We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.
Annual Performance
During the year, the Company demonstrated steady growth across financial, governance, and sustainability dimensions. Net profit after tax reached NT$2.165 billion, representing an increase of 45.2% compared with 2023, reflecting improved operational efficiency and the gradual realization of market expansion results, and laying a solid foundation for continued investment in innovation and sustainability.
At the same time, the Company maintained its commitment to integrity governance, recording zero corruption incidents for the year, demonstrating sound internal control mechanisms and effective risk management, and successfully fostering a transparent and responsible corporate culture. In terms of ethical management, 15,902 participations were engaged in integrity management training, strengthening employees’ awareness of legal compliance, ethics, and professional conduct, and embedding integrity as a core value of daily operations. In response to increasingly severe information security threats, the Company also successfully passed ISO 27001 Information Security Management System certification, indicating that its information protection processes meet international standards and effectively safeguard the data security of customers and partners.
Overall, these achievements demonstrate the Company’s comprehensive progress in financial performance, integrity governance, gender diversity, and information security, laying a more solid foundation for sustainable development.
2.165 billion
Net profit after tax
0
Corruption incident
15902 attendances
Business integrity education and training
Information Security Management Policy
Information Security Management Organization
In accordance with the ISO 27001 international information security management standard, Sunon has comprehensively implemented its information security management system and established a cross-departmental and cross-functional Information Security Management Committee. The Chairman serves as the convener of the committee and has authorized the head of the information security department to serve as the Chief Information Security Officer, with dedicated responsibility for overseeing the Company's internal information security matters. At the same time, the Company has established an Information Security Implementation Team, Information Security Technology Team, and Information Security Audit Team to coordinate the formulation, review, and execution of information security management policies, and to implement information security risk management and compliance reviews.
The Information Security Management Committee regularly convenes information security management review meetings to review implementation status, and reports implementation results as well as review and improvement matters to the Board of Directors on a quarterly basis. In 2025, it reported to the Board four times. The main reporting items included information security governance measures, information security monitoring measures, information security testing measures, information security education and training activities, implementation of information security solutions, and planning of threat defense strategies.
The structure of the Company's Information Security Management Committee is shown below, with a total of 17 members.
- 董事會
-
- 資訊風險管理委員會
(總經理擔任召集人) -
- 行政單位
- 資訊單位
-
- 稽核小組
-
- 內部資安稽核
- 外部資安稽核
- 技術小組
-
- 網管人員
- 系統人員
- 建置小組
-
- 資訊安全管理
- 資料中心管理
- 各事業處主管
- 資訊風險管理委員會

Information Security Management Policy
To fully safeguard the confidentiality, integrity, and availability of operational information, Sunon has established an information security management policy as the basis for management, which applies to all personnel. The Company has also established the Personnel Security and Education and Training Procedures to ensure that all employees understand relevant information security requirements, apply them appropriately, and fulfill their protection responsibilities. The Company's information security management policy covers strengthening personnel capabilities, preventing data leakage, implementing routine operations and maintenance, and ensuring service availability. In addition, the Company has also established thematic policies on business continuity management, risk and opportunity assessment, and outsourced security management in order to comprehensively implement information security management and control mechanisms across various risk areas.
- Strengthen Personnel Capabilities
- Conduct information security education and training to promote personnel awareness of information security and strengthen their understanding of related responsibilities.
- Prevent Data Leakage
- Protect information related to the Company's business activities to prevent unauthorized access and modification and ensure its accuracy and completeness.
- Implement Routine Operations and Maintenance
- Conduct regular internal and external audits to ensure that relevant operations are effectively implemented.
- Ensure Service Availability
- Ensure that the Company's critical business systems maintain an appropriate level of system availability.
Information Security Management Mechanism
In response to the continuous evolution of external information security threats, the Company strengthens cloud login and access controls through defense-in-depth and joint protection mechanisms, and comprehensively enhances information security and personal data protection measures to prevent material information security incidents and regulatory penalties, safeguard the Company's information security reputation and operational stability, and regularly conduct information security drills and internal and external audits to strengthen real-time detection and response capabilities for information security incidents. At the same time, privacy and personal data protection are incorporated into the overall governance system to ensure compliance with relevant regulations and stakeholder expectations.
In addition, the Company regularly conducts information security awareness campaigns, social engineering email drills, and information security education and training to ensure that employees fully understand and jointly comply with information security requirements. For suppliers involved in information services and outsourced management, the Company incorporates information security into supplier management and contractual clauses, requiring suppliers to sign confidentiality undertakings and information security compliance commitment letters. Through audit, evaluation, and guidance mechanisms, the Company enhances the overall information security protection level of the supply chain, builds a resilient digital operating environment, and supports its sustainable development objectives.
Information Security Awareness and Education and Training
We have also established the Personnel Security and Education and Training Procedures, incorporating information security training into mandatory onboarding courses to ensure that 100% of new employees complete the training. Incumbent employees are also required to receive annual refresher training and undergo evaluation of training effectiveness. In 2025, total participation reached 14,701 person-times, with total training hours amounting to 3,995 hours. Through institutionalized management and diversified course activities, the Company continues to strengthen employees' information security awareness and embed security concepts into daily operations.
| Information Security Agreement | Signing Rate | 100% |
| Education and Training | Total Training Participations | 14,701 person-times |
| Total Training Hours | 3,995 hours | |
| Average Training Hours per Person | 0.5 hours |
ISO 27001 Information Security Management System
In addition to complying with domestic information security regulations, the Company’s information security operating procedures also incorporate international information security standards, with the aim of enhancing information security protection and aligning with global practices.
As of the end of 2024, Sunon’s Kaohsiung Headquarters, Kunshan Guangxing Plant, and Beihai Sunon Plant have all passed the international standard requirements for ISO/IEC 27001:2022 Information Security Certification. The Company will continue to strengthen its information security management mechanisms and defense capabilities, practice good corporate governance and corporate social responsibility, and enhance global customers’ trust in Sunon’s information security.
Annual Implementation Status
- ✓ Implementation status for Year 114
- ✓ Implementation status for Year 113
- ✓ Implementation status for Year 112
- ✓ Implementation status for Year 111
- ✓ Implementation status for Year 110
Information Security Reporting and Incident Management
The Company has established a comprehensive information security reporting and incident management mechanism and, for the response to and handling of information security incidents, has formulated the Security Incident Management Procedures, incorporating information security incidents as an important component of corporate governance and operational risk management. Through clear reporting procedures and graded handling principles, the Company ensures that all types of information security incidents can be reported promptly, handled appropriately, and followed up continuously for improvement, thereby reducing potential impacts on operations, customers, and stakeholders.
For the reporting and handling of information security incidents, we have clearly established information security reporting and handling procedures, and have set up a dedicated contact window and email mailbox for reporting information security incidents, vulnerabilities, or suspicious behavior. Once an information security incident report is received, the Information Security Team is responsible for handling the case, assigning the incident level, and eliminating and resolving the incident within the target handling timeframe. After the incident has been addressed, root cause analysis is conducted and corrective measures are taken to prevent recurrence. In 2025, the Company did not receive any information security incident complaints from competent authorities or third parties, and no material information security incidents occurred internally.

