The Company established an Information and Cyber Security Office on September 1, 2022, with one information security officer and one dedicated information security personnel. To effectively promote the implementation and operation of the company's Information Security Management System (ISMS), the Information and Cyber Security Management Committee was established on December 18, 2024, with the General Manager serving as the convener. A deputy convener and an executive secretary were appointed to coordinate the various tasks of the Information and Cyber Security Management Committee. Information security management representatives from the management levels of various business divisions and functional units are responsible for assisting in promoting and supervising the information security work of each unit. An Information Security Working Group was set up, divided into the following subgroups based on responsibilities: (1) Incident Response Team, (2) Information Asset Risk Management Team, (3) Document Management Team, and (4) Audit Team. Regarding the implementation and operation of the Company's Information Security Management System (ISMS), the system was officially announced in February 2025. The verification team from BSI Taiwan completed the two-phase verification in April 2025. After final confirmation by BSI Taiwan and headquarters, the ISO 27001:2022 certificate was issued in May, 2025, which certification is valid from May 14, 2025 to May 13, 2028. Furthermore, in order to verify the continued effectiveness of ISMS operations and compliance with the standard requirements, the BSI Taiwan verification team conducted a surveillance audit on February 10, 2026. The audit concluded with a pass for the ISO/IEC 27001:2022 Surveillance Audit. The ISMS was assessed as having a high level of maturity, stable management mechanisms, and zero nonconformities, demonstrating the organization’s capability to continuously maintain ISO/IEC 27001 certification.
The Company has not only obtained the ISO 27001:2022 certification but has also partnered with AIG Taiwan and Fubon Insurance to implement a cybersecurity insurance program, which insurance period runs from 12:00 on December 1, 2025, to 12:00 on December 1, 2026, with a coverage amount of USD 5 million. This measure aims to strengthen our financial resilience and response capabilities, effectively reduce supply chain risks, and enhance trust and collaboration among upstream and downstream partners. In addition, the Company has joined the Taiwan Cybersecurity Management Alliance (CISO Alliance) and the Taiwan CERT/CSIRT Alliance to enhance cybersecurity governance through cross industry exchanges, participation in regulatory and policy discussions, promotion of supply chain security, threat intelligence sharing, incident reporting and coordination, and technical collaboration. These efforts strengthen our cybersecurity management, technical defense capabilities, and operational resilience, while aligning with the national cybersecurity joint defense framework to elevate our overall cybersecurity maturity.

In alignment with the core business characteristics of the Company, the Policy establishes a framework to protect the rights and interests of the Company and its stakeholders. (including but not limited to employees, customers, vendors/upstream suppliers, shareholders, investors and financial/securities institutions, non-vendor suppliers/contractors, and government/competent authorities and society). All employees and the Company are collectively responsible for fostering a safe information and communication environment, enabling information security to be embedded into its corporate culture. The Company will implement a tailored-information security policy to clearly define security objectives and establish compliance requirements which shall be consistently upheld. For detailed information, please refer to the "Information and Cyber Security Policy" published on the Company's official website (Approved by the Board of Directors on January 13, 2025).
| Organizer | Course / Awareness Topic | Hours / Frequency | Participants |
|---|---|---|---|
| Taiwan Corporate Governance Association | Information security governance and management under geopolitics | 3 hours | Head of Information and Cyber Security obtained a certificate from Taiwan Corporate Governance Association |
| Yuan Ze University remote course | Fundamental Concepts of Digital Forensics | 3 hours | Information and Cyber Security Staff obtained a certificate from Yuan Ze University |
| Taipei e-Campus | ChatGPT Applications, AI Development, and Future Cybersecurity Threats | 3 hours | A total of 10 personnel, including the Head of Information and Cyber Security, Information and Cyber Security Staff, and IT personnel obtained certificates from Taipei e-Campus |
| Taipei e-Campus | Awareness Training on Information Security and Personal Data Protection | 3 hours | A total of 3 IT personnel obtained certificates from Taipei e-Campus |
| Taipei e-Campus | Latest Cyberattack Trends and Case Studies | 3 hours | A total of 3 IT personnel obtained certificates from Taipei e-Campus |
| UCOM Education & Training Center | Identity and Access Management in Windows Server 2016 | 3 hours | A total of 2 IT personnel |
| MIS / Information and Cyber Security Office (ICSO)- Internal Training | Information and cyber security education for new employees | 3 sessions | 32 new employees |
| Legal Office-Internal Training | Personal Data Protection, Confidentiality, and Software Usage Awareness | 3 sessions | 32 new employees |
| Chunghwa Telecom | 2025 Cybersecurity Threat Trends and Responses | 1 hours | 396 on-the-job employees |
| Chunghwa Telecom | Information Security Management System (ISMS) Introductory Meetings | 24 times | 23 information / cyber security and project team personnel |
| MIS / Information and Cyber Security Office (ICSO)- Internal Training | MIS Cybersecurity Awareness – “Information and Cyber Security and Software Use” and “Cybersecurity Intelligence” | 41 times | All employees |

In the year 2025, the Company did not incur any losses or experience any incidents affecting operations or reputation due to major information or cybersecurity events. Furthermore, there were no verified complaints regarding customer privacy violations or the loss of customer data.