Information Security and Privacy
WNC upholds its contractual and confidentiality commitments to customers through its WNC Information Security Policy, which integrates processes, regulatory compliance, training, and technology safeguards. These measures protect information assets from misuse, disclosure, alteration, or destruction caused by natural disasters, malicious acts, or human error, ensuring their confidentiality, integrity, and availability and fulfilling commitments to shareholders, customers, suppliers, and employees.
WNC has fully implemented the ISO/IEC 27001 Information Security Management System (ISMS) and has adopted the Plan-Do-Check-Act (PDCA) management cycle. In October 2024, WNC successfully obtained certification for the transition to ISO/IEC 27001:2022. Currently, operations in Taiwan, China, Vietnam, and the United Kingdom have completed certification, and the certification scope has expanded to the Mexico site in 2026 to ensure the stability of global operations.
Information Security Committee
WNC established an Information Security Committee in 2014, with the President and CEO serving as Chairperson and the Chief Information Security Officer (CISO) designated as the convener. Management review meetings are held semi-annually:
WNC Information Security Protection Mechanisms
01 Risk management and drills
Conduct risk assessments, business impact analyses (BIA), and drills for disaster recovery plans (DRP) and business continuity plans (BCP)
02 Technical control and monitoring
Carry out vulnerability scanning, penetration testing, red team exercises, and firewall rule reviews on a regular basis
03 Access management and awareness training
Conduct user account and access rights reviews, periodic social engineering exercises, and information security awareness programs and training

Organziation Structure
Under the Committee, an Information Security Execution Team, Emergency Response Team, and Information Security Audit Team have been established, all of which are led by the CISO to carry out designated tasks. Information security has been incorporated into the Corporate Governance Task Force under the Sustainability Committee of the Board of Directors. The CISO delivers quarterly reports on progress and performance, ensuring information security governance.
- Chairperson President & CEO
- Convener Chief Information Security Officer
- Information Security Audit Team
- Information Security Implementation Team
- Emergency Response Team

System and Product Information Security Committee
In 2022, to strengthen the resilience of product information security, a System and Product Information Security Committee was established, which is composed of top-tier managers of each unit and chaired by the President & CEO. The aforementioned committee works in collaboration with the Information Security Committee to establish a dual oversight mechanism. Information security requirements are fully integrated into Secure Development Lifecycle (SDL) practices, covering end-to-end process controls from R&D to production testing. This ensures that the company’s products are capable of defending against potential vulnerabilities and reduces the risk of sensitive data leakage.
WNC obtained IEC 62443-4-1 certification in April 2024 and integrated its processes into the JIRA platform in December, automating cybersecurity vulnerability management. Based on project needs, the cybersecurity team conducts dynamic application security testing (DAST) on products and provides recommendations to product development teams on how to fix vulnerabilities, ensuring that all stages of the product lifecycle comply with security requirements.
- Chairperson President & CEO
- Members Top-tier supervisors of each unit
- Technical and Response Team
- Policy Formulation and Implementation Team
- Audit Team

Information security risk identification and response
WNC conducts risk assessments semi-annually. Sites identifying risks above acceptable levels are required to implement mitigation, improvement, or control enhancement measures. In 2025, WNC introduced red team exercises to identify potential risks through technical testing and validate the effectiveness of security controls. All assessment results are submitted to the Information Security Committee for review and approval of the Company’s risk acceptance levels. In 2025, WNC had no record of any lawsuits related to violations of confidential customer information, and there were no major cybersecurity incidents.
Systematize reporting and response mechanisms
- Incident classification and response timeframes: Incidents are classified as standard, major, or critical based on their impact. The designated intake team assesses the incident and activates the response team. Each level has defined resolution timeframes; incidents not resolved within the required timeframe are evaluated for escalation.
- External notification and disciplinary actions: When necessary, external parties impacted by the incident or the competent authorities will be notified. If human misconduct is involved, investigation and disciplinary procedures will be initiated.
- Preventive measures: After the information security incident has been resolved, the responsible unit must submit an improvement report, analyze the root cause of the incident, and propose preventive measures or relevant training programs. Through this feedback mechanism, WNC aims to reduce the risk of incident recurrence as well as ensure business continuity and a consistent level customer service.
Key information security work items in the last two years

Completed
- Established product security testing service items and develop standardized procedures
- Continued conducting red/blue team assessment
- Deployed factory-wide monitoring and alert response mechanisms for non-IT production networked devices
- Implemented cybersecurity control processes and mechanisms for WNC’s supply chain
- Optimized the suspicious activity detection and monitoring network (MDR/XDR)
- Established an endpoint suspicious behavior monitoring network

