Information Security Management Policy
SynPower has established its information security policy in accordance with the Information Security Control Guidelines for TWSE/TPEx Listed Companies. Authorized by the Board of Directors, the company has established an Information Security Management Team, convened by the Chief Information Security Officer. We are committed to building a stable and trustworthy information security environment to protect the rights and interests of customers and stakeholders.
Zero Major Information Security Incidents in 2025 Through strict controls, SynPower had no major information security incidents in 2025, ensuring stable operations and data integrity.
2025 Information Security Resources and Results
Information Security Awareness Activities
6Times
Fraud prevention and information compliance
Social Engineering Drills
3Times
Annual click-rate target < 5%
Core Vulnerability Remediation
30Servers
Vulnerability patching for major servers
2025 Multi-layer Information Security Protection Results
System and Equipment Upgrades
- February Equipment UpdateCompleted core network equipment upgrades and strengthened firewall performance.
- August Vulnerability ScanPerformed scanning and vulnerability remediation for 30 core servers.
- Core MonitoringIntroduced an MDR managed detection and response system to ensure real-time defense.
Recovery and Risk Assessment
- December Annual AssessmentConducted the annual risk assessment plan in accordance with ISO 27001.
- December Disaster RecoveryConducted an off-site backup restoration drill to verify backup effectiveness.
Personnel Awareness and Audits
- Annual Information Security TrainingConducted 6 information security activities and 3 social engineering drills to strengthen employee awareness.
- July External AuditPassed the information operations audit by an accounting firm with no major deficiencies.
- Information Security AllianceContinues to be a TWCERT/CC member and participates in threat intelligence sharing.
Physical Access Control Management
- 24-hour Monitoring and ControlThe server room maintains 24-hour access control and video monitoring.
- Regular AuditsComplete records are maintained for regular internal and external audits.
Information Security Incident Reporting and Response Levels
| Level | Severity | Definition | Response Time Limit |
|---|---|---|---|
| Level 4 | Critical | Major damage to core systems or leakage of confidential data. | Within 36 hours |
| Level 3 | Major | Important business interruption or leakage of internal restricted-access data. | Within 36 hours |
| Level 2 | Attention | Minor impact on non-core systems. | Within 72 hours |
| Level 1 | Minor | Very low impact and no effect on normal system operations. | Within 72 hours |