Information Security

Information Security Management System

Information Security Organization

To proactively respond to increasingly sophisticated cyber threats and the risk of information leakage, HL D&I Halla has established and operates an information security management system based on a dual-accountability structure reporting directly to the CEO. The Chief Privacy Officer (CPO) oversees the secure management of personal information throughout its collection, processing, and retention, as well as the prevention of and response to personal information breaches. The Chief Information Security Officer (CISO), who concurrently serves as the Chief Location Information Officer, is responsible for information security across the Company, ranging from the establishment of company-wide security policies and the enhancement of employees’ security capabilities to the management of technical vulnerabilities. In particular, the CISO maintains close coordination with the HL Group Security Council and the security councils of its subsidiaries, enabling the Company to manage information security in an integrated manner and maintain a consistent group-wide security response framework. Based on this systematic organizational structure, HL D&I Halla will continue to strengthen the protection of employees’ personal information and the secure management of corporate information assets.

Information Security Organizational Chart

Information Security Policy

Under the leadership of the Chief Privacy Officer (CPO) and Chief Information Security Officer (CISO), HL D&I Halla has established and operates an information security management system based on its Security Management Regulations. The Company focuses on the systematic and effective protection of key information assets, including corporate information and personal information, while continuously advancing its security framework by regularly reviewing and revising its security management regulations to proactively respond to increasingly sophisticated cyber threats and changes in laws and regulations. In 2025, the Company promptly responded to the changing external environment by revising its Guidelines for the Operation and Management of Fixed Video Information Processing Devices on its website to reflect the latest operational practices HL D&I Halla also strictly complies with domestic and international laws and regulations related to personal information protection. To ensure that all stakeholders can clearly understand its personal information protection policies, the Company transparently discloses the key elements of its personal information processing policy in an easily accessible format through both the corporate website and the EFETE brand website. HL D&I Halla will continue to create a secure and trusted information protection environment through systematic information security management and ongoing security enhancement activities.

Key Personal Information Processing Labels

Information Security Incident Response System

Security Incident Response and Handling System

HL D&I Halla works closely with the HL Group Data Center (GDC) to strengthen information security by conducting preventive activities and regular security inspections. Through these efforts, the Company continuously maintains system stability and has established a framework for preventing security incidents. In the event of an information security incident, HL D&I Halla responds promptly in accordance with the “Security Incident Management” standards stipulated in its Security Management Regulations. Following the completion of remedial measures, the Company conducts a thorough analysis of the cause of the incident in close cooperation with GDC and systematically develops measures to prevent the recurrence of similar incidents.

Types of Security Incidents

Security Incident Handling Process

Information Security Activities

HL D&I Halla has strengthened the trust of customers and stakeholders through compliance with information security-related laws and regulations and systematic management activities. From an institutional perspective, the Company has enhanced the effectiveness of its information security policies and improved transparency for stakeholders by responding flexibly to changes in laws and regulations and continuously advancing its compliance system. To strengthen employees’ security capabilities, HL D&I Halla has focused on embedding security as a personal responsibility and an integral part of its organizational culture by organically linking education, training, and signed pledges. Through these efforts, the Company seeks to proactively minimize internal information security risks. In terms of threat detection and response, HL D&I Halla conducts continuous monitoring and regular risk assessments to identify potential threats at an early stage. The Company also focuses on building practical response capabilities to ensure prompt action against external emergency threats.

2025 Information Security Activities

Category Detailed Activities
Strengthening the Institutional Foundation Revised the guidelines for the operation and management of fixed video information processing devices on the website
Responded to information security disclosure requirements and obtained personal data protection liability insurance
Strengthening Employees’ Security Capabilities Conducted an information security awareness campaign
Conducted phishing email simulation training twice a year to raise employees’ security awareness
Provided customized security training by position
Required the submission of security and compliance pledges
Strengthening Threat Detection and Response Conducted monthly inspections of access logs for personal information processing systems
Inspected the account status of security equipment and solutions
Implemented follow-up measures based on information security risk assessments
Responded to emergency security inspection requests from the Ministry of Science and ICT
Performed emergency security updates for zero-day vulnerabilities

Internalization of Information Security

Information Security Training

Information Security Enhancement Campaign

HL D&I Halla regularly provides information security and personal information protection training at least once a year to all employees to raise information security awareness. The Company also conducts campaigns and job-specific training in parallel to enhance the practical effectiveness of its education programs. In May 2025, HL D&I Halla conducted an information security enhancement campaign to improve employees’ awareness of security incident prevention rules. In July, the Company provided an information security workshop and personal information protection training for quality managers who handle critical quality data related to customers and subcontractors and perform site-based duties, thereby strengthening security response capabilities tailored to their job characteristics.

Security Incident Prevention Guidelines

Set a password on the PC

Install mandatory security programs

Do not install illegal software or games

Do not mine cryptocurrency

Turn off the PC before leaving work

Phishing Email Simulation Training

HL D&I Halla conducted phishing email simulation training twice, on June 5 and October 31, 2025, to minimize the possibility of security breaches. As part of its preventive activities against the growing threat of email-based cyberattacks, the training was designed to help employees identify the key characteristics of phishing emails and become familiar with appropriate response procedures. Along with the training, HL D&I Halla distributed guidance materials containing key checkpoints for identifying phishing emails, including verification of the sender’s email address and country-code domain, inspection of URLs contained in the body of the email, identification of spelling and grammatical errors in the subject line and body text, and checks for attachments with unclear extensions. Through these materials, the Company strengthened not only participants’ awareness but also their practical response capabilities. Employees were also instructed on specific response procedures, including immediately disconnecting from the network after clicking a phishing email, conducting a full scan using antivirus software, and promptly reporting the incident to the IT manager.

Phishing Email Simulation Training

Response Activities for Personal Information Leakage Incidents

Liability Insurance and Technical Protection Measures

HL D&I Halla carries out preventive and response activities in preparation for unexpected personal information leakage incidents. The Company purchases personal information protection liability insurance every year to cover potential legal liability for damages arising from the leakage, loss, theft, or damage of personal information. In the event of an incident, this insurance contributes to protecting the rights of data subjects and providing remedies for damage. In December 2025, HL D&I Halla also strengthened its technical protection measures by performing emergency Windows security updates to proactively address zero-day¹⁾ security vulnerabilities.

1) Zero-day: A security vulnerability that may be exploited before, or immediately after, the manufacturer distributes a security patch

Preemptive Response to Information Leaks and Cybercrime Related to Sales Websites

HL D&I Halla plans to further strengthen its management system for protecting customers’ personal information in response to the growing number of cyber threats targeting the construction and real estate sales industry, including the creation of fraudulent sales websites. The Company currently conducts monthly log inspections and reviews download records for its sales management system. Going forward, the scope of inspection will be expanded to include the customer service website and the EFETE brand website, establishing a continuous monitoring system covering major personal information processing systems. HL D&I Halla also plans to progressively advance its technical protection measures by strengthening access rights management through system account reorganization, additionally developing log records for downloads of personal information files, and introducing secondary authentication for personal information downloads. Through these measures, the Company will securely protect customer information from internal and external threats and further strengthen stakeholder trust.

Personal Information Protection Management Plan