In progress
- Expand the scope of application of the information security operations center (SOC)
- Enhance correlation analysis and the depth of SOC monitoring
- Build and optimize an in-house SIEM monitoring platform
- Strengthen “blue team” information security talent
- Conduct red team exercises and in-depth vulnerability remediation
- Conduct cybersecurity compliance audits for all sites
- Enhance ISO 27001 certification and expand its scope to include the Mexico site
- Obtain TISAX VDA ISA 6.0 AL2 certification for automotive products
- Expand MDR coverage
- Formulate AI governance regulations
Supply chain information security management
WNC has established a lifecycle for supply chain information security risk management with reference to the core structure of the U.S. NIST Cybersecurity Framework 2.0. We screened 66 suppliers for in-depth cybersecurity assessments based on risk factors including supplier profile, system integration, data sensitivity, and transaction volume. The assessments cover seven domains — Governance, Identify, Protect, Detect, Respond, Recover, and Supply Chain Security — using 80 quantitative metrics to establish a cybersecurity baseline.
Supplier information security management is implemented using a three-tier classification system. For suppliers scoring below the average, WNC will implement a “tiered guidance and audit” mechanism. On-site or online audits began in 2026, and the aforementioned suppliers are required to meet the cybersecurity baseline by the end of 2027. By the end of 2026, WNC plans to integrate cybersecurity criteria into its supplier evaluation process alongside financial, sustainability, and quality indicators. This will ensure suppliers meet WNC’s cybersecurity risk tolerance from the outset of engagement and safeguard stakeholder information.
Establishing information security awareness
WNC instills information security awareness into its employees by conducting regular drills, improving areas of deficiency, and tracking the effectiveness of training. Semi-annual social engineering exercises are conducted across global operating sites and supported by real-world awareness campaigns on the internal portal to encourage prompt reporting of suspicious emails. Employees who click suspicious links or attachments during simulations are automatically assigned online training and required to pass an assessment. Through this dynamic approach, the social engineering simulation click rate fell significantly from 9.97% in 2024 to 6.2% in 2025, achieving the annual target of below 10%.

Participation in information security training courses in 2025
| Course | Participants | Number of employees completing the training | Training hours |
|---|---|---|---|
| Information security policies and regulations promotion | IDL | 4,180 | 1,184 |
| Information security general knowledge courses | IDL | 4,201 | 1,120 |
| Defenses against social engineering | Employees who fail phishing tests | 190 | 31 |
| Overview of TISAX VDA ISA 6.0 standards | TISAX certification unit personnel | 41 | 102.5 |
Privacy protection
- Personal data protection training course 3,853Attendances
- Training hours 643 Hours
- Indirect employees completion rate 96.2%
- 2025 Personal data breaches 0 Incident

WNC has established a cross-border personal data protection framework and publishes the WNC Privacy Policy on its website, outlining how personal data is processed and how data subjects can exercise their rights. In 2024, WNC established a cross-unit “Data Protection Group”, which holds quarterly meetings to ensure the effectiveness of its management framework. In addition, WNC undergoes annual ISO 27001:2022 external audits by SGS, covering privacy protection and personally identifiable information (PII) controls. Personal data protection is also incorporated into the annual internal audit program.
In 2026, WNC issued Personal Data Protection Management Regulations, consolidating and replacing previous policies to fully align with the EU General Data Protection Regulation (GDPR). The regulations standardize procedures for collecting, processing, and using personal data across global operations. They also introduce data lifecycle management and retention-period reviews, while maintaining flexibility to comply with local regulations. WNC performed well in the area of personal data protection, with zero incidents of personal data breaches in 2025.
To strengthen cybersecurity and privacy awareness, WNC launched dedicated personal data protection training in its Taiwan and China sites in 2025. The program reached 3,853 direct and indirect employees, totaling 643 training hours, with a 96.2% completion rate among indirect employees. In 2026, WNC formulated training courses catered to the needs of each site and gradually implemented the courses in the Vietnam and Mexico sites.
WNC has established a number of reporting and consultation channels to ensure that stakeholders can promptly exercise their rights and provide feedback on privacy-related issues:
- Mailbox for violation reporting: [email protected]
- Mailbox for submitting requests to exercise rights relating to personal data: [email protected]
- Mailbox to request personal data of job applicants: [email protected]