Customer Privacy and Information Security

》Information Security Management Organizational Structure

BES established the Information Security Office at the end of 2022. This office is responsible for planning the security management of information operations, establishing and maintaining the information security management system, coordinating the formulation and implementation of information security and data protection policies, and conducting risk management and compliance audits.

A dedicated promotion team was also established. The General Manager concurrently serves as the Chief Information Security Officer (CISO). The supervisor of the Real-time Audio-Visual Command Center acts as the supervisor and Information Security Officer. Two full-time information security specialists are assigned to the team. Heads of all departments within the Company (legal, audit, IT, engineering, and other departments) are team members who lead efforts to advance corporate information security initiatives and related audit work. The Chief Information Security Officer shall report to the Audit Committee and the BOD semiannually. In 2025, the chief submitted two reports to the Audit Committee and one to the Board of Directors.

》Information Security Management Policy

》Information Security Incident Management and Response

In accordance with BES’s information security policy, BES implements an information security incident management procedure to swiftly respond to and recover from security incidents, including the following measures:

While establishing its information security management system, BES will strengthen relevant security management and control measures. It will continue to conduct simulated key inspections and advocacy training to enhance endpoint protection. Regular information security policy communications and related education and training will be rolled out to all staff to shorten incident response time, improve the security of the Company’s data and systems, and mitigate corporate losses. Following BES’s “Personal Data File Security Maintenance Plan,” BES conducts regular audits on the maintenance of personal data files (at least once per year) to verify compliance with the provisions stipulated in this plan. For non-conformities identified during audits and potential risks of non-compliance, improvement actions shall be formulated and fully implemented. Implementing corrective and preventive actions shall comply with the following requirements:

》Information Security Education and Training

ISO 27001

Customer Privacy and Information Security

》Information Security Management Organizational Structure

BES established the Information Security Office at the end of 2022. This office is responsible for planning the security management of information operations, establishing and maintaining the information security management system, coordinating the formulation and implementation of information security and data protection policies, and conducting risk management and compliance audits.

A dedicated promotion team was also established. The General Manager concurrently serves as the Chief Information Security Officer (CISO). The supervisor of the Real-time Audio-Visual Command Center acts as the supervisor and Information Security Officer. Two full-time information security specialists are assigned to the team. Heads of all departments within the Company (legal, audit, IT, engineering, and other departments) are team members who lead efforts to advance corporate information security initiatives and related audit work. The Chief Information Security Officer shall report to the Audit Committee and the BOD semiannually. In 2025, the chief submitted two reports to the Audit Committee and one to the Board of Directors.

》Information Security Management Policy

》Information Security Incident Management and Response

In accordance with BES’s information security policy, BES implements an information security incident management procedure to swiftly respond to and recover from security incidents, including the following measures:

While establishing its information security management system, BES will strengthen relevant security management and control measures. It will continue to conduct simulated key inspections and advocacy training to enhance endpoint protection. Regular information security policy communications and related education and training will be rolled out to all staff to shorten incident response time, improve the security of the Company’s data and systems, and mitigate corporate losses. Following BES’s “Personal Data File Security Maintenance Plan,” BES conducts regular audits on the maintenance of personal data files (at least once per year) to verify compliance with the provisions stipulated in this plan. For non-conformities identified during audits and potential risks of non-compliance, improvement actions shall be formulated and fully implemented. Implementing corrective and preventive actions shall comply with the following requirements:

》Information Security Education and Training

ISO 27001