized after an information security incident occurs.
2-5. Information equipment should be inspected on an annual basis. If information equipment is to be replaced, the storage media should first be disposed of by formatting and erasing the data from the storage media to be destroyed and physically destroying it with a hammer or drilling device to ensure that the storage media and data cannot be reused.
2-6.Introduce information security protection system, install and control software on hosts and endpoints, and implement real-time early warning monitoring.
2-7. The Company shall regularly review areas for further enhancement of information security management on an annual basis. In addition to improving equipment or management mechanisms, the Company should conduct further user education and training, if necessary, to reduce the likelihood of information security incidents.
2-8.We conduct quarterly social engineering drills to ensure that internal personnel are well-prepared to respond appropriately to external malicious phishing email attack incidents and have an established reporting mechanism. Necessary educational training is also provided to unfamiliar employees.
2-9.Join the cybersecurity alliance (TWCERT/CC) and regularly receive cybersecurity information.


3.Input resources for information and communication security management
3-1. Case Studies on Information Security and Information Security Awareness Promotion. 
3-2. Regular monthly cybersecurity meetings are held to develop action plans according to the cybersecurity prevention program. 
3-3. Software Inventory: Establish a management system for software installations. Perform an inventory at least once a year to ensure the legal use of licensed software and to guard against malicious software.
3-4. Endpoint Protection: Check virus definition updates every 2 hours. Install endpoint monitoring agents to enhance system reliability.
3-5. Establish a firewall for protection against Distributed Denial of Service (DDOS) attacks and implement a control mechanism on the mail server to block large volumes of spam and viruses.
3-6. We have formulated a plan to introduce Managed Detection and Response (MDR) services, which is expected to be gradually implemented in 2024, with full deployment upon completion.
3-7. General Vulnerabilities and Exposures (CVE) patching for servers: Regularly check for security update information, and perform a weekly check of Microsoft operating system updates.
3-8. Disaster Recovery: Establish dedicated backup servers and related software, and formulate data backup policies for core systems. The system has a cold standby mechanism.
3-9. Disaster Recovery (DR) Drills: Conduct DR drills for core systems twice a year.


4.Organizational structure for information security
The Company has established a dedicated information security unit with two members to hold quarterly ad hoc meetings to decide on matters related to the information security system and to establish the security responsibilities of the information security management structure. The unit also reports to the Board of Directors on the implementation of information security management on an annual basis.


