original hero image
Material Issue 5
Information Security including Personal Information Protection

Information Security including Personal Information Protection


Ⅰ. Governance

Decision-making Structure

Hanmi Pharm operates an Information Security Committee for systematic and effective information protection activities. In addition, the CEO is designated as the Chairperson of the Information Security Committee to review and decide on major agenda items related to information security and personal information protection. When important issues arise, the Information Security Committee holds meetings every week. As cyber-attacks, personal information leaks, and hacking incidents targeting pharmaceutical and bio companies have continuously increased recently, the Information Security Committee has established and is actively implementing a systematic and independent information protection management system to proactively respond to these threats. In particular, to respond quickly to information security breaches, a reporting system and penalty regulations for violations have been established, and response measures and penalty levels are reviewed and determined according to the severity of the violation, thereby systematically addressing breach incidents. Furthermore, to prepare for increasing cyber threats, regular penetration testing and vulnerability assessments are continuously conducted, identifying potential security vulnerabilities that may arise during information system and personal information processing in advance and implementing improvement measures. The inspection results are shared with relevant departments to establish recurrence prevention measures and continuously enhance the level of information protection. To date, not a single personal information leak or security breach incident has occurred, and ongoing management and improvement efforts will be made to prevent future security incidents. To effectively carry out information security and personal information protection activities, the company maintains close cooperative relationships with external expert groups to acquire specialized information and capabilities, including information security threat trends and related control measures. Additionally, an Information Security Steering Committee operates to review and decide on matters related to the planning, execution, evaluation, and improvement of (personal) information protection tasks. Members of the Information Security Committee, including the CISO, strengthen mutual communication and cooperation through weekly security meetings. We also plan to provide regular training to enhance the expertise of responsible executives.

Information Security Committee

Personal Information Protection Operating Organization

Operating Method

Category

Operating Frequency

Role

Information Security Committee

Weekly

ㆍReview and decision on major agenda items related to information security

Personal Information Protection Committee

Monthly

ㆍReview of personal information-related matters

Roles and Responsibilities

Category

Roles and Responsibilities

CEO

ㆍChairperson of the Information Security Committee

CISO (Chief Information Security Officer)

Information security strategy establishment, risk management, cyberattack response, and organizational asset protection

CPO (Chief Privacy Officer)

ㆍEstablishment of personal information protection policies, oversight of regulatory compliance, and ensuring
transparency and accountability in data usage

Personal Information Handlers

ㆍExecutives of departments handling personal information

Personal Information Protection Officer

ㆍPersonal information protection

Technical Security Management Officer

ㆍTechnical Personal Information Protection

Physical Security Officers

ㆍManagement of Access, CCTV, etc.

Departmental Personal Information Officers

ㆍExecutives of Personal Information Departments

Personal Information Protection Contractors

ㆍOperation of Personal Information Processing Systems or Task Outsourcing


II. Strategy_Identification of Risks and Opportunities

Based on the results of the IRO analysis, Hanmi Pharmaceutical identifies key risks and opportunities that can significantly impact stakeholders and sustainability related to information security, including personal information protection. We are continuously striving to develop effective countermeasures based on this understanding.

RISK


Imposition of punitive administrative fines and liability for compensation in the event of a large-scale data breach.

Nature of Impact

Potential Impact

Affected Stakeholders

Customers

Severity of Impact
on Society and Environment

Scale ■■■□□ / Scope ■■■□□ / Recoverability ■■■□□

Expected Financial Impact

Likelihood ■■□□□ / Scale ■■■□□

Impact on the Company

Imposition of punitive administrative fines and liability for compensation in the event of an incident.

