Risk Management
- Home
- About HTY
- Risk Management
Risk Management
- Copied
Risk Management Mechanism
Hsin Tung Yang places great importance on identifying and managing the potential risks associated with its business operations. The Company conducts comprehensive risk assessments covering the organization as a whole, its manufacturing facilities, and all operating channels to identify and evaluate potential risks. Based on the nature of each risk, appropriate management mechanisms and corresponding mitigation measures are established to effectively control risks and strengthen preventive capabilities.
| Risk Identification Results and Response Actions | ||
|---|---|---|
| Risk Category | Risk Description | Response Actions |
| Climate Change and Natural Disaster Risk |
|
|
| Food Safety Risk |
|
|
| Regulatory and Compliance Risk |
|
|
| Market Competition Risk |
|
|
| Supply Chain and Operational Risk |
|
|
| Information Security Risk |
|
|
Crisis Management Mechanism
When a potential risk escalates into an actual crisis, the relevant departments immediately activate the Company's crisis management mechanism to ensure a timely and effective response. In the event of a major emergency, the President convenes a dedicated task force comprising the responsible departments to evaluate the situation and determine appropriate emergency response measures. The incident and the corresponding response are subsequently reported to the Chairman and the Board of Directors.
Information Security
Hsin Tung Yang has established a comprehensive information security management policy, covering the establishment of an organization-wide assessment mechanism, an information asset management mechanism, and the formulation and live drilling of an information security business continuity plan. It has also set up an Information Security Management Committee, responsible for determining the acceptable risk threshold and reviewing risk assessment results, risk improvement plans, and control measures. According to task requirements, four working groups have been established under the Committee to handle information security processing, document control, internal audit, asset inventory, and risk assessment.
Information Security Management Organization Structure
Information Security Management Measures
In accordance with the ISO/IEC 27001 Information Security Management System (ISMS), Hsin Tung Yang has established management procedures and implemented action plans to strengthen information security governance. The Company's annual information security initiatives include website vulnerability scanning, server vulnerability scanning, social engineering simulation exercises, and information security verification. Resources dedicated to information security management include:
- Comprehensive deployment of endpoint protection software to safeguard the information security of all endpoint devices.
- Engagement of professional consultants to perform vulnerability scanning of hosts and websites.
- Collaboration with external information security consultants to monitor the security and protection of information systems, with regular meetings to discuss information security issues.
Intellectual Property Management
Hsin Tung Yang regards its brands and trademarks as important core assets. Its intellectual property management measures include strengthening trademark registration and brand protection, establishing a trade-secret management system, promoting employee confidentiality agreements and training, introducing document classification and access control mechanisms, and complying with relevant regulations to avoid infringement risk. At the same time, the Company incorporates intellectual property management into corporate governance and integrates it with operating strategy, so as to enhance corporate competitiveness and brand value.
Protecting Customer Privacy
Hsin Tung Yang obtains member registration information through its online shopping website and in-store membership registration. It safeguards the security and privacy of customers' personal data through prior notification of and consent to the collection of personal data, the establishment of a tiered access-control system, strengthened information security protection, the implementation of employee confidentiality training and management of outsourced vendors, and compliance with data retention and destruction mechanisms.
Intellectual Property Management
The Company regards its brands and trademarks as core assets. Comprehensive intellectual property protection mechanisms have been established and closely integrated with its business strategy:
Customer Privacy and Data Protection
The Company protects the personal data of both online and in-store members by strictly implementing personal data protection mechanisms. In 2025, no incidents of reported violations related to integrity principles were recorded:
Supply Chain Security Protection
To prevent procurement activities and raw materials from threats and counterfeiting, the Company has strengthened contract reviews and supplier evaluation processes while establishing coordinated protection mechanisms:
- Copied