
Hanmi Science operates an Information Security Committee for systematic and effective information protection activities. The CEO is designated as the Chairperson of the Information Security Committee, reviewing and deciding on major agenda items related to information security and personal information protection. When important issues arise, Information Security Committee meetings are held weekly. As cases of cyber terrorism, personal information leakage, and hacking targeting pharmaceutical and bio-companies have continuously increased recently, the Information Security Committee is actively implementing a systematic and independent information protection management system to proactively respond to these threats. In particular, to respond swiftly to information security breaches, a reporting system and disciplinary regulations for violations have been established. By reviewing and determining response measures and punishment levels according to the severity of the violation, the committee systematically addresses infringement incidents. Furthermore, in preparation for increasing cyber threats, regular simulated hacking and vulnerability assessments are continuously performed, thereby identifying potential security vulnerabilities that may occur during information system and personal information processing in advance and implementing corrective actions. The inspection results are shared with relevant departments to establish recurrence prevention measures and continuously enhance the level of information protection. To date, there have been no personal information leakage incidents or security breaches, and continuous management and improvement efforts will be made to prevent future security incidents. To effectively carry out information security and personal information protection activities, the company maintains close cooperative relationships with external expert groups to secure specialized information and capabilities, including information security threat trends and related control measures. Additionally, an Information Security Steering Committee is operated to review and decide on matters concerning the planning, execution, evaluation, and improvement of (personal) information protection tasks. Members of the Information Security Committee, including the CISO, enhance mutual communication and cooperation through weekly security meetings. Regular training will also be conducted to strengthen the expertise of the responsible executives in the future.
Information Security Committee

Personal Information Protection Operating Organization

Category | Operating Frequency | Roles |
|---|---|---|
Information Security Committee | Weekly | ㆍ Review and decision on major agenda items related to information security |
Personal Information Protection Committee | Monthly | ㆍ Review of personal information-related matters |
Category | Roles and Responsibilities |
CEO | ㆍChairperson of the Information Security Committee |
CISO (Chief Information Security Officer) | ㆍInformation security strategy establishment, risk management, cyberattack response, and organizational asset protection |
CPO (Chief Privacy Officer) | ㆍEstablishment of personal information protection policies, oversight of regulatory compliance, and ensuring |
Personal Information Handlers | ㆍExecutives of departments handling personal information |
Personal Information Protection Officer | ㆍPersonal information protection |
Technical Security Management Officer | ㆍTechnical Personal Information Protection |
Physical Security Officers | ㆍManagement of Access, CCTV, etc. |
Departmental Personal Information Officers | ㆍExecutives of Personal Information Departments |
Personal Information Protection Contractors | ㆍOperation of Personal Information Processing Systems or Task Outsourcing |
Based on the results of the IRO analysis, Hanmi Science is identifying key risks and opportunities related to information security, including personal information protection, that could significantly impact stakeholders and sustainability, and is continuously striving to develop effective response measures.
RISK | |
|---|---|
Business operational disruption due to security incidents such as customer information leaks or system unavailability | |
Characteristics of Impact | Potential Impact |
Affected Stakeholders | Customers, employees, shareholders, and investors |
Severity of Impact | Scale ■■■■□ Scope ■■■■□ Recoverability ■■■□□ |
Expected Financial Impact | Likelihood ■■■□□ Magnitude ■■■□□ |
Impact on the Company | ㆍImposition of administrative fines or penalties due to violation of the Personal Information Protection Act |
Company's Response | ㆍEstablishment of international standard information security management system |
OPPORTUNITY | |
|---|---|
Enhancing safety through strengthened information security and personal information protection policies and management system certification | |
Characteristics of Impact | Actual Impact |
Affected Stakeholders | Customers |
Severity of Impact | Magnitude ■■■■□ Scope ■■■□□ |
Expected Financial Impact | Likelihood ■■■□□ Magnitude ■■■□□ |
Impact on the Company | ㆍImproved customer trust through minimizing legal risks |
Hanmi Science, based on the management's firm commitment to information protection, completely enacted and revised 5 types of information security regulations and 8 types of guidelines in 2025 to ensure the confidentiality, integrity, and availability of all data generated and processed by the company. In particular, as the company-wide work environment transitioned to Microsoft 365 (M365), we reorganized the overall information protection standards, including access control, account management, data protection, and log management, to align with the M365 environment, reflecting the characteristics of the cloud environment and collaboration systems. All information protection related documents, including these information protection regulations and guidelines, personal information processing policy, and internal personal information management plan, are established and operated reflecting revisions to the Personal Information Protection Act and internal operational status, and are kept up-to-date through periodic reviews and revisions in accordance with changes in relevant laws and regulations and the environment. In addition, Hanmi Science continuously updates its personal information processing policy whenever there are changes to the Personal Information Protection Act or issues requiring changes within the policy, and makes it public through the main website so that employees and data subjects can easily check it. Hanmi Science's personal information processing policy and the Information Protection Declaration, which confirms the management's commitment to information protection, can be found via the link above.
Hanmi Science carries out various activities, including thorough pre- and post-measures, for personal information protection. In preparation for potential customer personal information leaks, we establish relevant regulations and guidelines, set up a system for rapid response in case of an incident, and also subscribe to personal information protection liability insurance to prepare for additional risks. Furthermore, in the event of a personal information leakage incident, we have prepared a personal information leakage response manual to prevent further damage and ensure rapid recovery. According to this manual, upon an incident, we immediately identify the cause, take measures to prevent further leakage, notify affected parties, and report to relevant authorities. In particular, the Personal Information Protection Officer reports the incident to the CEO, forms a rapid response team for personal information leakage to systematically address it, and also prepares relief measures for victims and recurrence prevention strategies. In conjunction, we collaborate with the Personal Information Protection Commission to deliberate and determine response measures and punishment levels according to the severity of the incident, and implement regular security training and internal management plans to prevent security breaches. Moreover, major service platforms that process customer personal information and provide payment functions are regularly checked through mock hacking, and any vulnerabilities identified are immediately addressed to improve weak points. Furthermore, all websites publicly launched by Hanmi Science undergo a pre-launch security review process, conduct mock hacking, address 100% of all discovered vulnerabilities, complete implementation verification, and finally operate under a system approved by the CISO before launch.