Company's Response Approach

ㆍEstablishment of an integrated protection system focused on personal information leakage response and prevention
ㆍConducting education and campaigns to raise personal information awareness for personal information handlers

OPPORTUNITY


Establishment of Information Security Management System

Nature of Impact

Actual Impact

Affected Stakeholders

Employees

Severity of Impact
on Society and Environment

Scale ■■■□□ / Scope ■■■□□

Expected Financial Impact

Likelihood ■■■□□ / Severity ■■■□□

Impact on the Company

ㆍEnhancing customer trust by minimizing legal risks
ㆍEnsuring business continuity
ㆍPreventing financial losses due to legal disputes



Ⅱ. Strategy_Risk and Opportunity Response Plan

Establishment of an International Standard Information Security Management System

Strengthening Information Security Regulations/Guidelines and Personal Information Processing Policy

Based on the management's strong commitment to information security, Hanmi Pharmaceutical fully revised and amended 5 types of information security regulations and 8 types of guidelines in 2025 to ensure the confidentiality, integrity, and availability of all data generated and processed by the company. In particular, as the company-wide work environment transitioned to Microsoft 365 (M365) based, the standards for overall information security, including access control, account management, data protection, and log management, were reorganized to align with the M365 environment, reflecting the characteristics of cloud environments and collaborative systems. All information security-related documents, including these information security regulations and guidelines, the personal information processing policy, and the internal personal information management plan, are established and operated to reflect amendments to the Personal Information Protection Act and internal operational status, and are kept up-to-date through periodic review and revision in accordance with changes in relevant laws and the environment. Furthermore, Hanmi Pharmaceutical continuously updates its personal information processing policy whenever there are changes to the Personal Information Protection Act or issues requiring changes within the personal information processing policy, and makes it publicly available on its main website so that employees and data subjects can easily check it. Hanmi Pharmaceutical's Personal Information Processing Policy and Information Security Declaration, which demonstrates the management's commitment to information security, can be checked via the link above.

ISO 27001 International Standard Information Security Certification Renewed for 8 Consecutive Years

Hanmi Pharmaceutical obtained ISO 27001, the international standard certification for information security management, in 2018, becoming the first in the pharmaceutical industry to do so. In 2025, we renewed the certification to the ISO 27001:2022 version, maintaining our certification for 8 consecutive years. Furthermore, to objectively verify the safety of the information security management system across all new drug and formulation technology research activities, external auditors are involved in internal audits. Hanmi Pharmaceutical will continue to maintain these international standard certifications and further develop a superior and safer information security management system, thereby strengthening its competitiveness as a global pharmaceutical company.

Establishment of an integrated protection system focused on personal information leakage response and prevention

Hanmi Pharmaceutical undertakes various activities, including thorough pre- and post-measures, to protect personal information. In preparation for potential customer personal information leaks, the company establishes relevant regulations and guidelines, maintains a system for rapid response in case of an incident, and subscribes to personal information protection liability insurance to mitigate additional risks. Furthermore, in the event of a personal information leak, a personal information leak response manual is in place to prevent damage escalation and ensure quick recovery. According to this manual, incidents trigger immediate root cause identification, additional leak prevention measures, notification to affected parties, and reporting to relevant authorities. Specifically, the Chief Privacy Officer reports incidents to the CEO, forms a rapid response team for personal information leaks to manage the situation systematically, and also devises relief for victims and recurrence prevention measures. Concurrently, in collaboration with the Personal Information Protection Commission, response measures and penalty levels are reviewed and determined based on incident severity, and regular security training and internal management plans are implemented to prevent infringement incidents. Additionally, key service platforms that process customer personal information and provide payment functions are regularly audited through simulated hacking, and any identified vulnerabilities are immediately addressed and improved. Moreover, all Hanmi Pharmaceutical websites publicly accessible undergo a pre-opening security review process, including simulated hacking, and all discovered vulnerabilities are 100% remediated, followed by implementation verification, and finally opened after confirmation by the CISO, operating under a comprehensive system.

Personal Information Protection Infringement Incident Reporting/Response Process


Personal Information Awareness Enhancement Training for Personal Information Processors

Hanmi Group conducted personal information protection awareness enhancement training for all employees, reflecting the amended Personal Information Protection Act for 2025. The training was particularly practice-oriented to ensure employees handling personal information could learn with greater attention. The curriculum focused on common errors during personal information processing and frequent violations during personal information collection, providing realistic guidance on how to respond swiftly and appropriately if a personal information leak occurs. Furthermore, to prevent indiscriminate processing when outsourcing or sharing personal information, personal information processors were educated to clearly recognize their legal and ethical responsibilities and to strictly adhere to secure processing procedures. This initiative supported employees in establishing a secure personal information management culture and preventing legal risks. Hanmi Pharmaceutical plans to continue expanding customized training programs to strengthen practical capabilities related to personal information protection.


