| Report to the Board of Directors |
The Cyber security team reports on information security work to the Board of Directors at least once a year. The content of this year's information security report was completed and reported to the Board of Directors on August 22, 2025.
|
| Cyber security management policies |
- Allocate appropriate resources to establish an information security management mechanism, strengthen employees' awareness of information security, and ensure that all employees have the responsibility and obligation to protect the security of the information assets they are responsible for or use.
- Authorize appropriately and only grant employees necessary permissions and information to complete their work, to prevent intentional or unlawful acts, and ensure the confidentiality, integrity, and availability of the company's important information assets.
- The Company's information security measures shall comply with the Company's information security policy and related information security management methods, and shall comply with legal and regulatory requirements.
- When an information security incident occurs, it shall be handled in a timely and appropriate manner with an appropriate response.
|
| Specific Management Plans and Implementation Status for the Current Year |
The Company places great emphasis on information security management, continuously optimizing and establishing various management measures. In 2025, the main resources invested in information security management are as follows:
- Entrusted a certification body to conduct a network security level protection assessment of the CRM membership system, including physical data center environment, application system security, network perimeter protection, and security management controls. A total of 30 working days were invested, with costs of RMB 276,000.
- To enhance employees’information security awareness, the Company conducted organization-wide cybersecurity training, with each employee participating for approximately 1 hour.
- Security personnel participated in online training programs totaling 35 hours, with costs of RMB 11,500.
- The Company continuously revised and updated its information security management policies, requiring 6 working days.
- An annual information and communication risk assessment was conducted, requiring 15 working hours.
- Email security was strengthened through the upgrade of the email firewall to filter inbound and outbound messages, involving 17 working days and costs of RMB 160,000.
- End-user internet access controls were enhanced by upgrading the web access behavior management system and adjusting access policies, involving 8 working days and costs of RMB 96,600.
- Vulnerability scanning and assessment were conducted on all network servers and web services, with identified vulnerabilities tested and remediated, requiring 25 working days.
- A comprehensive review and validation of user accounts and access privileges across all systems were performed, requiring approximately 40 working days.
- File server management was strengthened through a review and verification of folder and file access permissions, requiring 12 working days.
- Systems and databases containing personal data were reviewed for privacy information. Access controls are strictly enforced, and no leakage risks were identified. This required 30 working days.
- Three internal and external information security audits were conducted, with no material deficiencies identified.
|