
Information Security

Information Security Management Framework
To implement the Company’s Information Security Policy and ensure clear accountability in information security governance, the Company has established a comprehensive information security management structure. The Information Security Promotion Team (Convener: Head of the Operations & Support Division) is responsible for coordinating the overall direction of the Company’s information security governance, supervising the implementation of information security-related operations across all departments, and ensuring the effective operation of various information security management mechanisms through regular meetings. At the execution level, the Company has established an Information Security Promotion Team responsible for planning information security projects, formulating specific implementation plans, and coordinating the promotion and execution of various information security measures to continuously enhance the Company’s overall information security management capabilities.
The Information Security Promotion Team consists of an Information Security Subteam and an Audit Subteam. The Information Security Subteam is responsible for day-to-day information security management, including core control measures such as network security protection, data encryption, and access control management, to safeguard the confidentiality, integrity, and availability of information assets. The Audit Subteam periodically reviews and verifies the implementation of information security projects and related control measures, and provides recommendations for improvement based on audit results to mitigate potential information security risks and continuously enhance the overall effectiveness of information security governance.

Information Security Incident Reporting Process
Information Security Reporting Process

Information Security Risk Identification and Control Measures
The Company has established a comprehensive information security protection mechanism and designated its corporate website, stock affairs system, accounting system, and order placement system as core operating systems. A business impact analysis has been completed and submitted to the Board of Directors to strengthen governance-level oversight and supervision of risks associated with critical information systems. The Company continues to enhance information system security protection and business continuity management to minimize the impact of unforeseen incidents on operations and customer services, thereby ensuring the stable operation of its core business activities.
To further enhance the maturity of information security governance, the Company plans to implement the PRTG information security monitoring tool as a mechanism for monitoring abnormal activities. The Company also plans to engage an independent third party to conduct an information security governance maturity assessment and refine information security risk control measures based on the assessment results. In addition, the Company is evaluating the adoption of cyber insurance to support its long-term stable operations and sustainable development.
Risk Categories
Infrastructure Risks
Cyberattack Risks
Data Corruption Risks
Cybersecurity Threat Intelligence Risks
Statistics on Information Security Incidents and Personal Data Protection Measures
To continuously strengthen the resilience of information security protection and safeguard the data security and privacy rights of customers and stakeholders, Uni-President Asset Management has established a systematic and consistent information security management mechanism through a comprehensive set of policies, reporting procedures, and information security control measures to address the increasingly complex digital risk landscape. The Company did not experience any material information security incidents or personal data breaches in 2025.
Furthermore, in response to personal data protection regulatory requirements and to continuously enhance data governance and control measures, the Company has further strengthened its personal data protection mechanisms. The Company currently implements the following management measures to ensure the proper protection and secure transmission of personal data.
Information Security Risk Awareness Enhancement and Training
In addition to continuously enhancing its information security policies, processes, and systems, the Company also provides diverse information security education and training programs for directors, supervisors, general employees, and IT personnel to strengthen their information security knowledge and risk awareness, thereby jointly reinforcing the Company’s overall information security framework. In 2025, the Company’s information security expenditures (including hardware and software licensing fees and employee training costs) accounted for 46.20% of its total information technology budget.
During the year, the Company arranged information security awareness sessions, training on emerging technology security, and social engineering defense training for directors, totaling 3 hours, to enhance information security literacy at the governance level. To strengthen employees’ information security risk awareness, Uni-President Asset Management conducts information security awareness campaigns via email every six months to remind employees to comply with relevant policies and requirements. The Company also regularly organizes information security awareness sessions, training on emerging technology security, and social engineering defense courses. Training content includes information classification management, awareness of information security risks related to deepfakes, and prevention measures. These programs aim to enhance employees’ information security awareness and skills, while improving the team’s understanding of and response capabilities regarding the latest information security risks and threat trends. The training duration totaled 3 hours, with 239 participant attendances.
To strengthen the Company’s information security personnel’s understanding of information technology developments, cybersecurity technologies, threat trends, and incident response capabilities, the Company arranged for Information Technology Department employees to participate in external training courses totaling 64 hours in 2025, with all participants successfully obtaining the relevant certifications. In addition, to continuously enhance the professionalism of the information security team, the Company encourages information security personnel to participate in professional training and obtain internationally recognized certifications, including CISM (Certified Information Security Manager) and CompTIA Security+. Currently, the number of information security-related certifications obtained represents 9.68% of the Company’s total assets (with total assets measured in units of NT$100 million).