台新新光金控

Sustainability Governance
Sustainability Governance

Information and Transaction Security

Information Security Management Mechanisms

Taishin FHC has established information security regulations such as the "Information Security Policy" and "Management Guidelines for Network Security Management" as guiding principles for the continued effectiveness of information security protection. It adopts the "Plan-Do-Check-Act" (PDCA) cycle operation model to establish an information security management system and continues to invest resources to maintain its effective operation and continuous improvement; clearly defines the rules for handling and protecting various information assets to enhance the reliability of information processing software and hardware, as well as the physical security maintenance of computer equipment; establishes an information security operation center (SOC) to strengthen security protection and obtain global intelligence to address security threats. The "Management Guidelines for IT Outsourcing" have been formulated for outsourced information
operations to standardize the information security requirements and scope of responsibility that third-party information service providers should comply with and improve the security management of projects.


The Company has established an "Information Security Committee" with Taishin FHC directors, Taishin FHC President, Taishin FHC chief information security officer, Taishin Bank President and first-level supervisors with information/security expertise as members. Meetings are held quarterly to discuss information security-related issues and improvement measures. The committee reports the overall information security governance and annual information security governance plan to the board members in the first half of each year, and reports the effectiveness of the information security plan in the second half of each year. The committee summarizes the latest information security threats and trends every six months, reports it to the Board of Directors, and obtains information security governance guidelines. The Information Security Committee held 4 meetings in 2024 and the attendance rate of directors was 100%.


The Company appointed a Chief Information Security Officer (CISO) as the highest level supervisor of informationsecurity, supervising company-wide information security operations and the effectiveness of information security management mechanisms. In order to improve the planning and management of information security risks from the perspective of business continuity management within the organization and enhance the overall information security maintenance capabilities, the Information Security Committee has established an "Information Security Specialist Team" composed of information security contact persons from various units. As seed members, they are responsible for promoting resolutions on information security matters and reporting the results of the promotion to the committee. The Information Security Department regularly convenes seed members to promote information security issues and related requirements to all employees of the Company in order to establish information security awareness among all employees.

 

The Information Security Department holds an Information Security Operations Review Meeting bimonthly, where the Chief Information Security Officer (CISO) reviews the execution status of various security tasks.

 

We have a director on the board and Cybersecurity / Information Security Committee with relevant background in IT engaged on the cybersecurity strategy process and someone in the Executive Management team who oversees the company’s cybersecurity strategy:

l   Name of board member: Mr.& Dr. Kuo, Jui-Sung

l   Relevant experience and previously held positions:

Dr. Kuo is an expert at information/information security; Professor of Department of Information Science, Business School, Soochow University; Professor of Department of Electrical Engineering, National Taiwan University; Chairman of TECO Technology Foundation; Director of TECO Image Systems; Supervisor of SerComm; Director of International Bank of Taipei; Director of Taishin FHC and Taishin Bank; Ph.D. in Physics, University of New Hampshire.

 

l   Name of Chief Information Security Officer (CISO): Jeff, Chen

l   Relevant experience and previously held positions:

Mr. Chen is an expert at information/information security; The Head of the Information Division at The Criminal Investigation Bureau of the National Police Agency, Ministry of the Interior ; Master's degree in Computer Science and Information Engineering from National Taiwan University of Science and Technology.

 

Information security management system certification

External Verification
Taishin's major subsidiaries and businesses have all obtained related international certifications for information security management system. Including banking, securities, and life insurance subsidiaries. Taishin Bank, Taishin Securities, and Taishin Life Insurances have obtained ISO 27001 Information Security Management System certification annually from 2010, 2022, and 2016, respectively, up until 2024 creating a safe and trustworthy information security environment, and protecting company assets and stakeholders' interests.

 

Taishin Bank attaches great importance to the security of customer personal information and obtained ISO 27701 Privacy Information Management System certification in 2024 to enhance personal data management and protection capabilities, strengthen information security control, and continue to provide more stable, safer, and higher-quality financial services while ensuring the security of data and safeguarding the rights and interests of customers.


Taishin Bank continues to obtain ISO 22301 business continuity management system certification. It ensures fast recovery of core business operations after a major disaster or incident in order to reduce impacts on stakeholders, financial markets, and the community and to fulfill Taishin's commitment to sustainability.

