original hero image
Material Issue 4
Information Security, Including Personal Information Protection

Information Security, Including Personal Information Protection


Ⅰ. Corporate Governance

Decision-Making Structure

Hanmi Science operates an Information Security Committee for systematic and effective information protection activities. The CEO is designated as the Chairperson of the Information Security Committee, reviewing and deciding on major agenda items related to information security and personal information protection. When important issues arise, Information Security Committee meetings are held weekly. As cases of cyber terrorism, personal information leakage, and hacking targeting pharmaceutical and bio-companies have continuously increased recently, the Information Security Committee is actively implementing a systematic and independent information protection management system to proactively respond to these threats. In particular, to respond swiftly to information security breaches, a reporting system and disciplinary regulations for violations have been established. By reviewing and determining response measures and punishment levels according to the severity of the violation, the committee systematically addresses infringement incidents. Furthermore, in preparation for increasing cyber threats, regular simulated hacking and vulnerability assessments are continuously performed, thereby identifying potential security vulnerabilities that may occur during information system and personal information processing in advance and implementing corrective actions. The inspection results are shared with relevant departments to establish recurrence prevention measures and continuously enhance the level of information protection. To date, there have been no personal information leakage incidents or security breaches, and continuous management and improvement efforts will be made to prevent future security incidents. To effectively carry out information security and personal information protection activities, the company maintains close cooperative relationships with external expert groups to secure specialized information and capabilities, including information security threat trends and related control measures. Additionally, an Information Security Steering Committee is operated to review and decide on matters concerning the planning, execution, evaluation, and improvement of (personal) information protection tasks. Members of the Information Security Committee, including the CISO, enhance mutual communication and cooperation through weekly security meetings. Regular training will also be conducted to strengthen the expertise of the responsible executives in the future.

Information Security Committee

Personal Information Protection Operating Organization

Operating Method

Category

Operating Frequency

Roles

Information Security Committee

Weekly

ㆍ Review and decision on major agenda items related to information security

Personal Information Protection Committee

Monthly

ㆍ Review of personal information-related matters

Roles and Responsibilities

Category

Roles and Responsibilities

CEO

ㆍChairperson of the Information Security Committee

CISO (Chief Information Security Officer)

Information security strategy establishment, risk management, cyberattack response, and organizational asset protection

CPO (Chief Privacy Officer)

ㆍEstablishment of personal information protection policies, oversight of regulatory compliance, and ensuring
transparency and accountability in data usage

Personal Information Handlers

ㆍExecutives of departments handling personal information

Personal Information Protection Officer

ㆍPersonal information protection

Technical Security Management Officer

ㆍTechnical Personal Information Protection

Physical Security Officers

ㆍManagement of Access, CCTV, etc.

Departmental Personal Information Officers

ㆍExecutives of Personal Information Departments

Personal Information Protection Contractors

ㆍOperation of Personal Information Processing Systems or Task Outsourcing


Ⅱ. Strategy_Risk and Opportunity Identification

Based on the results of the IRO analysis, Hanmi Science is identifying key risks and opportunities related to information security, including personal information protection, that could significantly impact stakeholders and sustainability, and is continuously striving to develop effective response measures.

RISK


Business operational disruption due to security incidents such as customer information leaks or system unavailability

Characteristics of Impact

Potential Impact

Affected Stakeholders

Customers, employees, shareholders, and investors

Severity of Impact
on Society and Environment

Scale ■■■■□ Scope ■■■■□ Recoverability ■■■□□

Expected Financial Impact

Likelihood ■■■□□ Magnitude ■■■□□

Impact on the Company

ㆍImposition of administrative fines or penalties due to violation of the Personal Information Protection Act
Decline in employee work productivity and business loss due to system paralysis
ㆍDecline in stakeholder trust

Company's Response

ㆍEstablishment of international standard information security management system
Establishment of an integrated protection system focused on personal information leakage response and prevention
Education to raise awareness of personal information for personal information handlers
ㆍSecurity awareness campaign to prevent personal information leakage and security incidents

