As cybersecurity threats grow increasingly sophisticated, enterprises must continuously strengthen their protective mechanisms to ensure the security and stability of business operations.

 

In 2017, the Group's IT Center implemented and obtained certification for the "ISO 27001 Information Security Management System," embedding the Plan-Do-Check-Act (PDCA) management cycle to meet the objectives and requirements of the management system. In response to updates to international standards, the Company successfully completed the transition certification to the ISO/IEC 27001:2022 updated standard in 2025. The current certificate is valid until July 19, 2026.

 

In 2025, we continued to advance our information security management toward a Zero Trust architecture, strengthening identity authentication, endpoint and device security, and network segmentation. Guided by the People, Processes, and Technology (PPT) model, we continued to enhance information security maturity and reinforce cyber resilience through key initiatives.

 

These efforts support our digital transformation and help ensure the sustainable development of our business operations.

 

PDCA Method

PDCA METHOD

 

 

Information Security Organizational Structure

CEC has established an "Information Security Management Committee," convened by the Chief Information Security Officer (CISO) and composed of supervisors from relevant units. CEC has a total of 35 information security personnel. The Committee convenes regular meetings to review implementation progress and execution status, and reports the results to the Board of Directors annually.

 

In 2025, we focused on strengthening the inventory of information assets and risk management mechanisms, enhancing information security training and personnel awareness, implementing access control and account management systems, reinforcing system backup and business continuity management, and optimizing multi-layered information security defense and monitoring mechanisms.

 

Through these efforts, we continued to improve our overall information security governance framework across institutional, technical, and managerial dimensions. This ensures that our information security practices meet both CEC's internal operational needs and international standards.

Information Security Organizational Structure

Information Security Organizational Structure
 

Information Security Management

To ensure the Company's information security and mitigate potential associated risks, we have established a comprehensive information security management framework in accordance with international standards and best practices. This framework is based on the ISO 27001 Information Security Management System (ISMS) and the five core areas of the National Institute of Standards and Technology (NIST) Cybersecurity Framework. Through this framework, we ensure the effective management of cybersecurity risks both internally and externally within the organization.

5 Major Areas of Information Security and Key Measures SOC

Five Core Domains of Information Security and Key Measures

In addition to managing information security in accordance with the ISO 27001 framework, CEC’s information security management practices are structured around four key dimensions: institutional and risk management, education and personnel management, technical protection and monitoring, and external collaboration and oversight. Through the parallel advancement of institutional development, risk control, and technical enhancement, we continue to strengthen our overall information security protection capabilities and incident response resilience. The relevant measures are summarized in
the table below.

  

Management Practice Key Measures
Policy and Risk Management • Established an information security management system based on the ISO 27001 framework.
• Conduct regular information asset inventories, risk assessments, and risk control measures.
• Established information security incident reporting and response procedures.
Education, Training and Personnel Management • Conduct information security training twice a year, along with annual social engineering simulation exercises.
• Require new employees to complete information security training and sign confidentiality agreements.
• Require all employees and outsourced contractors to sign confidentiality documents.
Technical Protection and Monitoring • Established multi-layered information security defense and backup mechanisms.
• Conduct regular vulnerability scanning and remediation, and implemented a Managed Detection and Response (MDR) monitoring system.
• Protect endpoint devices with antivirus software and strictly control account access rights.
External Collaboration and Supervision • Engage external professional vendors to provide 24/7 monitoring services.
• Supervisors oversee the implementation of information security policies.
• Participate in the Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC), the Information Security Officer Association, and the Taiwan Chief Information Security Officer Alliance to facilitate information security intelligence sharing and strengthen overall joint defense and incident response capabilities.

Results of Information Security Promotion

1

Official Website Vulnerability Scanning

  1. CEC conducts annual vulnerability scans on its official website and implements necessary remediation measures to address security vulnerabilities and prevent potential cyberattacks.
  2. MFA Deployment for VPN Access Across Sites
  3. VPN serves as a critical security gateway for employees to remotely access internal systems. MFA was fully enabled for the VPN at Taipei Headquarters in 2024, and deployment across all manufacturing sites was completed in 2025.

2

Implementation of O365 and MFA

CEC implemented Microsoft 365 in 2025 and enforced Multi-Factor Authentication (MFA) to strengthen account authentication security and protect sensitive corporate information.

