Next-Gen Thermal Solution

In this era of relentless AI evolution, technology relies on a force often overlooked,

yet never absent—Thermal Management.

We believe that every kilowatt saved and every cooling innovation is a gift of choice for the next generation.

SUNON—The artistry of air and water, for your everyday.

Corporate Governance

Corporate Governance

Annual Performance

During the year, the Company demonstrated steady growth across financial, governance, and sustainability dimensions. Net profit after tax reached NT$2.165 billion, representing an increase of 45.2% compared with 2023, reflecting improved operational efficiency and the gradual realization of market expansion results, and laying a solid foundation for continued investment in innovation and sustainability.

At the same time, the Company maintained its commitment to integrity governance, recording zero corruption incidents for the year, demonstrating sound internal control mechanisms and effective risk management, and successfully fostering a transparent and responsible corporate culture. In terms of ethical management, 15,902 participations were engaged in integrity management training, strengthening employees’ awareness of legal compliance, ethics, and professional conduct, and embedding integrity as a core value of daily operations. In response to increasingly severe information security threats, the Company also successfully passed ISO 27001 Information Security Management System certification, indicating that its information protection processes meet international standards and effectively safeguard the data security of customers and partners.

Overall, these achievements demonstrate the Company’s comprehensive progress in financial performance, integrity governance, gender diversity, and information security, laying a more solid foundation for sustainable development.

2.165 billion

Net profit after tax

0

Corruption incident

15902 attendances

Business integrity education and training

Information Security Management Policy

Amid accelerating digital transition and increasingly diverse information security risks, information security, privacy protection, and personal data protection have become indispensable core issues for sustainable corporate operations. We fully recognize that the confidentiality, integrity, and availability of information assets are directly related to operational resilience, customer trust, and long-term competitiveness. Accordingly, we must further strengthen our overall protection capabilities and ability to respond to complex threats by establishing a rigorous information security governance framework, institutionalized risk control mechanisms, and ongoing information security education and training, while building our management system in accordance with the ISO 27001 international information security management standard. At the same time, privacy and personal data protection are evolving toward a dual-track governance model that places equal emphasis on regulatory compliance and ethics. The Company has incorporated relevant policies and management mechanisms into its corporate governance framework to ensure compliance with regulatory requirements and respond to stakeholder expectations regarding data security and privacy protection, thereby laying a solid foundation for sustainable development.

Information Security Management Organization

In accordance with the ISO 27001 international information security management standard, Sunon has comprehensively implemented its information security management system and established a cross-departmental and cross-functional Information Security Management Committee. The Chairman serves as the convener of the committee and has authorized the head of the information security department to serve as the Chief Information Security Officer, with dedicated responsibility for overseeing the Company's internal information security matters. At the same time, the Company has established an Information Security Implementation Team, Information Security Technology Team, and Information Security Audit Team to coordinate the formulation, review, and execution of information security management policies, and to implement information security risk management and compliance reviews.

The Information Security Management Committee regularly convenes information security management review meetings to review implementation status, and reports implementation results as well as review and improvement matters to the Board of Directors on a quarterly basis. In 2025, it reported to the Board four times. The main reporting items included information security governance measures, information security monitoring measures, information security testing measures, information security education and training activities, implementation of information security solutions, and planning of threat defense strategies.

The structure of the Company's Information Security Management Committee is shown below, with a total of 17 members.

董事會
資訊風險管理委員會
(總經理擔任召集人)
行政單位
資訊單位
稽核小組
內部資安稽核
外部資安稽核
技術小組
網管人員
系統人員
建置小組
資訊安全管理
資料中心管理
各事業處主管

 

ISRMC Chart

Information Security Management Policy

To fully safeguard the confidentiality, integrity, and availability of operational information, Sunon has established an information security management policy as the basis for management, which applies to all personnel. The Company has also established the Personnel Security and Education and Training Procedures to ensure that all employees understand relevant information security requirements, apply them appropriately, and fulfill their protection responsibilities. The Company's information security management policy covers strengthening personnel capabilities, preventing data leakage, implementing routine operations and maintenance, and ensuring service availability. In addition, the Company has also established thematic policies on business continuity management, risk and opportunity assessment, and outsourced security management in order to comprehensively implement information security management and control mechanisms across various risk areas.

  1. Strengthen Personnel Capabilities
    • Conduct information security education and training to promote personnel awareness of information security and strengthen their understanding of related responsibilities.
  2. Prevent Data Leakage
    • Protect information related to the Company's business activities to prevent unauthorized access and modification and ensure its accuracy and completeness.
  3. Implement Routine Operations and Maintenance
    • Conduct regular internal and external audits to ensure that relevant operations are effectively implemented.
  4. Ensure Service Availability
    • Ensure that the Company's critical business systems maintain an appropriate level of system availability.

Information Security Management Mechanism

The Company has established a comprehensive information security management mechanism and built its Information Security Management System (ISMS) in accordance with the ISO 27001 standard. In conjunction with the Personal Data Protection Act, the Enforcement Rules of the Personal Data Protection Act, and the Cybersecurity Governance Guidelines for TWSE/TPEx Listed Companies, implementation is supervised by the Chairman and the Chief Information Security Officer. Through a cross-departmental information security governance structure, the Company clearly defines authority, responsibilities, and management processes. The Company regularly conducts information asset inventories, risk assessments, and vulnerability scans, and formulates appropriate protective measures and improvement plans accordingly to ensure the confidentiality, integrity, and availability of information assets.