 

Internal Audit
Taishin regularly conducts IT inherent risk assessments, self-assessments and self-audits of projects and general matters, and continuously maintains and monitors various information security risk indicators to ensure that various security risks can be detected and addressed in a timely manner, thereby strengthening the information security internal control mechanism and improving the level of information security protection. In addition to the aforementioned initiatives, the internal audit of Taishin FHC and its subsidiaries conduct internal audits. In accordance with the Taishin FHC Internal Audit System, the company performs at least one general business audit annually and at least one special audit every six months for both the company and its subsidiaries. These audits include information security objects such as the formulation and implementation of information security policies, management of information and communication system security, server and network security management. The findings are compiled into an internal audit report and submitted to the Audit Committee for review.

Information Security Event Response Exercises

For the purpose of building a complete information security chain, Taishin gathers information security data, such as hacker techniques and latest threats and trends from around the world. Taishin also checks whether internal security measures are able to detect and respond in real time. Cyber Offensive and Defensive Exercise and social engineering drills based on hacker logic and techniques are conducted regularly to identify hidden risks and reduce attacks and exposures and improve overall information security. The FFIEC/CAT framework is used to assess the development of IT security governance. Drills in 2024 included distributed denial of service drills and red team drills. All drills were completed on time, and system vulnerabilities and the effectiveness of cybersecurity defense systems were checked on an ongoing basis. Taishin has the Computer Security Incident Response Team (CSIRT) working under Taishin FHC to coordinate financial information security defense and facilitate real-time access and support for response measures taken by the Company and its subsidiaries in information security incidents and to reduce damages. Furthermore, Taishin has purchased information security insurance to prevent escalated losses and reduce damages caused by information security incidents in order to protect company assets and rights.

Enhancement of Transaction Security

The rampant use of Internet fraud and fraud app by hackers for watering hole attacks, spear phishing attacks, and ransomware attacks in recent years have severely damaged the interests of customers of banks worldwide. Taishin Bank and major subsidiary had established multiple information security controls for the information system, internal and external network environments and online transaction sites. The security status are presented on the Security Operation Center (SOC) platform to assist security operator to enhance Taishin Bank's information security, providing real-time information security event monitoring services.

To enhance overall information security abilities, the Company deployed a number of information security measures and became a member of the Financial Information Sharing and Analysis Center (F-ISAC) to enjoy information security intelligence, warning, and joint defense services, so that we can plan preventive, detection, and corrective security controls. We signed a MOU with a domestic government agency in 2022 and joined the key infrastructure information security joint defense system, becoming a pioneer of the financial industry in participating in Taiwan's information security national team. This has allowed us to further strengthen the security of stakeholders and the overall financial environmen.

Transaction security protocols Description
  • Global digital corporate banking network
  • Enhancement of multiple security certification and transmission encryption protocols to ensure data protection.

  • Mobile devices
  • Use biometrics/account and password, and one-time passwords to provide rapid, convenient, and secure NFC sensing applications and remote credit card transactions.

  • Electronic channels
  • Use mobile device binding, real-time payment notification SMS, transaction detection system, and other transaction verification protocols.

  • Transaction website and app
  • Introduce anti-phishing detection services to reduce significant numbers of fraudulent websites and apps to protect consumers' transaction security.

Information Security Promotion and Information Security Incident

1. Information Security System

  • Information security awareness training

    • All employees of Taishin receive at least 3 hours of "information security awareness training" courses and evaluations each year. The contents include regulations, social engineering, basic information security awareness, customer personal information protection, and case studies of information security incidents which help enhance information security. The training coverage rate and completion rate in 2024 were both 100%.
    • The Information Security Department issues information security notices to all employees of the Bank based on current events involving information security to continue to enhance their information security awareness.
  • Professional information security training

    • All employees of dedicated information security units have completed (e.g. bank) have completed at least 15 hours of external training based on the requirements for their operations to enhance their professional information security skills.
    • Information security contacts of all units are invited to attend professional information security training courses provided by external professionals to strengthen the information security capabilities of all units.
  • Social engineering drills

    • 4 social engineering drills such as simulated phishing email tests are implemented for employees of the Bank on an irregular basis each year. The test results are analyzed to identify employees with insufficient information security incidents to enhance training and reduce the risks of potential vulnerabilities.

