Risk management & Cyber Security

Cyber Security

Cyber Security

In order to reinforce information security management and improve the overall information services to ensure the consistency of information and business needs and effectively manage information security tasks, we have formulated the “Cyber Security Risk Management Framework” in accordance with ISO 27001, which covers cybersecurity policies and specific management solutions.

  

The Company aims to build a strict and effective information security defense. According to the cyber security risk management framework, the Information Security Management Committee has established an information security task force, an emergency response task force, and an audit task force. The Information Security Management Committee coordinates the formulation, implementation, risk management, regulatory compliance and auditing of information security and related policies. The audit supervisor supervises the implementation of information security operations and evaluates the effectiveness of the information security risk management measures of the entire corporate group, and regularly reports to the board on the effectiveness of the operations and systems of the overall information security management organization. In order to effectively promote the Cyber security policy, the Company has appointed a chief information security officer (CISO) and established a dedicated information security unit that has a supervisor and at least two specialists responsible for cyber security-related monitoring and the implementation of various management plans formulated by the Information Security Management Committee. Information security education and training sessions are carried out for all employees regularly. Personnel working in the information security dedicated units need to receive at least 16 hours of specialized information security training.

  

2023 Implementation Status of Cyber security

  1. Total held 5 internal review meetings of this year, and report to the Board of Directors the current implementation statue on November 8, 2023.
  2. Conducted three sessions of information security education and training, including topics such as「Introduction to social engineering attack techniques and email security education and training I & II」,「information security precautions and e-mail security」. All new employees must complete information security education and training courses, with 3,288 managers and employees participating in the sessions.
  3. Improve the security of employees’ access to the e-mail system. Conduct e-mail social engineering drills once. All employees of the Group participated in the drills.
  4. Announced at least five internal information security announcements to convey important regulations and precautions for information security protection.
  5. Audited the implementation of cyber security system by audit department and there is no significant deficiency be found. The information security management is still effective execution. The information security management is still effective execution.
  6. No losses were suffered from major Cyber security incidents.
We value your privacy
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing and performance efforts.
Accept All Cookies
Manage Preferences
We value your privacy

UPC and certain third parties use cookies on www.upc.com. The details regarding the types of cookies, their purpose and the third parties involved are described below and in our Cookie Policy . Please click on “Allow All” to consent to our usage of cookies in order to have the best possible experience on our websites. You can also set your preferences or reject cookies (except for essential cookies).
Allow All
Manage Consent Preferences
  • Essential cookies
    Always Active
    These cookies are essential in order to enable you to move around the website and use its features, such as setting your privacy preferences, logging in or filling in forms. Without these cookies, services requested through usage of our website cannot be properly provided. Essential cookies do not require consent from the user under applicable law. You may configure your web browser to block strictly necessary cookies, but you might then not be able to use the website’s functionalities as intended.
  • Analytics cookies
    These cookies collect information about how visitors use a website, for instance which pages visitors go to most often, and how visitors move around the site. They help us to improve the user friendliness of a website and therefore enhance the user's experience.
Confirm my Choices