Information Security & Data Privacy
Information Security Governance
Information Security Organization
Coway operates an executive-level Information Security Committee to establish robust governance over information security. The Committee is chaired by the Chief Information Security Officer (CISO), who satisfies the statutory qualification requirement of at least 10 years of professional experience in information security or IT pursuant to the 'Act on Promotion of Information and Communications Network Utilization and Information Protection.' Comprising heads of key relevant departments as members, the Committee deliberates on information protection policies and implementation directions under the leadership of the CISO. The Policy Security Team and the Technology Security Team oversee information security operations. They are responsible for establishing, implementing, and improving information security plans, as well as for conducting information protection audits, training and awareness programs, simulation drills, and system security management. Furthermore, Coway continuously reinforces its information security architecture and enhances data privacy standards through close interdepartmental collaboration, periodic monitoring, and proactive risk management.
Organizational Chart for Information Security
Key Organizations and Roles
Information Security Committee
The Coway Information Security Committee meets on a regular basis and continuously reviews amendments to applicable laws, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this process, Coway has taken proactive steps to apply any amendments promptly to its internal policies and processes. In 2025, Coway strengthened its disciplinary standards for security violations and advanced its security inspection and monitoring architecture, thereby elevating statutory compliance, operational stability, and customer trust.
2025 Key Activities and Achievements of the Information Security Committee
Information Security & Data Privacy Policy
Coway places the protection of customers' personal information as its top priority and maintains a systematic information protection management framework, with related regulations organized into a policy and guideline structure to ensure consistent application across operations. To respond to the rapidly changing information protection environment and business requirements, Coway periodically reviews related regulations and enacts or revises them as needed. In 2026, to strengthen information protection governance, Coway restructured the Information Security Committee and reinforced company-wide security inspections and continuous monitoring. By linking disciplinary procedures for violations with the Disciplinary HR Committee, Coway has enhanced accountability and execution. Reflecting the latest laws and changes in the work environment, Coway also revised 14 information protection guidelines and newly established one guide, thereby strengthening the related framework. By applying the same standards not only to internal organizations but also to the sales organization, outsourced contractors, and supply chain partners, Coway continues to reinforce its company-wide information protection framework.
Information Security Strategy
Information Security Management Framework
Mid- to Long-term Information Security Roadmap
Coway regards earning the trust of domestic and international customers as a core objective, maintaining a robust framework to proactively respond to internal operational risks as well as diverse external security threats. To this end, Coway has established a mid- to long-term information protection roadmap aimed at building an Information Security & Data Privacy Management System aligned with global standards, and continuously reviews and manages the status of its implementation.
Mid- to Long-term Information Security Roadmap
Information Security Risk Management
Information Security Risk Management Process
Coway manages information protection risks by classifying them into security incidents and IT disasters. Security incidents refer to incidents involving violations of security policies, such as information leaks and system breaches, while IT disasters refer to service interruptions caused by natural disasters, fires, and similar events. Security incidents are managed through preventive measures and incident response procedures. IT disasters are addressed by activating an Emergency Response Team. This ensures rapid recovery and business continuity.
Proactive Information Security Risk Prevention
Security Review
Coway carries out preventive activities—including risk assessments, the formulation of protective measures, and information protection training—based on a company-wide risk management framework designed to prevent security incidents. In particular, Coway operates a security review process that considers security from the system planning stage, reflecting information protection requirements in advance before new systems are built or services are launched. Through these preventive activities, Coway reviews and improves the appropriateness of personal information handling, system vulnerabilities, and compliance with security policies in advance, thereby minimizing potential risks.
Regular Information Security Risk Monitoring
To substantially elevate the level of information security and data privacy, Coway operates a range of regular monitoring activities year-round. Through field-oriented initiatives—such as malicious email response drills, clean desk campaigns, and security audits of entrusted partners—Coway proactively identifies and remediates security vulnerabilities across internal employees and supply chain partners alike. Going beyond simple inspections, Coway conducts tailored training programs aligned with each activity type, simultaneously preventing security incidents and fostering security awareness across the entire company.
