
The Company operates access control across the entire scope of information systems, networks, user accounts, and terminals, and utilizes security solutions to prevent and monitor major threats such as unauthorized access, information leakage, and malicious e-mails. The Company also protects customer data and third-party (partner company) data from unauthorized access and disclosure.
In terms of risk management, the Company identifies and evaluates risk factors and assigns priorities through regular information security risk assessments, and implements corrective actions for identified vulnerabilities. The Company also regularly audits internal control procedures to prevent information security violations.
When a breach of confidential information occurs, the Company applies the classification, isolation, and recovery stages in accordance with its Incident Response Plan (IRP), and carries out prompt analysis, reporting, action and recurrence prevention activities in accordance with internal response procedures.
In terms of policy and education, the Company regularly inspects and revises its information protection policies and internal security guidelines, and continuously conducts information protection awareness training, internal rules training, and security guidance for employees. To enable stakeholders to report information security issues, the Company maintains a whistleblowing procedure at all times and guarantees the confidentiality of the reporter and protection from disadvantage.
In addition, from 2025, the Company has strengthened recordkeeping and consent procedures by defining and operating document retention periods by information type (in compliance with the Personal Information Protection Act and the Medical Service Act), and obtaining the prior consent of stakeholders regarding the processing, sharing, and storage of confidential information.
In 2025, the Company achieved accident-free information security operations. Complaints received from outside and complaints raised by regulatory authorities were 0 cases each, and leakage, theft, or loss of customer information was also 0 cases. In the same year, the Company invested KRW 256 million in the information protection area and maintains ISO 27001 (ISMS) certification.