2026 / 7
028

/
Sep / 2026

Sustainable Governance

永續治理

Information Security Policy Statement Enhancement: Elevating Transparency, Safeguarding Enterprise Resilience and Investor Trust

Driven by global digital transformation and rapid technological evolution, the cyber threats and information security risks faced by enterprises are increasing at unprecedented speed and complexity. Information security has long transcended mere IT protection, evolving into a core component of corporate governance that dictates whether an enterprise can survive amidst market shifts and maintain superior competitiveness. Contemporary investors and stakeholders, when evaluating long-term corporate value, look beyond traditional financial performance to regard 'Digital Resilience' and 'Cyber Transparency' as crucial indicators of a company's capacity for sustainable operation.

To fulfill our solid commitment to stakeholders, maintain operational continuity, and proactively address market expectations regarding our corporate governance, CTCI has completed the review, revision, and update of its Information Security Policy Statement. We deeply understand that establishing a transparent security defense and management framework capable of withstanding international standard scrutiny serves not only as a firewall protecting intangible assets and trade secrets, but also as a new cornerstone for deepening market trust and guiding the enterprise forward steadily.

This Information Security Policy Statement update comes in response to the transition requirements of the ISO 27001:2022 international standard, while aligning with the expectations of the Dow Jones Best-in-Class Indices (DJ BIC) sustainability assessment regarding cyber governance. Through higher transparency and a more rigorous framework, we ensure that CTCI's information security management continuously aligns with global trends.

1. Enhancing Information Disclosure and Transparency in Response to ISO 27001:2022 Communication Requirements

ISO 27001:2022 explicitly requires enterprises to plan the topics, target audiences, timing, and channels for information security communications. CTCI has reinforced the following mechanisms accordingly:

• Clearer Information Disclosure & Communication Framework: We have established a systematic information security communication system to ensure critical security details are appropriately disclosed, including incident notification workflows, handling principles, policy updates, governance structure overviews, and management performance metrics. This enhances stakeholder visibility into governance quality.

• Defining Internal & External Stakeholders & Responsibilities: Communication scope encompasses investors, clients, business partners, supply chain vendors, regulatory authorities, and internal employees, ensuring all stakeholders receive clear and consistent information promptly.

• Diversified Communication Channels to Enhance Accessibility: Channels include the company website's cybersecurity risk management section, disclosures in annual/sustainability reports, investor conferences, material updates, and internal training platforms. This aligns with international standards and reinforces transparency commitments.


2. Continuously Optimizing Information Security Governance to Elevate Governance Quality

DJ BIC requirements for information security governance increase annually, placing special emphasis on whether enterprises establish clear and public security policies, possess robust governance structures with defined responsibilities, and systematically disclose security management performance.

CTCI's latest Information Security Policy Statement aligns with global pioneers, demonstrating a major shift from 'passive defense' to 'proactive transparent governance.' The key revisions of CTCI's updated Information Security Policy Statement are as follows:

• Ensure information security:Consolidate the ISMS to protect the company's information assets from internal or external threats of being stolen or disclosed, either maliciously or inadvertently, while ensuring monitoring and responding to information security threats. This includes maintaining transparency with affected stakeholders when breaches or threats occur, outlining actions taken to address vulnerabilities and prevent future risks.

• Raise information security awareness among staff:Conduct information security education and training program, keep staff educated to prevent information disclosure that may impact business operations, including establishing individual responsibilities for information security for the entire workforce. All employees shall comply with the company's Information Security Policy Statement and related declarations, follow the Information Security Management Regulations, remain alert to any suspicious activities at all times, understand the Information Security Incident Reporting and Managements Flow Chart, and are responsible for reporting such incidents.

• Persistent improvement of ISMS:Persistent supervision, measurement, evaluation, and analysis of information management activities, integrity and protection of data (This involves maintaining security controls that protect data throughout its lifecycle, including measures to prevent breaches and ensure that only authorized users can modify or access sensitive information), along with continuous improving in information security systems, will ensure the robustness and reliability of the ISMS, thereby improving the effectiveness of the system.

• Compliance with regulatory and contractual requirement:Operating information of all contracted engineering projects, including planning, design, procurement, construction, etc., is secure and compliant with government regulations, company policies and standards, and contractual requirements (establishing information security requirements for third parties, e.g., suppliers). In addition to complying with our company's information security policy Statement and related regulations, the software used by third parties when fulfilling the contract must not violate copyright laws. If illegal software use causes information security risk or act of infringement, the third parties involved shall assume all liabilities. This approach aims to mitigate risks associated with external relationships and safeguard shared infrastructures and data.

3. Strategic Significance of the Policy Update for Investors

• Enhancing Operational Resilience and Security:Enhanced cybersecurity management reduces risks such as operational disruptions and data breaches, effectively safeguarding enterprise value.

• Strengthening Governance Transparency for Sustainability Benchmarks:Transparent governance information enables investors to better understand the company's sustainability indicators and operational stability.

• Boosting Market Confidence and Long-Term Investment Value:In global markets, cybersecurity is a vital dimension for evaluating corporate performance. CTCI's alignment with international standards and ESG benchmarks boosts investor confidence and valuation.

4. Future Outlook

Information security is the bedrock of steady corporate operations. CTCI reinforces its cybersecurity management with a prudent and responsible posture, safeguarding operational resilience and delivering on its commitments to investors. Looking ahead, CTCI will continuously refine its security policies and practices—not only complying with relevant laws and global standards, but also framing cybersecurity as an essential strategic cornerstone for driving Environmental, Social, and Governance (ESG) sustainability. As global supply chains become increasingly interconnected, cybersecurity has become vital for maintaining operational stability and supply chain resilience. By implementing ISO 27001:2022 standards and connecting with international sustainability trends, CTCI continuously elevates its defense and resilience, translating risk management capabilities into a key driver of sustainable corporate growth.

**Photo credit: Pixabay
print