Information Security Risk Management Framework
Based on the concerns of internal and external stakeholders, Kinsus has established the “Information Security Management System” in accordance with international standards and legal requirements related to information security management operations and personal data protection. This system ensures that the company’s information and communication infrastructure and information systems comply with requirements for confidentiality, integrity, availability, and legality. Through the continuous improvement cycle of the PDCA (Plan-Do-Check-Act) management model, the Company integrates and strengthens its information security management system. The implementation of information security management in 2025 was reported to the Board of Directors by the convener of the management committee on December 22, 2025.
Information Security Management Overall Policy
The CEO of the Company has appointed an Information Security Management Representative to establish an internal Information Security Management Committee. This committee is responsible for formulating the Company’s information security management policies and establishing dedicated units, managers, and personnel for information security. They plan and implement information security operations within the Company.The CEO of the Company has appointed an Information Security Management Representative to establish an internal Information Security Management Committee. This committee is responsible for formulating the Company’s information security management policies and establishing dedicated units, managers, and personnel for information security. They plan and implement information security operations within the Company.

Figure 1. Information Security Management Committee
Kinsus's information security management policy is to "provide a reliable information security management operating environment to ensure the continuous normal operation of the Company’s business and achieve the Company's information security management goals."After review and approval by the CEO, it will be released for implementation.
I. Purpose
(1) Implement the Company’s information security management policy.
(2) Implement information security management system.
(3) Improve the quality of the Company’s information security management.
(4) Strengthen the Company’s information security management response capabilities.
(5) Achieve the measurement indicators of information security management policy.
II. Scope of Application
- Shih-Lei Factory (headquarters)Shih-Lei Factory (headquarters)
- Tsing-Hua Factory
- Xing-Feng Factory
- Youth FactoryYouth Factory
III. Goal
The information security management objective of Kinsus is to "ensure the confidentiality, integrity, and availability of organizational business-related information and communication systems and provide continuous and reliable services." To ensure the effective implementation of the Company's information security management system and meet the operational needs of the Company, all operational processes should be regularly reviewed, assessed, and adjusted based on the Company's information security management objectives
Information Security Management Effectiveness
1. Optimize information security policies and optimize information security operation specifications.
2. Information security policy / regulation of promotion and education and training.
1. The Information Security Management System (ISMS) Regulations was formally implemented and certified with ISO 27001 Information Security Management System Certification.
2. Continuous optimization of the ISO 27001 ISMS, including enhanced controls for cloud service security and configuration management, and other areas.
3. Ongoing information security training for new recruits, with awareness campaigns delivered via the EIP portal and screen savers.
4. Social engineering drills were conducted to strengthen employees’ awareness of cybersecurity threats.
1. Passed the annual surveillance audit for ISO 27001 certification.
2. More than 1,300 new employees completed information security awareness campaign as part of new employee orientation.
3. Completed 20,500 instances of information security awareness campaign, with no disciplinary cases resulting from violations.
4. Conducted two social engineering drills, with a total of 6,312 participations.
1. Make sure the network runs smoothly.
2. Prevent hacker invasion and damage.
1. A multi-layered defense and monitoring system was established. Strategies for managing network protection equipment continue to be refined, along with streamlined control procedures.
2. Strengthen information security protection for the supplier collaboration platform.2. Strengthen information security protection for the supplier collaboration platform.
Strengthen wireless network access security.
4. Strengthen data leakage prevention for AI applications.
1. The Intrusion Prevention System blocked the external intrusion threat, and the effective block and defensing rate reached 100%.
2. The number of interruptions of production units due to security threat was 0.2. The number of interruptions of production units due to security threat was 0.
3. Number of vendor information security violations: 0.
4. The information security incident like system intrusion was 0.
1. Reduce the risk of external security mail into colleague’s mailbox.
2. Protect company intellectual property and sensitive data from leakage.
1. An advanced email defense system was introduced.
2. AI technologies were deployed for outbound email audit management.
3. Outbound email screening mechanisms continue to be optimized.
4. The AI-based screening model was enhanced to improve accuracy and efficiency.
1. An average of 231 phishing emails were automatically blocked per month.
2. Zero information security incidents caused by high-risk emails.
3. Zero material violation incidents.
1. Protect the Company’s internal information equipment from virus attacks or malicious intrusion.
2. Protect the Company’s sensitive information.
1. Antivirus software has been installed on endpoint devices (PCs/laptops and machine controllers).
2. A watermark feature was implemented on NB/PC display content to enable traceability in case of data leakage.
3. Host system security was reinforced by upgrading critical system hosts with Managed Detection and Response (MDR) capabilities.
4. Vulnerability scans were conducted, and identified weaknesses are being continuously addressed.
1. Endpoint protection software installation rate for PCs/NBs: 100%; installation rate for information service hosts: 100%.
2. No virus infection or intrusion cases on IT/OA equipment; continued quarterly improvement for machine virus events: 0 per quarter.
3. Login access privileges for information system hosts and network management devices were brought under centralized management. No exception account login incidents or ransomware encryption incidents occurred.
4. Two vulnerability assessments were conducted, with remediation implemented as planned.
1. Protect the Company’s internal information equipment from virus attacks or malicious intrusion.
2. Protect the Company’s sensitive information.
1. Antivirus software has been installed on endpoint devices (PCs/laptops and machine controllers).
2. A watermark feature was implemented on NB/PC display content to enable traceability in case of data leakage.
3. Host system security was reinforced by upgrading critical system hosts with Managed Detection and Response (MDR) capabilities.
4. Vulnerability scans were conducted, and identified weaknesses are being continuously addressed.
1. Endpoint protection software installation rate for PCs/NBs: 100%; installation rate for information service hosts: 100%.
2. No virus infection or intrusion cases on IT/OA equipment; continued quarterly improvement for machine virus events: 0 per quarter.
3. Login access privileges for information system hosts and network management devices were brought under centralized management. No exception account login incidents or ransomware encryption incidents occurred.
4. Two vulnerability assessments were conducted, with remediation implemented as planned.
1. Integrity and compliance of data backup.
2. System backup and aid startup capability.
1. A cloud-based backup system was implemented to improve response capability in the event of anomalies.
2. DR system and data recovery drills were carried out to enhance switchover efficiency and reduce activation time during emergencies.
3. Established an automatic failover mechanism for network connections between cloud and on-premises environments.
1. Conducted disaster recovery drills for five critical service processes (data center infrastructure services, identity authentication systems, customer service systems, email systems, and privileged account management systems), with results meeting expectations.1. Conducted disaster recovery drills for five critical service processes (data center infrastructure services, identity authentication systems, customer service systems, email systems, and privileged account management systems), with results meeting expectations.
2. Achieved 100% availability for cloud-to-on-premises network connections, with automatic failover to backup connections, ensuring no disruption to business operations.