3

Update Firewalls and Strengthen Cloud Application and Email
Security

  1. Deploy next-generation firewalls (NGFW) to enhance intrusion detection and prevention (IDS/IPS), improving real-time response capabilities to network attacks.
  2. Enhance the integration and management of the cloud service platform while strengthening data protection mechanisms.
  3. Provide advanced threat protection to effectively guard against malicious emails, phishing attacks, and ransomware, ensuring secure corporate communications.

4

Continuous Improvement of Employee InformationSecurity  Awareness

  1. In 2025, all Taiwan-based employees participated in a one-hour basic information security training session.
  2. Two phishing social engineering simulation exercises were conducted, with click rates of 2% and 16%, respectively. Employees who clicked the simulated phishing emails were required to attend additional training and pass a test to ensure their understanding of CEC’s information security policies. The 2026 target is to further reduce the overall click rate to below 7%.

5

Information Security Protection and Offsite Backup Drills

Backup or monitoring mechanisms and drills have been established for critical information systems. Vulnerability scans are conducted regularly each year, and medium- to high-risk vulnerabilities are remediated accordingly. In 2025, all key systems completed at least two disaster recovery simulation drills.

Response and Management

CEC attaches great importance to information security incidents. In addition to ensuring timely response and damage control, we actively implement information security management measures to maintain customer trust and ensure the stability of business operations.

 

Upon confirmation of an information security incident, CEC immediately reports the incident to the Chief Information Security Officer (CISO), assesses the scope of impact, and activates the Emergency Response System (ERS).

The response process covers network isolation measures, such as disconnecting affected devices from the network and disabling VPN access, as well as system protection actions, such as password resets and verification of backup restoration. At the same time, relevant data is collected and provided to information security service providers for forensic investigation and evidence preservation.

 

In terms of information transparency and regulatory compliance, CEC promptly notifies the heads of affected business units and relevant stakeholders. Depending on the nature of the incident, the Legal, Finance (Spokesperson), and Public Relations units jointly assess whether to initiate law enforcement reporting procedures and disclose material information in accordance with applicable regulations. This ensures the timeliness and compliance of external disclosure.

 

Meanwhile, we continue to strengthen internal information security awareness and reporting discipline. If employees detect abnormal computer behavior or encrypted files, they are required to immediately disconnect from the network, shut down the computer, change passwords, and report the incident to the Helpdesk for assistance.

If ransomware messages are received, employees must immediately report the incident to MIS and are strictly prohibited from clicking any attachments or links, thereby preventing further spread of damage.

Information Security Incident Notification Process

 
In 2025, Chicony experienced one serious information security incident, primarily caused by external hackers. After the incident, the Company conducted a comprehensive review, analyzed the root cause, and implemented an improvement plan to strengthen future protection capabilities.
A

Response to Material Information Security Incident in 2025

Response to Material Information Security Incident in 2025

Personal Data and Privacy Protection

Chicony Electronics established the "Personal Data and Privacy Protection Policy" in 2025. The scope of protection covers the personal data of suppliers or customers' personnel, visitors (including website visitors), investors, contracting and litigation parties, job applicants, and users of products or services (collectively referred to as "Data Subjects"). Following the completion of the policy in 2025, education and training sessions were conducted based on its contents. A total of 189 employees received the training, with cumulative training hours reaching 94.5 hours.

Explore More
Ready for new challenges? Join our forward-thinking team to grow with us and realize your full potential.

數字驗證

請由小到大,依序點擊數字

Stakeholder Questionnaire Report Download

We use cookies to ensure our website's proper function, personalize content and ads, provide social media features, and analyze our traffic. We also share information about your use of our site with our social media, advertising, and analytics partners.

Manage Cookies

Privacy Preference Center

We use cookies to ensure our website's proper function, personalize content and ads, provide social media features, and analyze our traffic. We also share information about your use of our site with our social media, advertising, and analytics partners.

Manage Consent Settings

Necessary Cookies

Enable all by default

These cookies are strictly necessary for the website to function and cannot be turned off. They are typically set only in response to your actions, such as setting privacy preferences, logging in, or submitting forms. While you can block these cookies in your browser, certain website features may become unavailable.