Information Security Policies and Regulations
The Information Security Policy was most recently updated on March 2, 2023, approved by the Group Chief Financial Officer, covering aspects such as information system construction, user management, backup and contingency, equipment and network protection.
- Establish information system classification and protection standards.
- Prevent hacker intrusions, malware, and internal misuse.
- Prevent leakage of confidential information.
- Implement appropriate backup mechanisms and contingency plans.
- Ensure business continuity and disaster recovery capability.
- Strengthen information security management of outsourced services and supply chain monitoring.
- Enhance overall employee information security awareness and professional competence.

Cybersecurity Governance & Defense Framework
Governance &
Accountability
- Board Oversight: The Board serves as the highest oversight body, reviewing cybersecurity policies and monitoring performance reports regularly.
- Dedicated Personnel: Appointed 1 CISO and 1 dedicated cybersecurity officer to lead group-wide security, policy execution, and cross-departmental coordination.
- Internal Audits: Independent audit teams conduct regular cybersecurity and privacy assessments to embed compliance into daily operations.
Technical Defense &
Risk Management
- Multi-Layered Defense: Deployed firewalls, EDR systems, anti-phishing controls, data encryption, and off-site backups.
- Security Assessments: Perform group-wide vulnerability scans, penetration testing, and health checks to eliminate operational risks.
- Vendor Governance: Enforce strict access controls and require 100% of outsourced partners to sign NDAs and cybersecurity commitments.
Security Culture &
Workforce Defense
- Employee Training: Conduct annual security and privacy training for all staff, reaching 664 participants and 772 hours.
- Social Engineering Drills: Execute unannounced phishing simulations to sharpen employees' threat recognition and response capabilities.
Incident Response & Reporting Mechanism
We have established a robust incident response and reporting framework, implementing end-to-end closed-loop protection across six key stages to ensure operational continuity and customer data security:
1. Impact Assessment
Evaluating cybersecurity risks to reputation, customer trust, business continuity, and compliance to prioritize critical asset protection.
2. Management Goals
Targeting zero major security incidents while maintaining high system availability and disaster recovery readiness to safeguard data privacy.
3. Policy Commitments
Complying with privacy regulations under Board oversight to ensure a transparent, compliant, and trusted digital service environment.
4. Control Measures
Deploying firewalls, EDR, access controls, and backups alongside standardized incident SOPs and 100% vendor NDA compliance.
5. Evaluation & Audits
Conducting vulnerability scans, phishing simulations, and recovery drills, backed by independent audits reported directly to the Board.
6. Optimization
Updating policies based on threat intelligence and international standards, enhancing talent readiness, and strengthening supply chain defense.
Cybersecurity Performance & Zero-Incident Record
Silks Hotel Group continuously advances its cybersecurity management and personal data protection, achieving the following key performance results:
Key Performance Indicators (KPIs) | 2025–2026 Performance |
|---|---|
Major Cybersecurity Breaches & Losses | 0 incidents (Zero major cybersecurity breaches or financial losses incurred) |
Customer Privacy Violations & Data Loss Complaints | 0 complaints (Zero substantiated complaints regarding customer privacy violations or data loss) |
Dedicated Cybersecurity Personnel | 1 CISO and 1 dedicated cybersecurity officer appointed |
Security & Privacy Training Performance | 664 participants / 772 total training hours |
Security Testing & Vendor Compliance Rate | 100% vulnerability scans and penetration testing completed; 100% vendor NDA and security compliance rate |