Information Security Management
Information Security Framework and Policy
In recent years, hacker activities around the world have become increasingly rampant, and information security threats continue to emerge. These threats may not only cause major financial losses for enterprises but also inflict irreparable damage on reputation.
To respond to information security risks, EGAT has established a complete information security management system. In addition to introducing the ISO 27001 Information Security Management System, the Company conducted renewal review procedures and external audits in 2025. In the same year, it also developed an information asset inventory and risk assessment management system to monitor company endpoint computer usage and block non-compliant software. At the organizational level, EGAT has established the Information Security Management Division, led by a dedicated information security officer responsible for company-wide security governance decisions and for planning and promoting information security management and personal data protection matters. EGAT has also established the Information Security Promotion Committee, convened by the President, to implement information security awareness among all employees through top-down cooperation and allocation of responsibilities. At the policy level, EGAT follows the spirit of ISO 27001 by documenting its information security management system and formulating the Information Security Policy and Information Security Management Manual as references for the Company's information security management. At the management level, EGAT sets information security measurement targets, regularly evaluates information security performance, and continuously improves through internal and external audits, corrective management, and management review meetings to ensure information security management effectiveness.

Investment in Information Security Management
| Item | Specific Management Approach |
|---|---|
| Item Information Security Measurement | Specific Management Approach
|
| Item Information Security Incident Management | Specific Management Approach
|
| Item Business Continuity Management | Specific Management Approach
|
| Item Network Security | Specific Management Approach
|
| Item Device Security | Specific Management Approach
|
| Item Application System Security | Specific Management Approach
|
| Item Data Protection Security | Specific Management Approach
|
| Item Emergency Response and Recovery Mechanism | Specific Management Approach
|
Information Security Training
In 2025, EGAT conducted the following information security training and provided corresponding courses for different employee groups to strengthen information security awareness.
| Training Topic | Training Description | Resources Invested |
|---|---|---|
| Training Topic Information Security Awareness Course | Training Description Deepen information security risk awareness among all employees to protect company digital assets and strengthen cybersecurity resilience. | Resources Invested 3,494 participants |
| Training Topic Social Engineering Protection | Training Description Strengthen employees' awareness and vigilance against phishing emails. | Resources Invested 3,383 participants |
| Training Topic Social Engineering Protection Training Course | Training Description Introduce common social engineering techniques and fraudulent email types to high-risk email user groups to improve employees' information security awareness. | Resources Invested 594 hours |
Information Security Reporting Channels
For EGAT employees, information security incident reporting methods are announced on the Company's internal portal, with clear reporting guidance to help employees promptly report and handle information security risk events.
Personal Data Protection
To protect customer rights and ensure that the Company's collection, processing, and use of personal data comply with the Personal Data Protection Act and relevant regulations, and to prevent personal data held by the Company from being stolen, altered, damaged, lost, or leaked, EGAT has established the Personal Data File Security Maintenance Plan, which details procedures for personal data protection. In 2025, EGAT had no information security or privacy-related complaints involving data breaches, customer privacy violations, or loss of customer data, and no data leakage occurred.