OPPORTUNITY


Enhancing safety through strengthened information security and personal information protection policies and management system certification

Characteristics of Impact

Actual Impact

Affected Stakeholders

Customers

Severity of Impact
on Society and Environment

Magnitude ■■■■□ Scope ■■■□□

Expected Financial Impact

Likelihood ■■■□□ Magnitude ■■■□□

Impact on the Company

Improved customer trust through minimizing legal risks
Securing business continuity
Prevention of financial losses due to legal disputes



Ⅱ. Strategy_Risk and Opportunity Response Plan

Establishment of an international standard information security management system

Strengthening information protection regulations/guidelines and personal information processing policy

Hanmi Science, based on the management's firm commitment to information protection, completely enacted and revised 5 types of information security regulations and 8 types of guidelines in 2025 to ensure the confidentiality, integrity, and availability of all data generated and processed by the company. In particular, as the company-wide work environment transitioned to Microsoft 365 (M365), we reorganized the overall information protection standards, including access control, account management, data protection, and log management, to align with the M365 environment, reflecting the characteristics of the cloud environment and collaboration systems. All information protection related documents, including these information protection regulations and guidelines, personal information processing policy, and internal personal information management plan, are established and operated reflecting revisions to the Personal Information Protection Act and internal operational status, and are kept up-to-date through periodic reviews and revisions in accordance with changes in relevant laws and regulations and the environment. In addition, Hanmi Science continuously updates its personal information processing policy whenever there are changes to the Personal Information Protection Act or issues requiring changes within the policy, and makes it public through the main website so that employees and data subjects can easily check it. Hanmi Science's personal information processing policy and the Information Protection Declaration, which confirms the management's commitment to information protection, can be found via the link above.

Establishment of an integrated protection system focused on personal information leakage response and prevention

Hanmi Science carries out various activities, including thorough pre- and post-measures, for personal information protection. In preparation for potential customer personal information leaks, we establish relevant regulations and guidelines, set up a system for rapid response in case of an incident, and also subscribe to personal information protection liability insurance to prepare for additional risks. Furthermore, in the event of a personal information leakage incident, we have prepared a personal information leakage response manual to prevent further damage and ensure rapid recovery. According to this manual, upon an incident, we immediately identify the cause, take measures to prevent further leakage, notify affected parties, and report to relevant authorities. In particular, the Personal Information Protection Officer reports the incident to the CEO, forms a rapid response team for personal information leakage to systematically address it, and also prepares relief measures for victims and recurrence prevention strategies. In conjunction, we collaborate with the Personal Information Protection Commission to deliberate and determine response measures and punishment levels according to the severity of the incident, and implement regular security training and internal management plans to prevent security breaches. Moreover, major service platforms that process customer personal information and provide payment functions are regularly checked through mock hacking, and any vulnerabilities identified are immediately addressed to improve weak points. Furthermore, all websites publicly launched by Hanmi Science undergo a pre-launch security review process, conduct mock hacking, address 100% of all discovered vulnerabilities, complete implementation verification, and finally operate under a system approved by the CISO before launch.

Personal Information Protection Breach Reporting/Response Process

Education to raise awareness of personal information for personal information handlers

Hanmi Group conducted personal information protection awareness-raising education for all employees, reflecting the revised Personal Information Protection Act of 2025. In particular, it was developed with a practical focus to enable employees who handle personal information to learn more carefully.
The training content was structured around common mistakes during personal information processing and frequent violations during personal information collection, and realistically guided on how to respond quickly and appropriately when personal information leakage occurs. Furthermore, to prevent indiscriminate processing when entrusting or sharing personal information, personal information handlers were educated to clearly recognize their legal and ethical responsibilities and to thoroughly comply with safe processing procedures.
This supported employees in establishing a safe personal information management culture and preventing legal risks. Hanmi Pharmaceutical plans to continuously expand customized training to strengthen practical capabilities related to personal information protection in the future.