Hanmi Pharmaceutical Personal Information Awareness Training Materials

Security Awareness Enhancement Campaign for Preventing Personal Information Leakage and Security Incidents

Hanmi Pharmaceutical conducts various participatory campaigns to strengthen employees' information protection awareness and foster a secure work environment. Notably, in 2025, a password prevention campaign was launched to combat credential stuffing attacks, guiding employees to practice secure password management habits. Furthermore, quiz-format content was utilized to allow employees to naturally review personal information and information protection regulations frequently encountered in their work, providing opportunities for them to read and understand the rules directly. This campaign focused on actual security incident cases and prevention methods, raising employees' vigilance and supporting them in naturally applying security protocols in their daily tasks. Additionally, during periods when the likelihood of security incidents increases, such as vacation seasons or holidays, posters containing practical information protection rules—including precautions for external access, device loss prevention, and guidelines for handling personal information—are produced and distributed to help employees re-recognize security in their daily lives. Hanmi Pharmaceutical plans to continue developing an employee-participation-centric information protection culture.

2025 Information Security Campaign

Proactive Blocking Guidance for Unauthorized External AI Services

Personal Information Protection Day Password Change Campaign in Progress

Security Precautions Guidance Regarding Telecommunication
Company Hacking Incident

Company-wide Implementation of Personal Information Protection Training
for Preventing Personal Information Leaks

Security Guidance Regarding MS SharePoint Hacking Incident

Information Protection Day Quiz Event Campaign

Windows 11 Upgrade Implementation Guidance

Malicious Email Response Simulation Training Conducted

Implementation of Storage Media Security Measures (Degaussing)

Production and Distribution of Information Leakage Prevention Posters

Personal Information Protection Day Password Change Campaign
Information Leakage Prevention Poster
Information Leakage Prevention Poster

III. Risk Management

Hanmi Pharmaceutical integrates risk and opportunity management processes related to information security, including personal information protection, with its Enterprise Risk Management (ERM) system. By doing so, the company effectively manages overall corporate risks, maximizes potential opportunities, and promotes sustainable growth.

Risk and Opportunity Monitoring

Frequency

Subjects

Method

Oversight

Preventing Personal Information
Leaks

Ongoing

Employees

· Operating employee security awareness training and campaigns to
prevent security incidents
· Checking compliance with internal security policies

Information
Strategy Group

Preventing information leakage
by ex-employees

Ongoing

Employees scheduled for departure

· Account deactivation immediately upon receipt of resignation
· Revocation of all access rights, including VPN and business systems

Information
Strategy Group

Risk of similar incidents due to
increased hacking cases
at other companies

Ongoing

Personal information
handling systems

· Strengthening continuous monitoring due to numerous hacking cases
at other companies​
· Conducting vulnerability assessments on all sites that process, store,
and transmit personal information​
· Managing regular penetration testing and vulnerability remediation for
key systems

Information
Strategy Group

Additional security risks arising
after M365 implementation

Ongoing

Employees

· Phased implementation of Entra ID-based M365 security features
· Continuous enhancement of access control and account security policies

Information
Strategy Group

Need for security response due to
changes in laws and regulations

Ongoing

Company-wide

· Monitoring changes in laws and regulations​
· Reviewing business impact and revising internal regulations

Information
Strategy Group



Ⅳ. Indicators and Targets

Key Indicators

2025 Targets

2025 Performance

Attainment

2026 Targets

Mid-to-Long-Term Plan
(2030)

Establishment of
an international standard
information security
management system

Maintaining ISO 27001
certification

Successful renewal audit
for ISO 27001

Achieved

Maintaining ISO 27001
certification

ISO 27001 Continuous
certification

Information security
employee awareness
enhancement in progress

Information security
employee awareness
enhancement
in progress

Employee information
protection awareness
maturity enhancement

Achieved

Personal information protection training,
phishing email simulation training,
information protection campaigns
conducted

Information security training
design tailored to employee
job roles and ranks

(Personal)
information leakage
incident prevention

Achieved zero incidents
related to personal
information leakage or
security breaches

0 cases of personal
information leakage or
security breaches

Achieved

Achieved zero incidents related to
personal information leakage or
security breaches

Achieved zero incidents related
to security breaches or
personal information leakage