Cyber Security Management

Cyber Security Management

HOME

Sustainability

Governance

Cyber Security Management

Cyber Security Management

 

With the widespread use of computers and the rapid development of the Internet, society has undergone profound change. Alongside the convenience of information flows come growing concerns over cyber security. We therefore implement robust protection measures so that convenience is enjoyed only on the premise of security. This is the proper attitude in the information era and the way to meet future challenges.
 

Shih Wei exercises comprehensive controls over the access, processing, transmission, and retention of customer data, as well as the security of personnel and equipment. Security controls and maintenance measures are applied across application development and maintenance, databases, networks, personal computers, and storage media to prevent theft, loss, or leakage and safeguard customer data.

Cyber Security Policy

To maintain normal operation of networked information systems, ensure the security of information transmission and transactions, and protect the confidentiality and integrity of data processed by computers, thereby ensuring the security of data, systems, equipment, and networks. Operations are governed by the “Data Operations Cycle Procedures”, the “Information and Communications Security (ICS) Organization and Management Measures”, the “Information Operations Business Continuity Plan”, and the “Personal Data Protection Management Measures”.
 

Cyber Security Management Framework

 

Shih Wei attaches great importance to ICS and has established a Cyber Security Management Team convened by the head of the IT Office, with members including a qualified information-security supervisor, dedicated Cyber Security personnel, department heads, and IT Office colleagues. The team regularly discusses and reviews Company-wide Cyber-security issues.

 

Management and Implementation Methods

 

In addition to annual internal audits conducted by the Auditing Office, the Company engages an ICA firm to perform an information-operations cycle review annually. We respond to the recommendations in their reports and implement improvements. Examples include:

 
  1. Computer and information communications security controls
    We continuously implement security management mechanisms for computers and IT equipment. During the year, additional measures were introduced, including inspections of licensed software on vessels and the planning and execution of contingency drills for the employee portal system to enhance operational continuity and response capability. 

  2. Personal Data and Confidential Cyber Management
    We have established and implemented management and control measures for personal data and confidential information to ensure the security of data collection, use, storage, and transmission, thereby reducing the risk of data leakage. 

  3. Strengthening Integrated Protection of Cyber Systems
    We continue to enhance the integration architecture of its information systems. Firewall equipment is covered by comprehensive vendor technical support services, and threat intelligence services are continuously subscribed to in order to maintain real-time awareness of cyber security risks and strengthen defensive capabilities.

  4. Server Virtualization and Cloud-Based Management
    We remain committed to advancing server virtualization and cloud migration. We have successfully completed the cloud deployment and launch of key systems, while simultaneously reinforcing information security and access management mechanisms. 
    Within the cloud environment, robust data protection and redundant backup mechanisms have been established to mitigate operational risks. Furthermore, during system implementation and vendor selection, we rigorously evaluate information security management capabilities and perform periodic reviews to ensure overall compliance with relevant standards. 
    We also periodically review the validity of these certifications and the information security clauses in service agreements to ensure that supply chain information security management aligns with international standards and reduces risks related to personal data processing and storage. 

  5. Information Security Awareness Promotion and Professional Capability Development
    Information security–related news and announcements are shared periodically. In 2025, 8 information security awareness communications were conducted, and social engineering simulation exercises are continuously planned to enhance employees’ ability to identify phishing emails and fraudulent attacks. In addition, information technology personnel continue to strengthen their professional capabilities; in 2025, 2 Gemini Certified Trainer certifications were obtained.

  6. Employee Information Security Education and Training
    We continue to promote information security awareness training for employees. In 2025, HQ self-ran ICS awareness training: 79.9 person-hours with 167 participations and an online testing platform was provided. In addition, Information unit participation in online/onsite ICS courses or seminars: 22 person-hours with 9 participations.

  7. Recovery Drills and Audit Mechanisms
    Regular system recovery drills are conducted for critical systems. 2 drills in 2025. Licensed software inspections were also conducted, with two inspections at HQ and one inspection on vessels, all achieving a 100% compliance rate. Internal and external audits covering information cycle and ICS checks to ensure the effectiveness of overall information security management.

Customer Data and Privacy Protection

 

Shih Wei affords optimal protection to customer-provided data to ensure privacy. Comprehensive controls govern data access, processing, transmission, retention, and the security of personnel and equipment. Corresponding security measures are in place across applications, databases, networks, PCs, and storage media to prevent theft, loss, or leakage and safeguard customer data. 

In 2025, 0 complaints concerning infringement of customer privacy or loss of customer data, and 0 major information security incidents.

Ship Information and Communication Security (ICS) and Resources Invested in ICS


In 2025, we dedicated resources to the maintenance, upgrade, and replacement of shipboard computers, employee workstations, antivirus software updates, email protection, company website, and IT Infrastructure hardware and software. These actions have continuously elevated our overall ICS defense.

We are committed to implementing ICS on vessels. In addition to equipping our entire fleet's satellite systems with backup satellites and physical firewalls, we fully initiated the deployment of Low Earth Orbit (LEO) satellites at the end of 2025. This initiative not only enhances shipboard network speeds but also strengthens our information security control and monitoring capabilities. Furthermore, we regularly require the signing of information security codes of conduct, the viewing of training videos, and the execution of ICS incident drills. These efforts continuously bolster our crew members' ICS awareness and emergency response capabilities, ensuring the safety of vessel operations and the integrity of our information environment.

Regarding personal data protection, the on-board email service providers and the shore-based HR management systems have all achieved international certifications related to ICS management. This guarantees that our systems comply with international standards in data access control, risk management, and information security operations. Additionally, for the primary email and IT equipment used daily by crew members, we have deployed endpoint security software with real-time monitoring and protection capabilities to mitigate the risks to personal data posed by malware or unauthorized access. Microsoft Azure cloud servers are utilized to host our employee intranet portal and we have adopted cloud-based HR system on shore-based and on-board systems. This migration has significantly enhanced and perfected our disaster recovery and redundancy mechanisms.

Simultaneously, through crew training and awareness campaigns, we continuously reinforce our crew’s proper understanding of information security and personal data protection. Regular licensed software inspections were conducted to ensure the compliance of shipboard equipment and the overall security of our information environment.