2025 Key Activities and Achievements
Post-Incident Management of Information Security Risks
Personal Data Incident Response Process
To prevent the spread of damage and avoid secondary harm in the event of a personal information breach or information leakage, Coway has taken proactive steps to ensure a phased response tailored to each incident type. Personal data-related incidents are classified into Security Breach Incidents and Data Leakage Incidents (personal data leakage / internal proprietary data leakage), with optimized response measures established and operated in advance. Through continuous security monitoring and surveillance systems, any detected anomalies prompt immediate reporting of suspected security incidents to responsible personnel, while simultaneously activating an Incident Response Team (IRT) for swift initial action. Coway then carries out the following steps in sequence: fact-checking, evidence collection and preservation, and detailed analysis of the leakage path and its cause. Based on these findings, Coway establishes and implements recurrence prevention measures while promptly restoring services. The response process and outcomes are reported to the CEO and the CISO to support management's decision-making. The entire response process and outcomes are reported to the CEO and CISO to support executive decision-making. Furthermore, all response procedures are thoroughly documented and institutionalized as shared knowledge assets within the company. Lessons learned and leakage pathways are regularly disseminated through interdepartmental training, continuously reinforcing company-wide incident response capabilities.
Personal Data Incident Response Process
Post-Incident Management and Recurrence Prevention Framework
When a personal information incident occurs, the results of root-cause analysis derived during the incident handling process are translated into specific recurrence prevention measures and shared company-wide, ensuring that individual incidents are systematically managed to lead to organizational learning and the strengthening of management capabilities. Even after an incident, Coway continuously evaluates its security posture through ongoing security inspections and infrastructure vulnerability assessments. Furthermore, during the service operation stage, Coway conducts internal audits and policy compliance reviews to rigorously verify adherence to internal security standards and external regulatory requirements.
Coway also performs regular remediation activities for potential risks not identified through preventive measures, and in the event of a security incident or IT disaster, Coway activates a company-wide crisis management process to minimize damage and ensure business continuity, thereby protecting customer information and key assets. These post-incident management activities are systematically managed in accordance with personal information protection laws and internal standards.
Information Security Activities
Information Security Certifications
Coway has obtained certifications in information security and data privacy from accredited domestic and international certification bodies, validating the robustness of its information security management framework to external stakeholders. Rather than stopping at initial certification acquisition, Coway continuously evaluates the appropriateness of its management framework through annual surveillance audits and triennial recertification audits, driving ongoing enhancements aligned with the evolving security environment.
Information Security & Data Privacy Certification Status
Information Security Training
To enhance information protection awareness and security capabilities across all employees, Coway conducts company-wide information security training annually. In 2025, in addition to video-based training programs, Coway conducted on-site inspections and training of entrusted partners, raising the level of security management at field sales sites and elevating information security standards across all business operations.
In response to the recent increase in the use of generative AI services, the Information Security Office conducts continuous inspections and monitoring to prevent the external leakage of corporate information and security risks. To enhance employees' understanding of AI ethics and raise awareness of the safe use of AI, Coway also established and distributed the "Generative AI Usage Guide" company-wide. The guide includes key security rules that employees should observe when using AI services, such as the prohibition of inputting internal confidential data or personal data, as well as verifying copyright ownership and the credibility of generated outputs.
2025 Information Security Training
Information Security Campaign
To ensure that employees' security awareness translates into actual behavior in the workplace, Coway carries out information security campaigns continuously throughout the year. In 2025, with a focus on embedding security practices into daily operations, Coway executed various initiatives, including annual renewal reminders for the Information Security Pledge and guidance on compliant work practices.
2025 Information Security Campaigns
Information Security Investment
Coway recognizes information protection as a core management element rather than a cost, and continues to expand its investments to advance protection frameworks and reinforce threat response capabilities. Pursuant to the "Act on the Promotion of the Information Protection Industry," Coway has been designated as an entity subject to information protection disclosure obligations since 2022, and transparently discloses the overall information protection status, including investment scale, personnel, certifications, and key activities, on an annual basis. The purpose of the disclosure is to support a safe digital environment for users and to encourage companies to voluntarily invest in information protection. As of the end of 2025, Coway's investment in information protection totaled KRW 3.49 billion, accounting for 4.6% of its total IT budget. Key investment items include strengthening endpoint security through the adoption of an Endpoint Detection and Response (EDR) solution, as well as conducting on-site security audits of entrusted partners in collaboration with specialized security firms.
Safeguarding Personal Data Rights of Data Subjects
To enable data subjects to substantively exercise their rights regarding their personal data, Coway maintains a process framework that promptly responds to deletion requests and related grievances. In particular, Coway actively responds to requests received through the "e-Privacy Clean Service" operated by the Personal Information Protection Commission. This service enables data subjects to review their historical online registrations based on identity verification records and conveniently withdraw membership from unnecessary websites, thereby supporting autonomous data management. By continuously upgrading and expanding diverse intake channels, including external linkage channels, Coway is enhancing the level of protection for data subjects' rights.