Digital transformation is a key strategy for HLC, and information security plays a central role within it. Internally, the Company has comprehensively revamped its official website and related applications and strengthened data integration mechanisms, to ensure that both security and operational efficiency are enhanced simultaneously. By leveraging AI technology, we have enhanced smart customer service functions and reduced potential risks associated with manual handling of sensitive data. Therefore, HLC views information security as a crucial component of corporate competitiveness and incorporates it as one of the key objectives in its digital transformation blueprint. Through continuous optimization and technological upgrades, we actively respond to ever-evolving external challenges. Information Security Management Policy and Governance Structure HLC has established a Information security Management Organization. The Chief Information Officer (CIO) serves as the Chief Information Security Officer (CISO), responsible for reviewing the Company’s information security management system objectives and implementation scope, chairing management review meetings, and making decisions about significant matters. We have also appointed information security professionals as information security consultants to provide guidance and consulting advice related to information security management and technical fields. The manager of the Operations Technology Office serves as the Executive Secretary, responsible for early warning and monitoring of information security status and for handling information security incidents. Information personnel are assigned to the “Information Security Response Team” and the “Information Security Audit Team” based on their tasks. The former is responsible for monitoring, responding to, and handling information security incidents to guarantee quick response and recovery of information assets in the event of a threat. The latter is responsible for internal audits and compliance reviews of the Information Security Management System (ISMS). After conducting internal audits annually, a management review meeting is held to report regularly to the CISO. Since implementing the ISO 27001 management system in 2024, the Company has continued to improve its information security management system, obtained external certification in August 2024, and completed the surveillance audit in 2025.
Information Security Management Measures and Achievements HLC has established a comprehensive information security infrastructure to ensure the stability and security of both internal and external corporate services. Key Dimension Description of Approach Host system upgrade and backup mechanism enhancement Host systems are fully upgraded and equipped with advanced backup management mechanisms to ensure continuous operation in any unforeseen circumstances. Concurrently, the Company is committed to continuously updating internal operating systems to reduce maintenance costs and potential risks, and enhance operational efficiency. We store key data, applications, and IT system backups in Far EasTone’s Taichung data center to prevent data loss and business interruption due to natural disasters, cyberattacks, or equipment failures. Strengthening information security control and data circulation efficiency To respond to increasingly complex cyber threats, the Company has deployed proactive defense mechanisms and strengthened information security control to ensure data integrity during transmission and storage. The adoption of cloud application technology and the optimization of API management models further enhance data circulation efficiency and lay a solid foundation for future digital transformation. Vulnerability scanning and risk assessment To ensure standardization and internationalization of security management, the Company regularly commissions information security consulting firms annually to perform vulnerability scanning and comprehensively assess information system vulnerabilities and the overall information security risk level. In 2025, two vulnerability scans were conducted. The third-party scanning reports provide HLC with clearer recommendations for vulnerability remediation, followed by secondary scans to ensure that all major vulnerabilities have been completely corrected. Zero trust architecture and endpoint security management To enhance endpoint and account security, HLC aligns with the Group’s information security policy by adopting a “Zero Trust mindset” in planning computer and system architectures. Through standardized computer and account operation standards and processes—including antivirus software, security updates, endpoint behavior detection, USB control, software installation privilege management, identity verification, automated installation procedures, and antivirus/security updates—we are strengthening our foundational infrastructure’s protection functions. We are also applying new information security defense features to reinforce identity authentication and the security of information system usage. Business Continuity Planning (BCP) To prevent disruption of the Company’s business activities and protect critical business processes from major failures or disasters, the Company has formulated alternative plans to execute in the event of a major failure or disaster that affects critical business processes. This ensures continued security and business operations, while mitigating losses caused by such incidents. Information security insurance coverage Through information security insurance, the Company reduces financial and legal risks caused by information security incidents, while gaining professional support to enhance response capabilities.
Information Security Incident Response Management HLC conducts at least one information security disaster recovery drill annually to enhance its team’s response capabilities, while ensuring swift action according to Standard Operating Procedures (SOPs) in the event of an information security incident. At the same time, we test backup and recovery mechanisms to verify their effectiveness in real-world scenarios, thus ensuring that critical systems can resume operation smoothly. During these drills, we also simulate attacks or system failures. This helps us identify potential vulnerabilities in our information security strategies and technologies and allows for immediate remediation to strengthen our overall information security defense capabilities. To further enhance information security management, the Company has established a reporting and response mechanism for information security and personal data breach incidents, with incident classification, severity levels, and response procedures clearly defined. In the event of an information security incident, we will complete damage control or recovery operations within the specified timeframe based on the impact level of the incident. Afterwards, we will be conduct root cause analysis and take corrective measures to prevent similar incidents from reoccurring.
