
Hanmi Pharm operates an Information Security Committee for systematic and effective information protection activities. In addition, the CEO is designated as the Chairperson of the Information Security Committee to review and decide on major agenda items related to information security and personal information protection. When important issues arise, the Information Security Committee holds meetings every week. As cyber-attacks, personal information leaks, and hacking incidents targeting pharmaceutical and bio companies have continuously increased recently, the Information Security Committee has established and is actively implementing a systematic and independent information protection management system to proactively respond to these threats. In particular, to respond quickly to information security breaches, a reporting system and penalty regulations for violations have been established, and response measures and penalty levels are reviewed and determined according to the severity of the violation, thereby systematically addressing breach incidents. Furthermore, to prepare for increasing cyber threats, regular penetration testing and vulnerability assessments are continuously conducted, identifying potential security vulnerabilities that may arise during information system and personal information processing in advance and implementing improvement measures. The inspection results are shared with relevant departments to establish recurrence prevention measures and continuously enhance the level of information protection. To date, not a single personal information leak or security breach incident has occurred, and ongoing management and improvement efforts will be made to prevent future security incidents. To effectively carry out information security and personal information protection activities, the company maintains close cooperative relationships with external expert groups to acquire specialized information and capabilities, including information security threat trends and related control measures. Additionally, an Information Security Steering Committee operates to review and decide on matters related to the planning, execution, evaluation, and improvement of (personal) information protection tasks. Members of the Information Security Committee, including the CISO, strengthen mutual communication and cooperation through weekly security meetings. We also plan to provide regular training to enhance the expertise of responsible executives.
Information Security Committee

Personal Information Protection Operating Organization

Category | Operating Frequency | Role |
|---|---|---|
Information Security Committee | Weekly | ㆍReview and decision on major agenda items related to information security |
Personal Information Protection Committee | Monthly | ㆍReview of personal information-related matters |
Category | Roles and Responsibilities |
CEO | ㆍChairperson of the Information Security Committee |
CISO (Chief Information Security Officer) | ㆍInformation security strategy establishment, risk management, cyberattack response, and organizational asset protection |
CPO (Chief Privacy Officer) | ㆍEstablishment of personal information protection policies, oversight of regulatory compliance, and ensuring |
Personal Information Handlers | ㆍExecutives of departments handling personal information |
Personal Information Protection Officer | ㆍPersonal information protection |
Technical Security Management Officer | ㆍTechnical Personal Information Protection |
Physical Security Officers | ㆍManagement of Access, CCTV, etc. |
Departmental Personal Information Officers | ㆍExecutives of Personal Information Departments |
Personal Information Protection Contractors | ㆍOperation of Personal Information Processing Systems or Task Outsourcing |
Based on the results of the IRO analysis, Hanmi Pharmaceutical identifies key risks and opportunities that can significantly impact stakeholders and sustainability related to information security, including personal information protection. We are continuously striving to develop effective countermeasures based on this understanding.
RISK | |
|---|---|
Imposition of punitive administrative fines and liability for compensation in the event of a large-scale data breach. | |
Nature of Impact | Potential Impact |
Affected Stakeholders | Customers |
Severity of Impact | Scale ■■■□□ / Scope ■■■□□ / Recoverability ■■■□□ |
Expected Financial Impact | Likelihood ■■□□□ / Scale ■■■□□ |
Impact on the Company | Imposition of punitive administrative fines and liability for compensation in the event of an incident. |
Company's Response Approach | ㆍEstablishment of an integrated protection system focused on personal information leakage response and prevention |
OPPORTUNITY | |
|---|---|
Establishment of Information Security Management System | |
Nature of Impact | Actual Impact |
Affected Stakeholders | Employees |
Severity of Impact | Scale ■■■□□ / Scope ■■■□□ |
Expected Financial Impact | Likelihood ■■■□□ / Severity ■■■□□ |
Impact on the Company | ㆍEnhancing customer trust by minimizing legal risks |
Strengthening Information Security Regulations/Guidelines and Personal Information Processing Policy
Based on the management's strong commitment to information security, Hanmi Pharmaceutical fully revised and amended 5 types of information security regulations and 8 types of guidelines in 2025 to ensure the confidentiality, integrity, and availability of all data generated and processed by the company. In particular, as the company-wide work environment transitioned to Microsoft 365 (M365) based, the standards for overall information security, including access control, account management, data protection, and log management, were reorganized to align with the M365 environment, reflecting the characteristics of cloud environments and collaborative systems. All information security-related documents, including these information security regulations and guidelines, the personal information processing policy, and the internal personal information management plan, are established and operated to reflect amendments to the Personal Information Protection Act and internal operational status, and are kept up-to-date through periodic review and revision in accordance with changes in relevant laws and the environment. Furthermore, Hanmi Pharmaceutical continuously updates its personal information processing policy whenever there are changes to the Personal Information Protection Act or issues requiring changes within the personal information processing policy, and makes it publicly available on its main website so that employees and data subjects can easily check it. Hanmi Pharmaceutical's Personal Information Processing Policy and Information Security Declaration, which demonstrates the management's commitment to information security, can be checked via the link above.
ISO 27001 International Standard Information Security Certification Renewed for 8 Consecutive Years
Hanmi Pharmaceutical obtained ISO 27001, the international standard certification for information security management, in 2018, becoming the first in the pharmaceutical industry to do so. In 2025, we renewed the certification to the ISO 27001:2022 version, maintaining our certification for 8 consecutive years. Furthermore, to objectively verify the safety of the information security management system across all new drug and formulation technology research activities, external auditors are involved in internal audits. Hanmi Pharmaceutical will continue to maintain these international standard certifications and further develop a superior and safer information security management system, thereby strengthening its competitiveness as a global pharmaceutical company.