2. Supplier Management

Taishin FHC has a set of” Information Service Outsourcing Guidelines” in place that outlines the standard operating procedures and rules concerning outsourcing of information service.  Taishin Bank has the IT Outsourcing Guidelines in place to provide the standard operating procedures and rules for IT outsourcing, which covers outsourcing custody of computer hardware/software and outsourcing IT processes and services. To ensure security and feasibility of outsourcing, the persons in charge of the bank's projects and the relevant personnel of the Information Technology Division will perform full and rigorous supplier evaluation, and assess the access risk in selected suppliers and perform background or credit checks as needed in order to ensure the quality and security of internal operation and protect the rights of the bank and its customers.

3. Information Security Incident Reporting and Handling

Taishin FHC has implemented the "Taishin FHC Information Security Incident Management Guidelines" to establish the reporting and response procedures for information security incidents. The Company and its subsidiaries will each consider the scope and severity of impact of information security incidents and proceed to determine and analyze such incidents. For example, major information security incidents will be reported to the supervisors in charge as well as Taishin FHC Chief Information Security Officer and Chief Information Office. The information security response procedures will be carried out for incident management, cause confirmation and correction, service restoration, and review and improvement in order to reduce hazards and losses. Taishin adheres to the domestic regulatory requirements as well as local regulatory requirements in other countries, and checks and reports compliance regularly to the local competent authorities.


In 2024, two cybersecurity incidents related to system-related data breaches occurred at subsidiaries of Taishin. Upon investigation and follow-up, the first incident was found to be caused by the exploitation of a web vulnerability. In collaboration with the information security team and external digital forensics experts, it was confirmed that the incident did not result in operational disruptions or data tampering. Traffic analysis showed no evidence of breaches involving customer personal data breaches. The vulnerability has been remediated, and monitoring and alert mechanisms have been reinforced to prevent recurrence. The second incident involved irregularities in the mailing addresses of dunning letters and errors in credit card statement data. In response, internal controls and operational procedures have been enhanced, and pre-event, in-process, and postevent verification mechanisms have been established to prevent recurrence.

Questionaire

Questionaire

You are invited to fill in the questionnaire to assist us realizing the CSR fulfillment.

您正在離開本站!

您現在欲前往的網站並非搜尋結果台新新光金融控股股份有限公司有限公司(本公司)所有,而是各由其所屬之第三人所有、操縱及控制。 本站對第三人所有之網站亦無任何操縱或控制的權限。 本站上之網路指示連結功能僅為提供您的便利而設。本站及本公司對該第三人所有之網站上的內容品質、效力、正確性、完整性、即時性、適法性,及該網站上之任何言論或聯結不負任何責任。 本站及本公司亦無調查、監視第三人所有的網站上的內容之品質、效力、正確性、完整性、即時性、適法性的義務。本站上之網路指示連結功能無論於任何情形下,不能解釋成為對任何第三人網站的保證、背書、推薦或相類的聲明。 本站及本公司特於此明確宣示對於任何第三人所有網站之內容的品質、效力、正確性、完整性、即時性及適法性不負任何明示或默示的擔保責任。

即將前往的網址 : https://www.tsholdings.com.tw/news/news_04.jsp?newspage=01&readYear=2020&rowid=24441

公告

台新金控與新光金控合併案,業經金融監督管理委員會核准,並已訂定114年7月24日為合併基準日。合併後,台新金控為存續公司(合併後更名為「台新新光金控」)、新光金控為消滅公司。台新金控將以「客戶權益」為優先,兩家金控合併後,所有台新金控旗下子公司客戶的往來的權益及一切權利義務不變,不會因本合併案而受到任何影響,客戶無需做任何變更申請,敬請放心。若您有任何疑問,歡迎洽詢您的業務代表或撥打以下客服專線: 台新銀行: (02)2655-3355、台新證券: (02)4050-9799、台新人壽: (02)2171-1132、台新投信: (02)2501-3838,我們將竭誠為您服務。再度感謝您的長期支持,更期待您未來繼續惠予指導。

很抱歉,您目前使用的瀏覽器無法支援瀏覽。

建議您升級瀏覽器,以利瀏覽此網站的所有內容,謝謝您的配合。

© 台新新光金融控股股份有限公司版權所有

建議瀏覽器:IE10+, Chrome, Safari, Firefox