5. Operations
5-1.Date reported to the Board of Directors in 2025: July 28, 2025
Category Operational Situation
Management Staffing 1. The Company has established an Information Security Management Team, with two dedicated personnel responsible for executing related operations.These responsibilities include policy planning and implementation, management of user computer and corporate network access permissions, firewall and antivirus software administration, as well as data backup planning, redundancy, and recovery drills.
2. In 2024, the Company’s information security personnel received training on the Personal Data Protection Act (Security Maintenance), social engineering, and cybersecurity control guidelines, totaling 32 participant-hours.
In 2025, the personnel completed cybersecurity courses offered by the Taiwan Academy of Banking and Finance, totaling 14 participant-hours, and passed the related assessments.
Information security and control measures 1. In 2024, three security patches were applied, and real-time disconnection alerts were added to enhance network incident response capabilities.
2. A filtering mechanism was configured on the email server to prevent the spread of spam messages. A migration to a cloud-based solution is planned for 2025.
3. System network operations utilize MPLS VPN connections to prevent unauthorized external access. In addition, HiNet enterprise security services are employed to block external attacks.
4. Antivirus software was renewed in June 2022 under a three-year contract. The software is in its third year of use as of 2025. Security patches for operating systems on servers are reviewed monthly and updated in real time.
5. Logging into company-issued personal computers and accessing internal systems requires account ID and password authentication. Passwords must be changed every three months; accounts will be locked if the password is not updated within the required period, and access will be suspended until a formal request is submitted. Passwords must be at least 8 characters in length and include a combination of numbers and letters.
6. In July 2024, a review of ERP system access permissions was completed, confirming the accuracy of the user list. The review for 2025 is scheduled to be conducted in July.
7. In 2024, vulnerability scans were completed on six servers and penetration tests were conducted on three servers. This included operating system upgrades and remediation of application vulnerabilities based on OWASP guidelines. The 2025 assessments are scheduled for September.
Information Equipment Security 1. Critical system servers are housed in a professional data center with access control measures in place to regulate personnel entry.
2. In 2024, a maintenance inspection was conducted on information servers at all locations to reduce the risk of equipment failure, and hardware warranty contracts were completed. In 2025, server inspections and maintenance at all locations have also been completed.
3. In 2024, a full backup of the core systems—including programs and data—was completed, in compliance with the 3-2-1 backup security standard. Critical system data is backed up twice daily on a scheduled basis, and the backup results are sent out immediately via email. In 2025, in response to the upgrade to VMware 8.0, the backup processes have been revised accordingly.
4. In 2024, MDR (Managed Detection and Response) software was fully implemented to carry out proactive threat detection and cybersecurity incident response. In 2025, alert optimization was conducted to reduce unnecessary notifications.
5. In the second half of 2024, endpoint protection was implemented to enforce USB access control. In 2025, software installation control measures are being introduced, with implementation scheduled for October.
Enhanced information security awareness 1. All new employees are required to sign the “Computer Usage Policy Agreement” to ensure they understand the company’s regulations regarding computer use, network management, software installation, and related policies.
2. New employees are required to complete the “New Employee Information Access Application Form.” After confirmation by relevant supervisors and the IT manager, personal computer access permissions are granted. Additional system access may be provided based on job requirements, upon submission of the “Information Access Addition/Modification Application Form,” and approval by the department manager.
3. In 2024, regular cybersecurity awareness campaigns were conducted covering topics such as ransomware prevention, vulnerability mitigation, email security, and major amendments to the Personal Data Protection Act. Awareness messages are set to display upon startup of personal computers. As of 2025, six sessions have been completed, with monthly campaigns ongoing.
4. In 2024, four social engineering drills were conducted. Excluding new employees, staff across departments demonstrated increased cybersecurity awareness—upon receiving suspicious emails, they not only refrained from clicking on them but also promptly reported such incidents to the Information Security Department, thereby enhancing collective defense against cyber threats. As of 2025, one social engineering drill has been completed.
5. In 2024, the “Information and Communication Security Incident Response and Internal Reporting Plan” was established and released. It defines the standards and reporting mechanisms for security incidents, outlines the organization of the response committee, and specifies detailed roles and responsibilities. A drill is scheduled for 2025, with implementation planned for December.
6. In 2024, an online course on cybersecurity vulnerability prevention was arranged for new employees, followed by an online assessment. A total of 33 new employees completed the course and passed the test. As of 2025, 15 new employees have completed the training.

