Management Approach
Bora Pharmaceuticals is committed to enhancing cybersecurity management. The Company has established the “Bora Group Cybersecurity Policy,” “Bora Group Information Assets Usage Policy,” “AI Technology Usage Policy,” and “Information System and Business Continuity Plan,” which are subject to regular review and updates to serve as guiding principles for cybersecurity affairs. A Chief Information Security Officer (CISO) and a dedicated Cybersecurity Department have been established to coordinate group-wide security, monitoring, and incident response. Additionally, Bora has implemented multiple cybersecurity systems and continuously optimizes its defense mechanisms. These measures include deploying next-generation firewalls, spam filtering systems, and data backup solutions to ensure the integrity and stability of its information assets.
Cybersecurity Management and Organizations
To ensure the implementation of cybersecurity, Bora Pharmaceuticals established the Bora Group Cybersecurity Policy in 2021 and updated it in 2025. The relevant policies are regularly reviewed and updated in response to changes in cybersecurity risks to ensure continuous improvement and effectiveness. Additionally, the company actively participates in collaborative cybersecurity defense organizations, such as the Science Park Information Sharing and Analysis Center, the Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC), and the Chief Information Security Officer (CISO) Association, to strengthen its collaborative cybersecurity capabilities.
Since January 31, 2023, Mr. Chia-Chu Chen, Vice President, has served as the Chief Information Security Officer (CISO), regularly reporting to the President to enhance the overall cybersecurity management level of the Bora group. Global Cybersecurity Manager Mr. Lin-Chieh Ku leads global security operations, projects, and cross-region integration while overseeing the Group Cybersecurity Department. To ensure continuous monitoring, the Company has established a dedicated cybersecurity function responsible for consistent surveillance and response to potential security threats. The CISO reported on the implementation of information security measures to the Board of Directors on November 13, 2025. No material information security incidents occurred in 2025.
Cybersecurity Management Measures
| Strategy | Mechanism | Initiatives |
|---|---|---|
| Information Security | Establishment of Information Security Organization; Formulation of Information and Communication Security Policies; Enhancement of Existing Information and Communication System Security | Appointed Dedicated Information Security Officers and Team Members to Oversee and Implement Cybersecurity Initiatives; Conducted Regular Reviews and Updates of Bora’s Information and Communication Security Policy; Evaluated Existing Information and Communication Systems, with Ongoing Efforts towards Optimization |
| Technology Applications | Strengthening of Information and Communication Systems; Internal and External Data Collection; Data Analysis and Response | Continuous Assessment and Upgrade of Email Protection; Enhancement of Endpoint Defense Capabilities; Abnormal Network Activity Monitoring and Prevention; Integration of Existing Cybersecurity Tools to Improve Monitoring Efficiency |
| Information Optimization | Ongoing Enhancement of Company-wide Information Security Awareness; Progressive Strengthening of Cybersecurity Defense and Protection Systems; Regular Implementation of Backup and Disaster Recovery Drills for Critical Systems and Data | Regular Distribution of Cybersecurity Newsletters, with 13 Issues Published in 2025. Beginning in 2025, Cybersecurity Content is Integrated into the Group’s Internal Employee Newsletter, Achieving an 88% Distribution Completion Rate; Implementation of Information and Communication System Vulnerability Management; Execution of Cybersecurity Awareness Training for All New Hires; At Least 1 Social Engineering Drill Conducted Annually to Enhance Employee Cybersecurity Awareness |
Cybersecurity Implementation Status
- System and Protection Upgrade: In 2025, we fully extended and deployed next-generation email and endpoint protection systems to all domestic and overseas facilities, and established USB scanning and control mechanisms at each facility to ensure all global sites receive consistent and optimal protection.
- Awareness Training and Exercise: In 2025, we launched a group-wide “Online Information Security Awareness Training Month” across domestic and international locations and conducted social engineering (phishing email) simulation drills on a regular basis.
- Multi-Factor Authentication (MFA): Fully implemented the multi-factor authentication mechanism, strengthening the reliability of employee identity verification and effectively preventing hackers from accessing company systems through stolen credentials.
- Acceptable Use Policy: The Group Cybersecurity Department created and issued the “Acceptable Use Policy” at the beginning of 2024 and introduced the “AI Acceptable Use Policy” by year-end to address potential risks associated with emerging technologies.
- New Employee Training: Integrated basic information security courses in both Chinese and English into the onboarding program for new employees.
- Social Engineering Prevention Courses: Conducted educational sessions for all employees to enhance their ability to recognize phishing attacks and other social engineering tactics.
- Advanced Professional Training: Provided in-depth cybersecurity technical training for IT department personnel to ensure key technical staff are equipped to handle the latest security threats.
Information Security and Business Continuity Plan
The Company prioritizes operational continuity in the event of disasters or major cybersecurity incidents. It has established an “Information System and Business Continuity Plan” and implemented backup mechanisms for core systems and sensitive data. Measures include off-site data backup, network redundancy, and regular disaster recovery drills under different scenarios to test system recovery time objectives (RTO) and recovery point objectives (RPO).
Information Security Incident Reporting
Bora Pharmaceuticals has established the “Information Security Incident Reporting and Response Procedure” in accordance with the Cybersecurity Management Act and related regulations, setting up standardized reporting and response processes to ensure timely reaction, effective damage control, and rapid recovery in the event of an information security incident.
The Company has established an Information Security Incident Response Team, with the head of the Information Management Department serving as the chief coordinator, overseeing disaster recovery and business continuity drills during normal operations and leading response efforts when incidents occur. Information security incidents are classified into 4 levels, from Level 4 to Level 1. Depending on the severity level, the response team must complete initial damage control within 24 to 72 hours, followed by incident forensics, root cause analysis, and system recovery.
For Level 4 major information security incidents, the Company will hold press conferences and issue press releases through authorized spokespersons in accordance with regulations; when necessary, third-party cybersecurity organizations with professional certifications (such as CISSP or CEH) may be commissioned to conduct investigations and forensics. Bora Pharmaceuticals has also established a 24-hour cybersecurity reporting hotline for all employees, temporary staff, and partner vendors to promptly report suspected information security incidents.
AI Governance Framework
The Company advances digital transformation through a governance framework that emphasizes responsible and transparent use of artificial intelligence. The Group’s Information Management Division has issued the “AI Technology Usage Policy” to govern the ethical use and risk management of AI technologies. The policy applies across the Group and requires that AI systems be used only for legitimate and lawful purposes, with restrictions on the input of sensitive data unless appropriately de-identified and authorized.
AI-generated outputs are subject to human review and are not used as the sole basis for decision-making. Within this governance framework and in connection with the Microsoft 365 environment, the Company enables the use of Microsoft Copilot for general productivity applications such as meeting notes and task tracking. Such applications are limited to non-regulated operational areas and do not interface with core regulated systems.
Personal Data Privacy Protection
The Company is committed to the protection of personal data and has established a comprehensive “Personal Data Protection Policy” applicable to all employees,subsidiaries, and key partners. We collect, process, and use personal data in accordance with the principles of legality, fairness, and transparency, ensuring data security while providing individuals with the right to manage their data. To mitigate potential risks, the Company implements strict access controls, encryption technologies, and audit mechanisms to prevent unauthorized access or misuse of personal information. Additionally, Bora conducts annual internal and external audits on personal data protection and provides relevant training to employees to enhance compliance and data security, ensuring alignment with international regulatory standards and best practices.