ESG

Sustainable Governance

Information Security




The information technology dissemination model changes with each passing day. If information security vulnerabilities are exploited by hackers and causes customer information to be leaked, it will further affect customers' trust or loyalty to the Company, or cause the Company to be fined or face other legal consequences for violating relevant laws and regulations. All of these situations might affect the Company's external image and reputation. Information security risk management and taking appropriate measures can effectively reduce the Company's potential financial losses and legal risks. It will also protect the Company's reputation and avoid potential negative impacts, creating a positive effect on protecting the economy, society and business partners, as well as the rights and interests of the Company and customers.

Therefore, Brogent continues to improve information security governance and strengthen information security capabilities. All information operations not only comply with international information security standards, but also comply with domestic and overseas laws and regulations on personal data protection and information security. The Company's information security unit is the Intelligent Systems Center, and dedicated information security personnel are appointed in accordance with the "Information Security Management Guidelines for TWSE/TPEx-listed Companies." The Intelligent Systems Center is responsible for formulating the Company's Information Security Policy, planning information security measures, and carrying out information security-related operations to ensure proper protection of the Company's confidential information, trade secrets, and personal data.

Brogent attaches great importance to AI governance and has established an AI risk assessment process to ensure that AI applications meet information security and operational risk management requirements. If employees need to use AI tools, they must submit an internal electronic application form specifying the purpose and scope of use. The Intelligent System Center conducts information security risk assessments (including data security, system access, and software source security) to ensure that AI tools undergo risk control before adoption, reducing potential information security threats while maintaining comprehensive review and tracking mechanisms. In addition, the "AI Technology Usage Guidelines" have been established and promoted through annual information security training courses. The Company will evaluate the formulation of the "AI Use Management Regulations" in the future to incorporate AI governance mechanisms into documented information security management systems, further improving the maturity of AI governance and corporate risk control capabilities.

▍Information Security Policies
Brogent's information security management goals are developed to ensure the Confidentiality, Integrity, Availability, and Compliance of its core business systems. The Company identifies and assesses qualitative or quantitative risks based on the criticality of the assets. Through appropriate control measures and continuous review mechanisms, the Company verifies the effectiveness of information security management implementation and ensures the achievement of established goals.



▍Information Security Management Structure
To reduce the probability of information security threats and their impact, and to improve the Company's business continuity, Brogent has established an Information Security Committee, with the President serving as the chairperson. The Committee convenes regular meetings each year to review information security strategies, goals, and implementation results to strengthen information security governance and supervision mechanisms. The Company's responsible unit for information security is the Intelligent Systems Center, and the Chief Information Security Officer (held by the head of the Intelligent Systems Center) is responsible for formulating information security policies, planning related protection measures, and promoting and ensuring the execution of information security operations. In addition, in line with the spirit of ISO 27001 Information Security Management System, the Company adopts a PDCA (Plan–Do–Check–Act) continuous improvement cycle to continuously enhance its information security management system and ensure the achievement of its information security management goals.

In 2025, the Information Security Committee consisted of 14 members and convened 1 information security meeting during the fiscal year. The Committee reviewed information security strategies, risk assessment results, and improvement plans to reinforce governance mechanisms. To continue to invest resources to improve information security management, Brogent invested approximately NT$11.57 million in information security, mainly for the deployment of information security protection equipment, system maintenance, vulnerability scanning, information security education and training, and external professional consulting services. In addition, the Intelligent Systems Center organizes information security drills from time to time every year and continues to promote information security training and advocacy campaigns to enhance employees' information security risk awareness and response abilities. The implementation status of information security management was reported to the Board of Directors on December 31, 2025.



▍Information Security Identification Process
Brogent has established a systematic information security risk assessment process to incorporate information security risks into the overall risk management framework, and continues to conduct rolling reviews and improve control measures.



▍Information Security Measures
The Company incorporates information security risks into its overall risk management plan and includes information security risk assessment, risk control, risk monitoring, and risk response measures in the risk management process to ensure effective information security risk management. At the same time, the Company strengthens employees' information security awareness and training so that employees can identify and respond to various types of information security threats and risks, including how to identify phishing emails, process personal information, and create establish strong passwords.

To strengthen network and information security protection mechanisms, the Company regularly engages professional third-party information security service providers to perform vulnerability scans and information security health checks. The Company conducts one outsourced vulnerability scanning service annually (including an initial scan and a follow-up rescan) to perform vulnerability scanning and information security checking for the Company's external-facing service hosts, internal key servers, and important information systems. The Company also conducts vulnerability detection and risk assessment for operating systems, applications, and network equipment to identify potential information security vulnerabilities and exposure. Upon completion of the scan, the external professional institution issues an assessment report with improvement recommendations classified by risk level (High, Medium, Low). The Company convenes vulnerability patching meetings based on the report findings, sets improvement timelines, and tracks patching progress to ensure that high-risk vulnerabilities are addressed with priority. Relevant implementation results and improvements are regularly submitted to the Information Security Committee for reporting and review to strengthen the supervision and continuous improvement mechanisms of the governance body. In 2025, the Company convened 19 internal CVE vulnerability patching meetings to accelerate bug fixes and risk control efforts.

Additionally, the Company conducted periodic disaster recovery drills to ensure rapid response and recovery when information security incidents occur. Through systematic resource allocation and strengthened risk management capabilities, the Company continues to enhance its overall information security protection level and operational resilience.

▍Improve Information Security Prevention Awareness
Brogent plans information security drills and protection promotion plans every year. During regular meetings of the Information Security Committee, the results of the drills are reviewed and followed up for improvement. Employees identified as exhibiting medium- to high-risk behaviors during phishing simulation drills are required to undergo strengthened training and risk identification guidance to reduce the risk of recurrence. All new employees receive orientation on information security policies. Additionally, the Company conducts annual organization-wide information security awareness training. Referencing the testing standards of the telecommunications industry, the Company designs information security protection awareness tests that meet the Company's business model, operating environment, and corporate culture to verify training effectiveness. In 2025, the training examination achieved a 100% pass rate.



 
*

▍Customer Privacy

Brogent holds internal training courses to enhance employee awareness on protecting customer privacy and confidential information, and only use and protect customer information based on the contract signed with customers. Our Legal Department reviews contract content and the scope of information disclosed in each contract before marketing and disclosing customer information to the public, and legal advice will be provided to the marketing team on information disclosures. When customers discover that private or confidential information has been leaked, they can file a complaint or report through Brogent's official website (https://www.brogent.com/en/contact-us.html). No customer complaints of violating customer privacy or leakage of confidential information were received in 2025.

▍Personal Data Protection
Brogent has established the "Personal Data Protection and Management Rules" in accordance with the "Personal Data Protection Act". All employees are required to collect, process, and use personal data in compliance with these rules. In addition, the Company has established a "Personal Data Protection Management Implementation Team" (hereinafter referred to as the "PD Team"). The Legal & IP Dept. serves as the coordinating unit, the Intelligent Systems Center acts as the information security unit, and the Audit Office serves as the audit unit. The PD Team is composed of representatives from each center/department and regularly reviews whether the Company's collection, processing, and use of personal data comply with the "Personal Data Protection and Management Rules". Personal data that no longer has a retention necessity is destroyed on a regular annual basis.