The company prioritizes cybersecurity and data protection to prevent impacts on business operations. The Technology and Cybersecurity Committee reviews the cybersecurity risk management policies to align with business objectives and the company`s context, including preparing for new threats and complying with relevant laws and international standards. These serve as guidelines for managing technology and cybersecurity risks for Information Technology (IT) systems, Operational Technology (OT) systems, and Artificial Intelligence (AI) systems, in accordance with the NIST Cybersecurity Framework (CSF) 2.0. This framework includes: Governing cyber risks (Govern) to ensure continuous management and reporting of cybersecurity performance; Identifying scope and understanding various contexts for cyber risk management (Identify), including vulnerability management (inspecting and closing cyber vulnerabilities); Protecting against cyber risks (Protect); Detecting and monitoring risks (Detect); and Responding to threats and recovering systems (Respond & Recover).

The company is certified for information security management (ISO27001 and 27701) and also promotes and builds cybersecurity awareness among employees through regular Information Security & Cybersecurity Awareness training. The content is updated to align with each functional operation (Role-Based Training). Simulated phishing, smishing, and quishing emails or messages are conducted. Employees are informed about the methods and channels provided for reporting cybersecurity incidents. Virtual cyber threat response drills (Cyber-Drill and Incident Response Tabletop Exercise) are organized to ensure employees are prepared to prevent and respond to cyber threats by improving the Business Continuity Plan and related cybersecurity operational processes.
Additionally, the company is committed to protecting the personal data of customers, partners, personnel, and stakeholders, ensuring it is safe and compliant with personal data protection laws and guidelines set by regulatory bodies in each country. A Personal Data Protection Policy has been established, and a Personal Data Protection Officer unit regularly inspects, supervises, and educates on the use of customer personal data.
Target and Performance
2024 Target | 2024 Performance | |
---|---|---|
Number of incidents related to the cybersecurity | 0 | 0 |
For more information, please refer to 2024 Annual Report (Form 56-1 One Report); Part 1 Business Operation and Performance, page 51 – 52.
Performance