Material Topics
Information and Cyber Security
Impact Level
Impact Materiality : Very High
Financial Materiality : Medium
Stakeholders
Shareholder
Business Partner
Customer
Employee
Investor
Public Sector

SDGs Targets

Long-Term Targets 2025
Targets Progress
Zero incidents of information security and cybersecurity attacks resulting in damage to the company 0 0 0
Time to detect attacks is less than the global median* Less than 11 days Less than 11 days Less than 11 days

* Global median dwell time is 11 days (Source: FireEye Mandiant: M-Trends Report 2025)

Challenges and Opportunities

Currently, business operations increasingly apply digital technologies across both production systems and operational networks, which are connected to the internet. Also, employees have adapted to working through a work from anywhere approach. These factors may increase the risk of cyber threats, such as the theft of critical data or disruption of key information technology systems. Such incidents could impact business continuity, reliability, corporate image, and the company’s reputation.

To enhance system preparedness and strengthen information technology security measures, GC has implemented prevention, detection, and analysis of potential cyberattacks through its service channels, covering both on-premise and cloud protection. In addition, the GC conducts vulnerability assessments of its systems.

In this regard, GC implements an information security management system that is aligned with the IT security policies, while also developing employee capacity at all levels to be aware of and capable of applying proper mitigation measure against cybersecurity threat.

Management Approach GRI 3-3 (2021)

Cybersecurity Governance

To establish clear operational direction and and create transparency at policy management and operation levels, GC has implemented an information security management system and personal data security managament in accordance with GC’s strategic plan and cyber-related international standard ISO/IEC 27001:2022, ISO/IEC 27701:2019, and National Institute of Standards and Technology (NIST) framework, covering all six areas of operation, namely Govern, Identify, Protect, Detect, Respond and Recover.

Information Security/Cybersecurity Management Guideline and Process according to NIST Cyber Security Framework

The management hierarchy can be divided into three levels: (1) Governance level, (2) Management level, and (3) Operational level. GC has established a cybersecurity unit to enhance the effectiveness of information security and cybersecurity management.

Role Relevant Committee/Department
Governance level
  • Develop and review of information security and cybersecurity strategies
  • Govern and manage IT operations
  • Board Level Audit Committee
  • GC Group’s Digital & IT Steering Committee (DISC)
  • Digital and Information Technology Investment Management Committee
  • Enterprise Risk Management Committee
  • Information Security Management System Committee (ISMSC)
Management Level
  • Manage technology infrastructure to meet usage needs and keep up with international standards
  • Manage information and personal data security according to ISO standards
  • Monitor and verify accuracy and precision
  • Enterprise Architecture Committee
  • Cybersecurity Department
Operation Level
  • Establish systems, procedures, and services for users to comply with
  • Assess performance monitoring and report risks to the Enterprise Risk Management Committee
  • Cybersecurity Department

Moreover, GC has appointed the Senior Vice President – Transformation Excellence to serve as Chief Information Security Officer (CISO), with the following roles and responsibilities:

AI Governance and Responsible AI

As GC accelerates the adoption of artificial intelligence and Generative AI across operations from data analysis and process optimization to content generation and customer engagement these technologies introduce new categories of risk alongside their benefits, including data privacy exposure, algorithmic bias, misinformation, and the environmental cost of computing infrastructure. Left unmanaged, these risks could affect data security, business reputation, regulatory compliance, and stakeholder trust.

To capture the benefits of AI responsibly, GC has established an AI Policy and supporting usage guidelines that set out clear principles, defined boundaries, and a structured approval process for the use and development of AI across the organization, while building employee capability to use these tools safely and ethically.

GC has established clear boundaries for the use of AI to ensure it is applied responsibly, ethically, and in accordance with applicable laws and regulatory requirements. AI is intended to support innovation, operational efficiency, and business decision-making, while maintaining appropriate human oversight. AI must not be used in a manner that compromises information security, privacy, intellectual property rights, or applicable legal and ethical requirements. The use of AI involving internal-use, confidential, or strictly confidential Company information, or information subject to disclosure approval, is restricted and must comply with the Company's AI Policy and related guidelines. Personnel remain accountable for reviewing AI-generated outputs and for decisions made based on such outputs.

GC's approval framework defines four levels of use:

  • Permitted without approval: use of approved internal or public generative AI tools for general tasks that do not involve internal-use, confidential company information, including answering questions, translation, content generation, and formatting, in accordance with AI Policy and related guidelines.
  • Requiring approval from the relevant business unit: submitting company information classified as confidential, or otherwise subject to disclosure approval, to an internal Generative AI tool.
  • Prohibited outright: any use through internal or public Generative AI tools involving inaccurate or inappropriate content, or confidential and sensitive information.

GC develops and uses AI with consideration for environmental sustainability, including the use of computationally efficient algorithms and demand-based cloud resource allocation to reduce the electricity and water consumed by AI computing. GC is working to extend equivalent environmental expectations to AI services and infrastructure provided by third parties.

GC's Generative AI Usage Guideline requires personnel to recognize and report suspicious AI-generated content used to deceive or impersonate individuals, including manipulated video, audio, or text. GC's current AI use cases are focused on supporting business operations and do not include applications involving manipulative behavior, exploitation of vulnerabilities, social scoring, or unauthorized biometric surveillance.

GC's AI Policy was approved by the PTTGC Group's Digital & IT Steering Committee (DISC), the Group-level governance body responsible for overseeing digital and information technology strategy.