Personal Data Protection In compliance with the Personal Data Protection Act and other applicable laws and regulations, HLC has established a “Personal Data Management Manual,” which clearly sets out the mechanisms governing the collection, processing, use, and protection of personal data. The Manual applies to the Company’s regular employees, contract employees, student workers, and outsourced service providers. To effectively manage privacy-related risks, HLC has established a “Personal Data Affairs Office,” headed by the Director of the Information Technology Department. Its principal responsibilities include coordinating and liaising with the competent authorities on personal data protection matters, issuing emergency response notifications, reporting personal data security incidents, and handling data subjects’ requests to exercise their rights. The Office comprises legal, customer service, audit, and information technology teams, which are respectively responsible for providing legal information on personal data protection, handling data subjects’ requests to exercise their rights, conducting personal data audits and following up on identified deficiencies, and protecting personal data in technology environments. An ad hoc Emergency Response Team is also established when necessary to manage emergency response activities and respond to personal data breaches. When collecting customer data, HLC adheres to the principle of data minimization, that is collecting only the necessary information required to provide services. Customers can easily query, correct, or delete their personal data through convenient channels, thus ensuring full data transparency and control. All information is processed using advanced encryption technology and secured with a layered access control mechanism to ensure that only authorized personnel can access sensitive data. For data storage and deletion, the Company sets clear retention periods and safely destroys data upon expiration to prevent any unauthorized use. Furthermore, we conduct annual personal data inventory and risk assessments. We also consistently offer employee personal data protection training on a yearly basis. Additionally, all outsourced service providers are required to sign personal data protection clauses and non-disclosure agreements. In 2025, there were no personal data breaches or infringement incidents occurring.
Artificial Intelligence Applications and Personal Data Protection HLC actively promotes the application of artificial intelligence and, based on the nature of its business operations, has introduced a diverse range of technologies, including generative AI and knowledge bases (LLM & RAG), AI agents and process automation, perceptual AI (speech/image/OCR), and conventional machine learning and analytics. Through these technologies, the Company is building an AI application ecosystem spanning all business units. The Company also allows employees to use generative AI platforms independently for applications such as text, image, and speech generation, presentation development, marketing proposal preparation, and code writing. These initiatives continuously enhance employees’ digital productivity and support the organization-wide adoption of an AI-enabled culture. While actively embracing AI technologies, the Company also places a high priority on personal data protection. HLC has established the “Regulations Governing Personal Data Management in Technology Environments,” which expressly prohibit personal data, as defined under applicable laws and regulations and Company policies, from being used with external artificial intelligence (AI) services for analysis, model training, testing, or other purposes, thereby mitigating the risk of data leakage. Where business needs require data containing personal information to be used for AI analysis or model processing, such use must be limited to AI tools developed internally or introduced by the Company. The matter must also be reported to the Personal Data Affairs Office and recorded in the personal data inventory. These requirements ensure that personal data remains properly controlled throughout the AI application process while maintaining an appropriate balance between technological innovation and data governance Strengthening Awareness of Information Security and Personal Data Protection HLC recognizes that information security and personal data protection require the collective efforts of all employees. In accordance with the “Guidelines for Information Security Control of Listed and OTC Companies,” the Company’s Chief Information Security Officer completes at least 15 hours of professional or competency-based information security training each year. The Company has also designated information security and personal data protection as mandatory annual training for employees. All current employees receive regular information security and personal data protection education and training at least once a year. Covering topics ranging from fundamental information security awareness to advanced technical applications, the training is tailored to the needs of employees in different functions and continuously reinforces the importance of information security throughout the organization. New employees are required to complete mandatory personal data protection and information security courses upon joining the Company to establish a fundamental understanding of information security and familiarize themselves with the Company’s relevant policies and requirements. Assessments are also administered to verify the effectiveness of the training. In 2025, 100% of new employees completed the required training. In addition, the head of the Information Technology Department completed the 40-hour “ISO/IEC 27001:2022 “ Information Security Management Systems Lead Auditor” training course. The training supports the Company’s internal assessments and improvement efforts and helps ensure compliance with certification requirements. Additionally, to continuously enhance information security risk awareness, HLC conducts an annual company-wide computer audit, focusing on computer and device security, network security, software and application security, and data access permissions. We also periodically send information security newsletters to share information security news and new knowledge, promoting and conveying the Group’s latest information security regulations and precautions. To test employees’ ability to handle information security incidents and improve potential weaknesses, HLC collaborates with the Group to conduct regular social engineering drills annually. In 2025, HLC conducted a simulated phishing email exercise covering all employees to assess their information security awareness, achieving a coverage rate of 100%. The target pass rate for the exercise was 80%, while the actual completion rate was 74%. Employees who did not pass were required to complete two hours of remedial online training delivered by an external instructor and achieve a score of 100 on the post-training assessment. The training covered key indicators for identifying phishing emails, procedures for reporting suspicious emails, and practical case studies, with the aim of comprehensively strengthening employees’ information security awareness and self-protection capabilities and reducing the potential risks associated with social engineering attacks.