Information Security & Digital Resilience



01 Information Security Governance

SynPower focuses its information security management on the protection of information assets, regulatory compliance, cybersecurity awareness, and business continuity. Through clearly defined cybersecurity governance structures and responsibilities, the Company continues to strengthen information security governance and digital operational resilience.

01

Protect Information Assets

Reduce the risks of unauthorized access, unauthorized modification, and information leakage.

02

Regulatory Compliance

Continuously review information security management systems in accordance with applicable laws, regulations, and cybersecurity requirements.

03

Strengthen Cybersecurity Awareness

Enhance cybersecurity awareness across the organization through communication, training, and exercises.

04

Maintain Business Continuity

Reduce operational disruption risks through backup and recovery mechanisms.

05

Maintain Service Reliability

Support customer and operational requirements through a stable and secure information environment.

Information Security Role Responsibilities
Convener Served by the Chief Information Security Officer, who oversees the promotion and implementation of information security policies and reports cybersecurity status to the Board of Directors.
Information Security Manager Responsible for information security implementation and incident handling and for ensuring compliance with internal and external information security requirements.
Information Security Audit Function Conducts information security audits to verify that the Company's information security management practices comply with relevant requirements.
Information Security Promotion Function Business unit managers support the promotion and implementation of the Company's information security policies within their respective functions.
Information Security Management and Documentation Function Responsible for day-to-day information security management, record maintenance, and information security document control.

02 Information Security Management Mechanisms

The Company has established information security controls covering account privileges, system vulnerabilities, networks and endpoints, backup and recovery, incident management, auditing, and physical data center security.

01

Account and Access Management

Information system access privileges are managed according to job requirements to reduce unauthorized access risks.

02

System and Vulnerability Management

The Company continuously reviews vulnerabilities in information systems and equipment and tracks corrective actions for identified issues.

03

Network and Endpoint Protection

Information security controls and monitoring measures are used to strengthen protection for networks and endpoint devices.

04

Backup and Recovery

Backup procedures and data recovery exercises are conducted to strengthen recovery capabilities in the event of system abnormalities or disruptions.

05

Incident Management

Information security incident response and notification mechanisms are established to reduce the potential operational impact of cybersecurity incidents.

06

Audit and Continuous Improvement

Internal and external audits, together with corrective-action tracking, are used to continuously review the effectiveness of information security management.

07

Physical Data Center Security

Data center facilities are protected through 24-hour access control and video surveillance, with relevant records retained for periodic internal and external audits.

03 Cybersecurity Risks and Protection Measures

In 2025, the Company continued to strengthen its multi-layered cybersecurity protection through system and equipment upgrades, threat monitoring, risk assessment, disaster recovery, and external IT audits.

01

System and Equipment Upgrades

Core network equipment was upgraded to strengthen firewall performance, while vulnerability scanning and remediation were conducted for 30 core servers.

02

Monitoring and Threat Intelligence

Core business systems continued to use Managed Detection and Response (MDR) protection. The Company also maintained its TWCERT/CC membership and participated in cybersecurity threat intelligence sharing.

03

Risk Assessment and Disaster Recovery

Annual information security risk assessments were conducted with reference to the ISO 27001 management framework, together with off-site backup restoration exercises to verify recovery effectiveness.

04

External IT Audit

The Company cooperated with its accounting firm in conducting an information systems audit. No material deficiencies were identified in 2025.

04 Cybersecurity Education and Awareness

The Company continues to enhance employees' information security awareness through cybersecurity communications, training, and social engineering simulations.

2025

Cybersecurity Awareness Communications

6 sessions

2025

Social Engineering Training

1 session

2025

Social Engineering Simulation Exercises

3 exercises

05 Annual Information Security Performance

The Company reviews the effectiveness of its information security governance and implementation through material cybersecurity incident indicators and quantitative information on annual management mechanisms.

2025 Information Security Performance 0 Material Cybersecurity Incidents

No material cybersecurity incidents or material operational losses caused by information security incidents occurred in 2025.

Information Security Management Resources

Management Mechanism

Internal Information Security Audit

At least once annually

Governance Mechanism

Board Cybersecurity Report

At least once annually

Protection Scope

Core Server Vulnerability Scanning

30 servers

2024 Information Security Performance
  • Completed the deployment of a Managed Detection and Response (MDR) system for core business servers, strengthening real-time monitoring and threat response capabilities.
  • Conducted three social engineering simulation tests during the year, with an internal target of maintaining the click-through rate below 5%.
  • Dedicated information security personnel obtained ISO 27001 Information Security Management System Lead Auditor qualifications.
  • Continued operating off-site backup mechanisms and conducted annual disaster recovery exercises to verify the effectiveness of data recovery procedures.