We shoulder responsibilities for sustainability
by incorporating ESG foundations in our DNA at Ennostar
Information security and privacy controls have become an indispensable part of daily business execution. The parent company of Ennostar Group has established a dedicated information security management department responsible for Group information security operations and maintenance, architecture, policies, projects, and audit activities, leading subsidiaries in achieving Ennostar's information security objectives.
The Group has established Information Security Management Regulations to ensure the normal, secure, and stable operation of core information-system services and critical information infrastructure. These regulations serve as the highest-level guidance for the Information Center's information security management system, providing secure and reliable information services, ensuring the confidentiality, integrity, and availability of Information Center assets, complying with applicable laws and regulations, maintaining business continuity, reducing information-processing risks, and protecting the rights and interests of information-service users.
To ensure implementation strategies, targets, and performance related to information security, the Group established an Information Security Committee. The first level is the Board of Directors, responsible for deciding major information security proposals. The second level is the Corporate Sustainability and Risk Management Committee, chaired by the Group Chairman, responsible for determining the Group's information security direction and targets. The third level is the Information Security Committee, chaired by the Chief Information Security O icer, responsible for advancing Group targets and key initiatives. The fourth level is the Information Security Unit, responsible for implementing targets and projects. Information security management review meetings are held twice a year to report implementation status and resolutions to the President.

To ensure information security, meet customers' quality expectations, and protect privacy, the Group has established information protection management processes in accordance with ISO 27001. All Ennostar Group sites in Taiwan obtained third-party ISO 27001 certification in 2025, establishing information security management procedures aligned with international standards. Through international certification, the Group aims to reduce information security threats and provide the highest-standard protection for confidential information, including customers' intellectual property and process parameters.
To reduce the probability of risks and lessen their impacts, the Group actively introduces management systems as risk response measures:
- Pass an ISO 27001 information security management audit and certification conducted by an independent external third party each year.
- Conduct a risk assessment every six months.
- Conduct an internal audit every six months.
- Monitor daily for major information and communications security incidents caused by cyberattacks. Conduct six social-engineering phishing email drills each year on an unscheduled basis.
- Conduct a business continuity management plan drill each year based on the business-process impact analysis form.
- Maintain a weekly Panorays third-party rating score above 90.
The Group has established an information security incident response mechanism managed through seven stages: preparation, protection, detection, containment, eradication, recovery, and review. In the preparation stage, endpoint detection and response (EDR) tools and third-party monitoring mechanisms are comprehensively deployed for real-time detection and response. In addition to daily backups, o line backups are retained, and incident response drills are conducted annually under the response plan. In the protection stage, vulnerability scanning and a third-party risk-monitoring platform are used to understand vulnerability risk status. Remediation progress is reported at weekly meetings, and managers conduct backup restoration tests. When an incident is detected, it is classified and reported. The first priority is containment, including network disconnection and other isolation measures, to reduce impacts. Digital evidence is collected and properly preserved to support root cause investigation and eradicate threats before they recur.