Hanmi Group Personal Information Awareness Training Materials

Security awareness campaign to prevent personal information leakage and security incidents

Hanmi Science conducts various participatory campaigns to strengthen employees' information protection awareness and create a secure work environment. In particular, in 2025, we conducted a password prevention campaign to prevent Credential Stuffing attacks, guiding employees to practice safe password management habits. Additionally, we operated quiz-format content to allow employees to naturally check personal information and information protection regulations frequently encountered in their work, providing an opportunity for them to directly read and understand the regulations. This campaign was structured around actual security incident cases and prevention methods, raising employees' awareness and supporting them in naturally applying security rules in their daily work. Furthermore, during periods when security incidents are more likely, such as vacation seasons or holidays, we produce and distribute posters containing practical information protection rules, including precautions for external access, device loss prevention, and personal information handling guidelines, to help employees recognize security once again in their daily lives. Hanmi Science plans to continuously develop an employee participation-centered information protection culture in the future.

2025 Information Security Campaign

Proactive Blocking of Unauthorized External AI Services Guidance ​

Personal Information Protection Day Password Change Campaign Conducted​

Security Precautions Guidance Regarding Telecommunications
Company Hacking Incident ​

Company-wide Personal Information Protection Education Implemented
to Prevent Data Leakage​

Security Guidance Regarding MS SharePoint Hacking Incident ​

Information Protection Day Quiz Event Campaign​

Windows 11 Upgrade Implementation Guidance ​

Phishing Mail Response Simulation Training Conducted​

Implementation of Storage Media Security Measures (Degaussing)​

Production and Distribution of Information Leakage Prevention Posters​

Personal Information Protection Day Password Change Campaign
Information Leakage Prevention Poster
Information Leakage Prevention Poster



III. Risk Management

Risk and Opportunity
Monitoring

Period

Target Audience

Method

Oversight

Prevention of Personal
Information Leakage
Incidents​

Ad-hoc​​

Employees​

· Operating employee security awareness education and campaigns to
prevent security incidents​
· Checking compliance with internal security policies​

Information
Strategy Group​​

Prevention of Information Leakage by Departing
Employees​

Employees Scheduled
to Depart​

· Account deactivation immediately upon resignation submission
· Revocation of all access rights including VPN and business systems​

Increased hacking
incidents at other
companies, leading to
risk of similar accidents​

Personal information
handling systems​

· Enhanced continuous monitoring due to numerous hacking incidents at
other companies​
· Vulnerability assessments conducted for all sites that process, store, and
transmit personal information​
· Regular penetration testing and vulnerability management for key systems​

After M365
implementation,
additional security risks
arise​

Employees​

· Phased implementation of M365 security features based on Entra ID​
· Continuous advancement of access control and account security policies​

Changes in
laws and regulations

Company-wide​

· Monitoring of changes in laws and regulations​
· Review of business impact and revision of internal regulations​



Ⅳ. Indicators and Goals

Key Indicators

2025 Target

2025 Achievements

Achievement

2026 Goals

Mid-to-Long-Term Plan
(2030)

International Standard
Information Security
Management System
Establishment

-

-

-

ISO 27001 Certification
Acquisition

ISO 27001 Ongoing
Certification

Information security
personnel awareness
enhancement
in progress

Information security employee awareness enhancement
in progress

Improvement in employees' information protection awareness maturity

Achieved

Personal information protection
training, phishing email simulation
training, information protection
campaign implementation​

Designing information security training
appropriate for employees' job roles and ranks​

(Personal)
information leakage
accident prevention

No personal information
leakage or achievement
of no security breach incidents

No personal information leakage or 0 security
breach incidents

Achieved

No personal information leakage or
achievement of no security
breach incidents

No personal information leakage or achievement
of no security breach
incidents