Hanmi Group conducted personal information protection awareness-raising education for all employees, reflecting the revised Personal Information Protection Act of 2025. In particular, it was developed with a practical focus to enable employees who handle personal information to learn more carefully.
The training content was structured around common mistakes during personal information processing and frequent violations during personal information collection, and realistically guided on how to respond quickly and appropriately when personal information leakage occurs. Furthermore, to prevent indiscriminate processing when entrusting or sharing personal information, personal information handlers were educated to clearly recognize their legal and ethical responsibilities and to thoroughly comply with safe processing procedures.
This supported employees in establishing a safe personal information management culture and preventing legal risks. Hanmi Pharmaceutical plans to continuously expand customized training to strengthen practical capabilities related to personal information protection in the future.

Hanmi Science conducts various participatory campaigns to strengthen employees' information protection awareness and create a secure work environment. In particular, in 2025, we conducted a password prevention campaign to prevent Credential Stuffing attacks, guiding employees to practice safe password management habits. Additionally, we operated quiz-format content to allow employees to naturally check personal information and information protection regulations frequently encountered in their work, providing an opportunity for them to directly read and understand the regulations. This campaign was structured around actual security incident cases and prevention methods, raising employees' awareness and supporting them in naturally applying security rules in their daily work. Furthermore, during periods when security incidents are more likely, such as vacation seasons or holidays, we produce and distribute posters containing practical information protection rules, including precautions for external access, device loss prevention, and personal information handling guidelines, to help employees recognize security once again in their daily lives. Hanmi Science plans to continuously develop an employee participation-centered information protection culture in the future.
2025 Information Security Campaign | |
|---|---|
Proactive Blocking of Unauthorized External AI Services Guidance | Personal Information Protection Day Password Change Campaign Conducted |
Security Precautions Guidance Regarding Telecommunications | Company-wide Personal Information Protection Education Implemented |
Security Guidance Regarding MS SharePoint Hacking Incident | Information Protection Day Quiz Event Campaign |
Windows 11 Upgrade Implementation Guidance | Phishing Mail Response Simulation Training Conducted |
Implementation of Storage Media Security Measures (Degaussing) | Production and Distribution of Information Leakage Prevention Posters |
![]() Personal Information Protection Day Password Change Campaign | ![]() Information Leakage Prevention Poster | ![]() Information Leakage Prevention Poster |
|---|
Risk and Opportunity | Period | Target Audience | Method | Oversight |
|---|---|---|---|---|
Prevention of Personal | Ad-hoc | Employees | · Operating employee security awareness education and campaigns to | Information |
Prevention of Information Leakage by Departing | Employees Scheduled | · Account deactivation immediately upon resignation submission | ||
Increased hacking | Personal information | · Enhanced continuous monitoring due to numerous hacking incidents at | ||
After M365 | Employees | · Phased implementation of M365 security features based on Entra ID | ||
Changes in | Company-wide | · Monitoring of changes in laws and regulations |
Key Indicators | 2025 Target | 2025 Achievements | Achievement | 2026 Goals | Mid-to-Long-Term Plan |
International Standard | - | - | - | ISO 27001 Certification | ISO 27001 Ongoing |
Information security | Information security employee awareness enhancement | Improvement in employees' information protection awareness maturity | Achieved | Personal information protection | Designing information security training |
(Personal) | No personal information | No personal information leakage or 0 security | Achieved | No personal information leakage or | No personal information leakage or achievement |