Hanmi Pharmaceutical undertakes various activities, including thorough pre- and post-measures, to protect personal information. In preparation for potential customer personal information leaks, the company establishes relevant regulations and guidelines, maintains a system for rapid response in case of an incident, and subscribes to personal information protection liability insurance to mitigate additional risks. Furthermore, in the event of a personal information leak, a personal information leak response manual is in place to prevent damage escalation and ensure quick recovery. According to this manual, incidents trigger immediate root cause identification, additional leak prevention measures, notification to affected parties, and reporting to relevant authorities. Specifically, the Chief Privacy Officer reports incidents to the CEO, forms a rapid response team for personal information leaks to manage the situation systematically, and also devises relief for victims and recurrence prevention measures. Concurrently, in collaboration with the Personal Information Protection Commission, response measures and penalty levels are reviewed and determined based on incident severity, and regular security training and internal management plans are implemented to prevent infringement incidents. Additionally, key service platforms that process customer personal information and provide payment functions are regularly audited through simulated hacking, and any identified vulnerabilities are immediately addressed and improved. Moreover, all Hanmi Pharmaceutical websites publicly accessible undergo a pre-opening security review process, including simulated hacking, and all discovered vulnerabilities are 100% remediated, followed by implementation verification, and finally opened after confirmation by the CISO, operating under a comprehensive system.
Personal Information Protection Infringement Incident Reporting/Response Process

Hanmi Group conducted personal information protection awareness enhancement training for all employees, reflecting the amended Personal Information Protection Act for 2025. The training was particularly practice-oriented to ensure employees handling personal information could learn with greater attention. The curriculum focused on common errors during personal information processing and frequent violations during personal information collection, providing realistic guidance on how to respond swiftly and appropriately if a personal information leak occurs. Furthermore, to prevent indiscriminate processing when outsourcing or sharing personal information, personal information processors were educated to clearly recognize their legal and ethical responsibilities and to strictly adhere to secure processing procedures. This initiative supported employees in establishing a secure personal information management culture and preventing legal risks. Hanmi Pharmaceutical plans to continue expanding customized training programs to strengthen practical capabilities related to personal information protection.

Hanmi Pharmaceutical conducts various participatory campaigns to strengthen employees' information protection awareness and foster a secure work environment. Notably, in 2025, a password prevention campaign was launched to combat credential stuffing attacks, guiding employees to practice secure password management habits. Furthermore, quiz-format content was utilized to allow employees to naturally review personal information and information protection regulations frequently encountered in their work, providing opportunities for them to read and understand the rules directly. This campaign focused on actual security incident cases and prevention methods, raising employees' vigilance and supporting them in naturally applying security protocols in their daily tasks. Additionally, during periods when the likelihood of security incidents increases, such as vacation seasons or holidays, posters containing practical information protection rules—including precautions for external access, device loss prevention, and guidelines for handling personal information—are produced and distributed to help employees re-recognize security in their daily lives. Hanmi Pharmaceutical plans to continue developing an employee-participation-centric information protection culture.
2025 Information Security Campaign | |
|---|---|
Proactive Blocking Guidance for Unauthorized External AI Services | Personal Information Protection Day Password Change Campaign in Progress |
Security Precautions Guidance Regarding Telecommunication | Company-wide Implementation of Personal Information Protection Training |
Security Guidance Regarding MS SharePoint Hacking Incident | Information Protection Day Quiz Event Campaign |
Windows 11 Upgrade Implementation Guidance | Malicious Email Response Simulation Training Conducted |
Implementation of Storage Media Security Measures (Degaussing) | Production and Distribution of Information Leakage Prevention Posters |
![]() Personal Information Protection Day Password Change Campaign | ![]() Information Leakage Prevention Poster | ![]() Information Leakage Prevention Poster |
|---|
Hanmi Pharmaceutical integrates risk and opportunity management processes related to information security, including personal information protection, with its Enterprise Risk Management (ERM) system. By doing so, the company effectively manages overall corporate risks, maximizes potential opportunities, and promotes sustainable growth.
Risk and Opportunity Monitoring | Frequency | Subjects | Method | Oversight |
|---|---|---|---|---|
Preventing Personal Information | Ongoing | Employees | · Operating employee security awareness training and campaigns to | Information |
Preventing information leakage | Ongoing | Employees scheduled for departure | · Account deactivation immediately upon receipt of resignation | Information |
Risk of similar incidents due to | Ongoing | Personal information | · Strengthening continuous monitoring due to numerous hacking cases | Information |
Additional security risks arising | Ongoing | Employees | · Phased implementation of Entra ID-based M365 security features | Information |
Need for security response due to | Ongoing | Company-wide | · Monitoring changes in laws and regulations | Information |
Key Indicators | 2025 Targets | 2025 Performance | Attainment | 2026 Targets | Mid-to-Long-Term Plan |
|---|---|---|---|---|---|
Establishment of | Maintaining ISO 27001 | Successful renewal audit | Achieved | Maintaining ISO 27001 | ISO 27001 Continuous |
Information security | Information security | Employee information | Achieved | Personal information protection training, | Information security training |
(Personal) | Achieved zero incidents | 0 cases of personal | Achieved | Achieved zero incidents related to | Achieved zero incidents related |