 

In response to the continuous evolution of external information security threats, the Company strengthens cloud login and access controls through defense-in-depth and joint protection mechanisms, and comprehensively enhances information security and personal data protection measures to prevent material information security incidents and regulatory penalties, safeguard the Company's information security reputation and operational stability, and regularly conduct information security drills and internal and external audits to strengthen real-time detection and response capabilities for information security incidents. At the same time, privacy and personal data protection are incorporated into the overall governance system to ensure compliance with relevant regulations and stakeholder expectations.

 

In addition, the Company regularly conducts information security awareness campaigns, social engineering email drills, and information security education and training to ensure that employees fully understand and jointly comply with information security requirements. For suppliers involved in information services and outsourced management, the Company incorporates information security into supplier management and contractual clauses, requiring suppliers to sign confidentiality undertakings and information security compliance commitment letters. Through audit, evaluation, and guidance mechanisms, the Company enhances the overall information security protection level of the supply chain, builds a resilient digital operating environment, and supports its sustainable development objectives.

Information Security Awareness and Education and Training

Through monthly information security awareness emails, Sunon continuously enhances employees' awareness of and vigilance toward information security. In addition, the Company requires all employees to sign information security agreements, achieving a 100% signing rate, in order to strengthen personnel awareness of information security responsibilities.

 

We have also established the Personnel Security and Education and Training Procedures, incorporating information security training into mandatory onboarding courses to ensure that 100% of new employees complete the training. Incumbent employees are also required to receive annual refresher training and undergo evaluation of training effectiveness. In 2025, total participation reached 14,701 person-times, with total training hours amounting to 3,995 hours. Through institutionalized management and diversified course activities, the Company continues to strengthen employees' information security awareness and embed security concepts into daily operations.

 

Information Security Agreement Signing Rate 100%
Education and Training Total Training Participations 14,701 person-times
Total Training Hours 3,995 hours
Average Training Hours per Person 0.5 hours

ISO 27001 Information Security Management System

 

In addition to complying with domestic information security regulations, the Company’s information security operating procedures also incorporate international information security standards, with the aim of enhancing information security protection and aligning with global practices.

 

As of the end of 2024, Sunon’s Kaohsiung Headquarters, Kunshan Guangxing Plant, and Beihai Sunon Plant have all passed the international standard requirements for ISO/IEC 27001:2022 Information Security Certification. The Company will continue to strengthen its information security management mechanisms and defense capabilities, practice good corporate governance and corporate social responsibility, and enhance global customers’ trust in Sunon’s information security.

 

Annual Implementation Status

Implementation status for Year 114
Implementation status for Year 113
Implementation status for Year 112
Implementation status for Year 111
Implementation status for Year 110

 

Information Security Reporting and Incident Management

The Company has established a comprehensive information security reporting and incident management mechanism and, for the response to and handling of information security incidents, has formulated the Security Incident Management Procedures, incorporating information security incidents as an important component of corporate governance and operational risk management. Through clear reporting procedures and graded handling principles, the Company ensures that all types of information security incidents can be reported promptly, handled appropriately, and followed up continuously for improvement, thereby reducing potential impacts on operations, customers, and stakeholders.

 

For the reporting and handling of information security incidents, we have clearly established information security reporting and handling procedures, and have set up a dedicated contact window and email mailbox for reporting information security incidents, vulnerabilities, or suspicious behavior. Once an information security incident report is received, the Information Security Team is responsible for handling the case, assigning the incident level, and eliminating and resolving the incident within the target handling timeframe. After the incident has been addressed, root cause analysis is conducted and corrective measures are taken to prevent recurrence. In 2025, the Company did not receive any information security incident complaints from competent authorities or third parties, and no material information security incidents occurred internally.

We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.

Manage Cookies

Privacy Preference Center

We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.

Privacy Policy

Manage Consent Settings

Necessary Cookies

Enable All

The operation of the website relies on these cookies, and you cannot disable them in the system. These cookies are usually set based on the actions you take (i.e., service requests), such as setting privacy preferences, logging in, or filling out forms. You can configure your browser to block or prompt you about these cookies, but this may cause certain website functionalities to not work.

Functional Cookies

These cookies allow for enhanced features and personalized content, such as videos and live chat. We or third-party providers that we have added to our page can set these cookies. If you do not allow the use of these cookies, some or all functionalities may not work properly.

Marketing Cookie

Marketing cookies can be used to track visitors' journeys on websites. The purpose is to display ads that are relevant to individual users or attract them, making it more important for publishers or third-party advertisers.

Targeted Cookie
These cookies are set by advertising partners through our website. These companies may use cookies to build your interest profile and show you relevant ads on other websites. They only need to identify your browser and device to function. If you do not allow the use of these cookies, you will not be able to experience targeted ads on different websites.

Social media cookie
These cookies are set by a range of social media services that we have added to the website, allowing you to share our content with friends and networks. They can track your browser across other websites and build a profile of your interests. This may affect the content and messages you see when visiting other websites. If you do not allow these cookies, you may not be able to use or view these sharing tools.