Information Security

In response to the digitalization trend, increasing information security risks, and stakeholders’ growing expectations regarding information security, Uni-President Asset Management has established its Information Security Policy to comprehensively strengthen information security governance and build secure and trustworthy information systems. This ensures the security of data, systems, equipment, and networks, safeguards customers’ rights and interests, and ensures compliance with applicable regulations. The Company’s information security management is centered on the three core principles of confidentiality, integrity, and availability. These principles ensure that information is accessible only to authorized personnel, prevent unauthorized disclosure, maintain the accuracy and integrity of information, and ensure that authorized users can access relevant information and assets when needed. Through comprehensive policies and procedures, clear management accountability, and the effective implementation of specific control measures, the Company continues to maintain operational stability and enhance stakeholders’ trust.

Information Security Management Framework

To implement the Company’s Information Security Policy and ensure clear accountability in information security governance, the Company has established a comprehensive information security management structure. The Information Security Promotion Team (Convener: Head of the Operations & Support Division) is responsible for coordinating the overall direction of the Company’s information security governance, supervising the implementation of information security-related operations across all departments, and ensuring the effective operation of various information security management mechanisms through regular meetings. At the execution level, the Company has established an Information Security Promotion Team responsible for planning information security projects, formulating specific implementation plans, and coordinating the promotion and execution of various information security measures to continuously enhance the Company’s overall information security management capabilities.


The Information Security Promotion Team consists of an Information Security Subteam and an Audit Subteam. The Information Security Subteam is responsible for day-to-day information security management, including core control measures such as network security protection, data encryption, and access control management, to safeguard the confidentiality, integrity, and availability of information assets. The Audit Subteam periodically reviews and verifies the implementation of information security projects and related control measures, and provides recommendations for improvement based on audit results to mitigate potential information security risks and continuously enhance the overall effectiveness of information security governance.

Information security governance structure

Information Security Incident Reporting Process

To strengthen the Company’s ability to respond promptly to information security incidents, enhance reporting mechanisms, and ensure that related risks are properly managed, the Company has established comprehensive handling procedures in accordance with the Uni-President Asset Management Information Security Incident Reporting Procedures. These procedures clearly define the reporting, response, and follow-up processes for unexpected information security incidents. Covered incident types include data breaches, system vulnerabilities, and attacks involving viruses or malicious software. Upon becoming aware of an information security incident, the Company reports the incident to the competent authority within 30 minutes in accordance with applicable regulations and simultaneously activates its internal response and control mechanisms. This ensures that the incident is addressed promptly and appropriately, mitigates potential impacts, and safeguards the rights and interests of customers, employees, and other stakeholders, demonstrating the Company’s strong commitment to information security governance and risk management.

Information Security Reporting Process

Cybersecurity incident reporting process

Information Security Risk Identification and Control Measures

The Company has established a comprehensive information security protection mechanism and designated its corporate website, stock affairs system, accounting system, and order placement system as core operating systems. A business impact analysis has been completed and submitted to the Board of Directors to strengthen governance-level oversight and supervision of risks associated with critical information systems. The Company continues to enhance information system security protection and business continuity management to minimize the impact of unforeseen incidents on operations and customer services, thereby ensuring the stable operation of its core business activities.


To further enhance the maturity of information security governance, the Company plans to implement the PRTG information security monitoring tool as a mechanism for monitoring abnormal activities. The Company also plans to engage an independent third party to conduct an information security governance maturity assessment and refine information security risk control measures based on the assessment results. In addition, the Company is evaluating the adoption of cyber insurance to support its long-term stable operations and sustainable development.

Risk Categories

Infrastructure Risks

Infrastructure Risks

Risk Description
Power outage: In the event of a power supply disruption, information systems may become inoperable, affecting business continuity
Risk Control Measures
- Install a UPS (Uninterruptible Power Supply).
- Connect the building’s diesel generator system to extend backup power supply
Risk Description
Interruption of dedicated external service network lines: If external connections are disrupted, websites and online services may become unavailable, affecting customers’ user experience
Risk Control Measures
- Network Load Balancing Equipment (Radware Alteon Redundancy Mechanism)
- Two dedicated lines from different ISPs, with automatic traffic failover to the backup line upon detection of abnormalities
Cyberattack Risks

Cyberattack Risks

Risk Description
Cyber attacks: Potential hacker attacks, DDoS attacks, or other malicious activities may compromise system security and data integrity
Risk Control Measures
- McAfee IPS, Trend Micro Antivirus, and So-Net CDN
- System vulnerability scanning (twice a year), source code review for the official website and mobile app (once a year), and official website penetration testing (twice a year)
- Social engineering, backup and recovery, network redundancy, incident reporting drills
Risk Description
APT and unknown information security threats: APT or unknown malicious attacks may infiltrate corporate networks and compromise system security
Risk Control Measures
- Implement an MDR endpoint protection mechanism for real-time detection and automatic threat blocking
- Enhance recovery capabilities and conduct regular reviews.
Data Corruption Risks

