| Highlights and Key Achievements

Digital Trust

In the Digital Trust chapter, the Highlights and Key Achievements outlines the concrete results of Tatung System Technologies Inc.'s (tsti) multi-layered approach to information security and privacy protectio.

These achievements are not isolated milestones; they represent the culmination of a multi-year evolutionary framework designed to embed a corporate security culture of "Proactive Defense and Immediate Response" across all operation.

1. Core 2025 Quantitative and Qualitative Milestones

tsti's operational highlights for 2025 showcase robust technical defense and strict compliance outcomes:

  • Zero-Breach Excellence: For the reporting year, tsti achieved zero confirmed data breach incidents and received zero complaints regarding the infringement of customer privacy or the loss of customer dat.
  • Rapid Automated Incident Defense: Through its Security Operations Center (SOC) and endpoint protection systems, the company successfully detected and mitigated 2,729 Tier-1 and Tier-2 cybersecurity early-warning events (such as malware probes and anomalous connection attempts. Using high-efficiency monitoring, all events were contained and resolved within 0.5 hours, preventing operational disruptio.No events activated crisis management or required reporting to authoritie.
  • Certification Milestones: tsti passed the ISO/IEC 27001:2022 continuous audit on its first attempt and maintained its ISO/IEC 27701:2019 international privacy certificatio.
  • External Audit Responsiveness: The company successfully responded to 28 external cybersecurity audits and inquiry requests from government bodies, customers, and supply chain partners, providing complete supporting evidence regarding its security and ESG compliance maturit.
  • Escalating Financial Commitment: Reflecting the growing complexity of threats, tsti increased its cybersecurity-invested expenses to 4,152 (thousand NTD) in 2025, up from 3,067 in 2024 and 2,290 in 2023.

2. Strengthening Security Awareness and Professional Skills

A major element of tsti's digital trust strategy is fostering an active, educated "all-employee defense line":

  • Expanded Awareness Campaigns: In 2025, the company conducted 22 cybersecurity awareness campaigns, reaching a cumulative 11,000 participant attendee-times. To address rising threats, tsti doubled the campaign frequency from once to twice a month starting in October 2025.
  • Structured Training Hours: A total of 1,429 participants completed specialized security education, accumulating 1,715 cumulative training hours.
  • Featured Educational Courses: On September 23, 2025, the Head of Legal Affairs and the Head of Cyber Security co-lectured the "2025 Personal Data & Information Security Awareness Course" to over 200 enrollees, focusing on real-world response experiences and compliance roadmaps.
  • Advanced Professional Credentials: tsti fortified its internal technical expertise; its cybersecurity manager completed CISSP professional training, while other technical personnel completed CEH offensive and defensive training.

3. The Larger Context: The 2025 Digital Trust Framework

These accomplishments are supported by a broader structural and technological governance framework that has evolved over several years:

  • Governance Evolution: The oversight structure transitioned from the "Information Security Steering Committee" in 2019 to the "Cybersecurity and Privacy Protection Committee" in 2021. In 2023, it was upgraded to the Cybersecurity and Privacy Management Task Force to separate its functions from board-level committees and drive executive execution. In 2025, this task force held 4 regular working meetings and presented its annual report to the Board of Directors.
  • Unified Standard Framework: tsti systematically integrated its ISO/IEC 27001 (ISMS) and ISO/IEC 27701 (PIMS) management systems into a single integrated framework to optimize operational efficiency and workflow consistency.
  • Zero-Trust and AI-Driven Architecture: The framework relies on Zero Trust Architecture (ZTA)—enforcing Multi-Factor Authentication (MFA) and the Principle of Least Privilege (PoLP)—along with an AI-driven automated threat platform combining EDR/XDR, firewalls, and Security Information and Event Management (SIEM).
  • Cloud and Automation Governance: tsti expanded its cloud governance by deploying Microsoft Purview and optimizing Azure security configurations. It also implemented automated configuration check reports in 2025 to enhance auditing consistency, and introduced the Power Automate platform to convert manual workflows into secure, automated processes.

Please refer to the Sustainability Report [PDF] relevant chapter for more details.