Customer Privacy and Information Security  

I. Policy and Commitments

To safeguard customer privacy and information security, BES has established a range of internal management systems and operating procedures to ensure compliance and risk control throughout the information handling process. Relevant guidelines include: 

·Guidelines for Computer-Related Operations and Information Security Management", which regulate areas such as equipment and network connectivity usage, system development and programming, information file and operational processing, and information security audits; 

·Operational Guidelines for the Management of Financial and Non-Financial Information" and other internal control systems outline personal data protection standards to strengthen privacy safeguards during data processing; 

The company has also established an Audit Committee, in accordance with Article 14-1 of the Securities and Exchange Act, responsible for reviewing and revising internal control systems and regularly assessing their effectiveness to ensure the proper implementation of information security and personal data protection policies. 

BES is committed to continuously enhancing its information security management and customer privacy protection mechanisms in line with legal requirements and industry practices, thereby reducing potential risks and strengthening stakeholder trust. 

II. Management Review Mechanism 

BES's information security management policy is based on the ISO 27001 framework, with a focus on risk control across four key aspects: personnel, processes, systems, and internal controls. Through training, anomaly monitoring, access control, and audit mechanisms, the company strengthens cybersecurity awareness and operational resilience, ensuring that corporate data, customer privacy, and trade secrets are well protected. 

III. Organizational Structure and Units

BES established the Information Security Office at the end of 2022. The Office is responsible for implementing information security management plans, establishing and maintaining the information security management system, and overseeing the formulation, execution, risk control, and compliance auditing of information security and protection policies. Moreover, an Information Security Promotion Group was formed, with the President concurrently serving as the Chief Information Security Officer. The head of the Audio/Video Command Center serves as both the supervisor and the Information Security Officer. Two dedicated information security managers are also assigned. Managers of each department from across the company, including Legal, Audit, IT, and Engineering, are members of the group, responsible for promoting the company's information security and conducting related audits. 

 

 

 

IV. Indicators and Targets

Short-term (2026–2027)

  1. 1. At least one employee to obtain a professional information security certification (ISO 27001 Lead Auditor) in 2026.

  2. 2. Zero information security incidents per year.

  3. 3. At least four information security awareness sessions conducted annually.

  4. 4. Successfully pass the ISO 27001 assessment and obtain certification.

  5. 5. Improve the SecurityScorecard information security rating to Grade A.

Mid-term (by 2030)

  1. 1. Ensure that all designated internal information security personnel obtain at least one professional certification recognized by the Ministry of Digital Affairs.

  2. 2. Maintain zero information security incidents annually.

  3. 3. Conduct at least four information security awareness sessions each year.

  4. 4. Maintain a Grade A SecurityScorecard information security rating.

Long-term (from 2030 onward)
Ensure that information security and personal data protection systems comply with regulatory requirements, strengthen information security management and customer privacy protection mechanisms, and maintain customer trust.

V. 2025 Information Security and Personal Data Protection Achievements

• On December 23, 2025, the Company reported the 2025 information security operations to the Board of Directors.
• In 2025, CTCI did not receive any substantiated complaints regarding customer privacy violations or data loss, nor were there any records of penalties imposed by regulatory authorities.
• The Company has initiated the implementation project of the ISO 27001:2022 Information Security Management System, with Deloitte & Touche providing consulting and advisory services.
• One company-wide information security general awareness training session and four internal information security awareness campaigns were conducted, covering topics including personal data protection, construction site information security, prohibition of mainland China–branded ICT products, respect for intellectual property and prohibition of illegal software use, phishing email alerts, and enhancement of social engineering prevention awareness.
• The Company joined the Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) advocacy organization.

Customer Privacy and Information Security  

I. Policy and Commitments

To safeguard customer privacy and information security, BES has established a range of internal management systems and operating procedures to ensure compliance and risk control throughout the information handling process. Relevant guidelines include: 

·Guidelines for Computer-Related Operations and Information Security Management", which regulate areas such as equipment and network connectivity usage, system development and programming, information file and operational processing, and information security audits; 

·Operational Guidelines for the Management of Financial and Non-Financial Information" and other internal control systems outline personal data protection standards to strengthen privacy safeguards during data processing; 

The company has also established an Audit Committee, in accordance with Article 14-1 of the Securities and Exchange Act, responsible for reviewing and revising internal control systems and regularly assessing their effectiveness to ensure the proper implementation of information security and personal data protection policies. 

BES is committed to continuously enhancing its information security management and customer privacy protection mechanisms in line with legal requirements and industry practices, thereby reducing potential risks and strengthening stakeholder trust. 

II. Management Review Mechanism 

BES's information security management policy is based on the ISO 27001 framework, with a focus on risk control across four key aspects: personnel, processes, systems, and internal controls. Through training, anomaly monitoring, access control, and audit mechanisms, the company strengthens cybersecurity awareness and operational resilience, ensuring that corporate data, customer privacy, and trade secrets are well protected. 

III. Organizational Structure and Units

BES established the Information Security Office at the end of 2022. The Office is responsible for implementing information security management plans, establishing and maintaining the information security management system, and overseeing the formulation, execution, risk control, and compliance auditing of information security and protection policies. Moreover, an Information Security Promotion Group was formed, with the President concurrently serving as the Chief Information Security Officer. The head of the Audio/Video Command Center serves as both the supervisor and the Information Security Officer. Two dedicated information security managers are also assigned. Managers of each department from across the company, including Legal, Audit, IT, and Engineering, are members of the group, responsible for promoting the company's information security and conducting related audits. 

 

 

IV. Indicators and Targets

Short-term (2026–2027)

  1. 1. At least one employee to obtain a professional information security certification (ISO 27001 Lead Auditor) in 2026.

  2. 2. Zero information security incidents per year.

  3. 3. At least four information security awareness sessions conducted annually.

  4. 4. Successfully pass the ISO 27001 assessment and obtain certification.

  5. 5. Improve the SecurityScorecard information security rating to Grade A.

Mid-term (by 2030)

  1. 1. Ensure that all designated internal information security personnel obtain at least one professional certification recognized by the Ministry of Digital Affairs.

  2. 2. Maintain zero information security incidents annually.

  3. 3. Conduct at least four information security awareness sessions each year.

  4. 4. Maintain a Grade A SecurityScorecard information security rating.

Long-term (from 2030 onward)
Ensure that information security and personal data protection systems comply with regulatory requirements, strengthen information security management and customer privacy protection mechanisms, and maintain customer trust.

V. 2025 Information Security and Personal Data Protection Achievements

• On December 23, 2025, the Company reported the 2025 information security operations to the Board of Directors.
• In 2025, CTCI did not receive any substantiated complaints regarding customer privacy violations or data loss, nor were there any records of penalties imposed by regulatory authorities.
• The Company has initiated the implementation project of the ISO 27001:2022 Information Security Management System, with Deloitte & Touche providing consulting and advisory services.
• One company-wide information security general awareness training session and four internal information security awareness campaigns were conducted, covering topics including personal data protection, construction site information security, prohibition of mainland China–branded ICT products, respect for intellectual property and prohibition of illegal software use, phishing email alerts, and enhancement of social engineering prevention awareness.
• The Company joined the Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) advocacy organization.