Data Corruption Risks

Risk Description
File and data corruption: Data corruption caused by virus infections, equipment failures, or human errors may affect business operations
Risk Control Measures
- Perform daily backups of program files and databases; Store backups on file servers and tape media to enable immediate recovery in the event of abnormalities
Risk Description
Interruption of customer transactions or loss of transaction data: Transaction system failures or database corruption may result in transaction interruptions or loss of records
Risk Control Measures
- Establish a high-availability redundancy mechanism to ensure uninterrupted transactions
- The official website’s electronic trading system adopts a database cluster architecture to ensure the integrity of transaction records and prevent transaction data loss caused by single points of failure
Cybersecurity Threat Intelligence Risks

Cybersecurity Threat Intelligence Risks

Risk Description
Insufficient threat intelligence: Failure to promptly obtain the latest threat intelligence may hinder effective responses to emerging attacks and vulnerabilities
Risk Control Measures
- Join the Financial Information Sharing and Analysis Center (F-ISAC) to participate in joint defense and threat intelligence sharing, while gradually strengthening internal intelligence-sharing mechanisms
- Implement privileged access controls for Winmatrix Client
- Deploy Deep Security to protect the official website against tampering
- Establish a four-level ISMS document management framework and conduct regular reviews and revisions

Statistics on Information Security Incidents and Personal Data Protection Measures

To continuously strengthen the resilience of information security protection and safeguard the data security and privacy rights of customers and stakeholders, Uni-President Asset Management has established a systematic and consistent information security management mechanism through a comprehensive set of policies, reporting procedures, and information security control measures to address the increasingly complex digital risk landscape. The Company did not experience any material information security incidents or personal data breaches in 2025.


Furthermore, in response to personal data protection regulatory requirements and to continuously enhance data governance and control measures, the Company has further strengthened its personal data protection mechanisms. The Company currently implements the following management measures to ensure the proper protection and secure transmission of personal data.

 
Encrypted transmission of personal information
When business units request personal data for operational needs, the Information Technology Department transmits such data in encrypted form to ensure secure transmission.
 
Personal Data Screening for Emails
External emails are automatically screened before being sent. Emails containing 10 to 20 records of personal data must be reviewed by a supervisor and sent in encrypted form, while emails containing more than 20 records are prohibited from being sent to prevent personal data breaches.
 
Personal Data Retention Review
The Information Technology Department conducts regular reviews every six months and deletes unnecessary personal data to ensure compliant management.

Information Security Risk Awareness Enhancement and Training

In addition to continuously enhancing its information security policies, processes, and systems, the Company also provides diverse information security education and training programs for directors, supervisors, general employees, and IT personnel to strengthen their information security knowledge and risk awareness, thereby jointly reinforcing the Company’s overall information security framework. In 2025, the Company’s information security expenditures (including hardware and software licensing fees and employee training costs) accounted for 46.20% of its total information technology budget.


During the year, the Company arranged information security awareness sessions, training on emerging technology security, and social engineering defense training for directors, totaling 3 hours, to enhance information security literacy at the governance level. To strengthen employees’ information security risk awareness, Uni-President Asset Management conducts information security awareness campaigns via email every six months to remind employees to comply with relevant policies and requirements. The Company also regularly organizes information security awareness sessions, training on emerging technology security, and social engineering defense courses. Training content includes information classification management, awareness of information security risks related to deepfakes, and prevention measures. These programs aim to enhance employees’ information security awareness and skills, while improving the team’s understanding of and response capabilities regarding the latest information security risks and threat trends. The training duration totaled 3 hours, with 239 participant attendances.


To strengthen the Company’s information security personnel’s understanding of information technology developments, cybersecurity technologies, threat trends, and incident response capabilities, the Company arranged for Information Technology Department employees to participate in external training courses totaling 64 hours in 2025, with all participants successfully obtaining the relevant certifications. In addition, to continuously enhance the professionalism of the information security team, the Company encourages information security personnel to participate in professional training and obtain internationally recognized certifications, including CISM (Certified Information Security Manager) and CompTIA Security+. Currently, the number of information security-related certifications obtained represents 9.68% of the Company’s total assets (with total assets measured in units of NT$100 million).

2024 Information Security Investment

Software and hardware licenses and employee training as a percentage of the total information budget
46.20%