Information Security


Information Security

 

Information Security Governance and Organization

 
The role of information security is crucial to the operation of CTCI. Therefore, CTCI has incorporated information security into the company's overall risk management framework and established the Information Security Promotion Committee, with the President of CTCI serving as the committee chairman and Chief Information Security Officer (CISO) to issue Information Security Policy Statement as the foundation of promoting ISMS. In terms of execution, the Information Security Promotion Committee is responsible for formulating information security objectives, strategies, and management procedures. At least once a year, the committee convenes an Information Security Management Review Meeting to review information security management matters, conduct a risk assessment report, and review risk treatment plans. Additionally, recognizing the increasing importance of information security and to comply with the requirements of Taiwan's Financial Supervisory Commission for secondary exchange listed company, CTCI has established an Information Security Audit Section under the Information Security Promotion Committee to carry out IT audit operations. Such mechanism ensures effective operation of the ISMS, helps strengthen internal risk control, and continuously enhances information security capabilities, thus ensuring compliance with regulations and protecting business continuity. It was integrated into the Sustainability and Information Security Committee in 2025. The committee members are all composed of members of the Board of Directors, with Chien-Chung Li as the convener, and Directors Yancey Hai and Michael Yang as committee members. They report regularly to the Board of Directors.
 

 

Information Security Risk Assessment

CTCI has formally integrated information security into its overall risk management framework and conducts information security risk assessments at least once a year. For risks exceeding acceptable thresholds, CTCI would propose risk response plans and take measures to manage risks, ensuring continuous monitoring and improvement.
 

Key Information Security Risks in 2025

In recent years, with the frequent occurrence of Advanced Persistent Threat (APT) incidents, the company is facing increasing cybersecurity risks. To mitigate the likelihood and impact of these risks, CTCI has established comprehensive control measures against APT threats. Key measures include: privileged account management to ensure the security of highlevel access accounts; account review to regularly audit account activities and anomalous behaviors; social engineering exercises to raise employees' awareness of phishing and social engineering attacks; intrusion detection and malware detection systems for realtime monitoring and prevention of potential attacks; and regular drills and testing to ensure the effectiveness of cybersecurity defenses. Through these multi-layered APT control strategies, CTCI not only enhances its real-time detection and defense capabilities against cyber threats, but also strengthens the resilience of its overall information security management system, safeguarding corporate operations and data integrity.

APT Monitoring and Control Measures

Information Security Management System

Information Security Incident Reporting Procedure

In accordance with Information Security Incident Management Procedures and Information Security Management Regulations, if any employee of the company or third-party vendor discovers any abnormalities in information systems or equipment, or suspects a data breach, they are required to promptly report the incident following the tiered information security reporting mechanism. The report should be directed to the system administrators responsible for the relevant data, systems, or server rooms, as well as the Help Desk. The Help Desk is responsible for incident logging and follow-up. A clearly defined tiered reporting mechanism ensures that incidents are handled appropriately based on their severity, thus expediting the response process, minimizing the impact of information security risks on operations, and enhancing the timeliness and effectiveness of information security management.
 

Information Security Business Continuity Plan

CTCI continuously strengthens its information security protection and business operation
resilience. To ensure rapid recovery of information systems and uninterrupted operations in the event of a major information security incident or disaster, the company has established an incident response and backup mechanism in accordance with the "Information Security Management Regulations." The Kaohsiung backup data center serves as the primary site for backup operations. Critical system data is backed up, stored off-site, and regularly tested. Semi-annual exercises are conducted to simulate real-life scenarios, covering data recovery for key systems, system failover, emergency response procedures, and personnel responsibilities. These exercises validate the continuity of system operations and the integrity of data.
 
In addition, the company continues to implement the following routine information security measures:
● Weekly: Off-site backup, storage, and testing.
● Semi-annually: Business continuity exercises and vulnerability scanning.
● Annually: Vulnerability analysis by external experts, penetration testing (simulated hacker attacks), privileged account management reviews, and user account review.
 
Through a comprehensive backup infrastructure, disaster recovery exercises, and regular testing, CTCI is able to effectively identify potential risks, respond promptly to information security incidents, and significantly enhance the operational resilience of its information systems.
 

ISO 27001 Certification

To ensure information security and business stability, CTCI has established a comprehensive management system in accordance with ISO 27001. In 2023, CTCI obtained ISO 27001 certification for its Information Security Management System (ISMS), valid through 2026 (the certification body is SGS). To ensure continued alignment with international standards, the company undergoes annual surveillance audits conducted by third-party certification bodies, continuously strengthening the effectiveness of information security governance and the quality of its management practices.
 
As part of its commitment to the effective operation and continuous improvement of its IT infrastructure and ISMS, the company conducts internal audits semi-annually in line with ISO 27001 requirements. These audit results help identify potential risks and provide recommendations for improvement, enabling timely optimization and further reinforcing information security governance and overall operational resilience.
 

Information Security Awareness Enhancement

In response to the constantly evolving information security threats and tactics, CTCI continues to enhance the information security awareness of its colleagues. In 2025, the company conducted information security training for both IT Department staff and employees in general, totaling 8,523 hours. Professional information security training
 
covered ISO 27001 Information Asset Inventory and Risk Analysis, Software Development Life Cycle (SDLC) and Secure Coding, Internal Audit Methodologies, and participation in CYBERSEC Taiwan. General information security training covered topics such as recognizing social engineering attacks and information security focus, as well as Group information security management requirements awareness training. To hone skills, CTCI encourages colleagues from the IT Department to participate in various types of cybersecurity seminars, such as CYBERSEC, and invite vendors to introduce the latest information security trends and solutions. The company introduces various control measures to counter information security risks, such as USB blocking, digital sensitive document management, restrictions on personal wireless networks, and physical isolation of test environment. To reduce the likelihood or impact of risks, the company also strengthens backup management, engages external experts for third-party vulnerability analysis, and simulates hacker attacks. In terms of knowledgesharing, CTCI not only conducts physical education and training, but also creates online courses that teach employees how to identify social engineering attacks and gain a basic understanding of critical information security.
 

To enhance the information security awareness among all employees, CTCI uses the corporate intranet to post announcements on information security-related information. In the face of increasing threats, CTCI also established a social engineering prevention service, known as checkmyemail@ctci.com, through which employees could report suspicious emails, thereby enhancing the security of email communications. Given the severe threats posed by malicious and phishing emails, CTCI conducts quarterly social engineering exercises for 50% of its employees, ensuring that every employee takes part in the exercise at least twice a year. In 2025, CTCI continued conducting social engineering email exercises that drew on the latest current events and fabricated system notifications to enhance employees' awareness. As a result, there has been a decrease in the number of employees that have been categorized as mid-to-high risk compared to previous years, indicating the gradual integration of information security awareness into the work environment of all employees.
 

Outcome of Information Security Promotion

CTCI remains committed in promoting information security, firmly adhering to the four main objectives laid out in its information security policy. The company puts effort in safeguarding the confidentiality, integrity, and availability of information. The effort not only reflects CTCI's strength in the field of information security, but also highlights its high regard and commitment to corporate operations and the client's information security.
 

Between 2022 and 2025, CTCI reported no information security incidents, and there were no occurrences of personal data breaches or adverse impact on the rights and interests of customers or employees resulting from such events.