5-2.Date reported to the Board of Directors in 2026: July 28, 2026
Category Operational Situation
Management Staffing 1.The Company has established an Information Security Management Team, staffed by two information security personnel responsible for carrying out information security-related operations, including the planning and implementation of information security systems, management of access rights for employee computers and the Company’s networks, administration of firewalls and antivirus software, planning for data redundancy and backups, and conducting recovery drills.
2.In 2025, the information security personnel participated in Group training courses covering personal data security maintenance regulations, social engineering awareness training, and information and communications security control guidelines, totaling 48 participant-hours.
3.In 2025, information security courses provided by the Taiwan Academy of Banking and Finance were completed, totaling 14 participant-hours. In addition, six participant-hours of information security courses provided by the Taiwan Academy of Banking and Finance were completed in 2025.
Information security and control measures 1.In 2025, six security patch updates were performed for the firewalls and servers, and real-time notifications of network disconnection events were implemented to enhance network incident response capabilities. In 2026, the firewall firmware was further updated.
2.In 2026, the email server was migrated to the cloud-based Microsoft 365 (M365) platform. Multi-factor authentication and email filtering mechanisms were enabled to prevent the dissemination of spam emails. All users’ email client software was also updated.
3.System and network operations are connected through an MPLS VPN to prevent malicious external access. The Company also uses HiNet enterprise cybersecurity services to block external attacks.
4.The Company provides employees with personal computers and controls access to its internal systems. Users are required to enter an account name and password, and passwords must be changed every three months. Accounts will be locked if passwords are not changed by the specified deadline. Passwords must contain at least eight characters and include a combination of letters and numbers.
5.In 2025, access rights to the ERP system were reviewed once in each half of the year to verify the accuracy of the authorized user list.
6.In 2025, vulnerability scans were completed for six servers, and penetration tests were conducted on three servers. Operating systems were upgraded, and application vulnerabilities identified with reference to the OWASP guidelines were remediated.
Information Equipment Security 1.Critical system servers are housed in a professional data center. Following the relocation of the Taipei office, two server racks were installed, and the network cabling and equipment were upgraded to enhance network security. Access control measures have also been implemented to manage personnel entry and exit.
2.In 2025, maintenance was performed on information system servers at all locations to reduce the risk of equipment failure. Hardware warranty and maintenance contracts were completed in 2026.
3.In 2025, full backups of the core systems, including programs and data, were completed in compliance with the 3-2-1 backup strategy for information security. Critical system data is backed up automatically twice a day, and the backup results are immediately reported by email. In 2026, a disaster recovery drill using backup data was completed.
4.In 2025, Managed Detection and Response (MDR) software was deployed to proactively detect, respond to, and mitigate cybersecurity threats. In 2026, the antivirus software will be replaced and upgraded to enhance malware-scanning capabilities.
5.In 2025, endpoint protection measures were implemented, including controls over access to and use of USB devices. In 2026, the Company strengthened its monitoring of Google Chrome version updates and restricted the use of Microsoft OneDrive cloud storage.
Enhanced information security awareness 1.All new employees are required to sign the “Agreement on Compliance with Computer Use Rules” to ensure that they understand the Company’s requirements regarding computer use, network management, software installation, and other related matters.
2.New employees are required to submit an access authorization application form. Access rights to systems used on their personal computers are granted only after approval by the relevant supervisors at each level and the head of the information technology function.
3.In 2025, the Company conducted monthly cybersecurity awareness campaigns, completing a total of 12 campaigns covering the prevention of ransomware-related damage, protection against cybersecurity vulnerabilities, email security, and significant amendments to the Personal Data Protection Act.
4.Cybersecurity awareness messages are displayed when employees start their computers. Six campaigns had been completed in 2026, and the awareness campaigns continue to be conducted monthly.
5.In 2025, the Company conducted three social engineering exercises. Employees across all departments enhanced their cybersecurity awareness and, upon receiving suspicious emails, refrained from opening attachments and promptly reported such emails to the Information Security Department, thereby jointly strengthening information and communications security. Two social engineering exercises had been completed in 2026.
6.In 2025, the Company issued the “Information and Communications Security Incident Response and Internal Reporting Plan,” which establishes cybersecurity incident classification criteria and reporting mechanisms, as well as the organizational structure and division of responsibilities of the incident response committee. The Company also conducted an exercise simulating a change to the login password of the human resources system. Following the exercise, multi-factor authentication was introduced as an enhanced protective measure.
7.In 2025, the Company arranged an online course on cybersecurity vulnerability prevention for new employees, followed by an online assessment. All 33 new employees completed the course and passed the assessment. In 2026, nine new employees had completed the course and passed the assessment.
6. Major Information and Communication Security Incidents:
  • No major information and communication security incidents occurred in 2024-2026. Most incidents were hardware failures, all of which were resolved within the originally defined SLA timeframe.
7. Information and Communication Security Risks and Mitigation Measures
  • Achieved the required standards of the SecurityScoreCard (SSC) platform—exceeding the industry average—and continuously addressing potential cybersecurity risks.
  • Implemented a globally recognized MDR system to respond to risk alerts in real time. Established a corresponding SOP knowledge base to reduce response time.
  • Conduct annual security incident reporting and disaster recovery drills on selected core systems, with continuous review and optimization of response strategies.
8.Information and Communication Security Risks and Mitigation Measures:
8-1.Number of information and communication security management meetings held
Item Number of Information and Communication Security Meetings in 2026
Internal Weekly Meeting 18
Internal monthly meeting 6
External Cybersecurity Forum 2

8-2.Asset security monitoring coverage
Item Coverage (imported count / total count)
MDR Active Protection (Laptops, Desktops, and Servers) 136/145=93.8%
Endpoint Protection (Laptops & Desktops) 128/128=100%