Highlight Performance

Data breaches
Case
Total number of clients, customers, and employees affected by the breaches
Case

Management Approach

Osotspa recognizes the critical importance of cybersecurity in today's interconnected world and has made it a top priority within its operations. Leveraging the latest NIST Cybersecurity Framework (CSF) 2.0, Osotspa establishes a comprehensive approach to protect its digital assets and maintain the trust of its stakeholders. By integrating the NIST CSF's core functions of Govern, Identify, Protect, Detect, Respond, and Recover, Osotspa ensures a robust cybersecurity strategy that addresses potential threats proactively and ensures swift recovery in case of incidents.

Furthermore, Osotspa goes beyond mere compliance by fostering a culture of cybersecurity awareness and empowerment throughout its workforce. Through continuous training, education, and the implementation of stringent policies, every employee at Osotspa becomes a proactive defender against cyber threats. By embracing cutting-edge technologies and strategic partnerships, Osotspa remains agile and adaptive in an ever-evolving cybersecurity landscape, reaffirming its commitment to safeguarding its operations and maintaining the trust of its customers and partners.

Govern
The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
Identify
The organization’s current cybersecurity risks are understood.
Protect
Safeguards to manage the organization’s cybersecurity risks are used.
Detect
Possible cybersecurity attacks and compromises are found and analyzed.
Respond
Actions regarding a detected cybersecurity incident are taken.
Recover
Assets and operations affected by a cybersecurity incident are restored.

Cybersecurity Governance

Osotspa has established a cybersecurity governance framework to ensure effective oversight, management, and escalation of information security and cybersecurity risks across the organization.

At the executive level, the Head of Digital Technology serves as the Company’s highest-ranking executive responsible for digital technology, cybersecurity, responsible AI, and digital transformation. The position is one level below the Chief Executive Officer (N-1) and reports directly to the CEO. While the formal job title is “Head of Digital Technology,” the role carries enterprise-wide accountability equivalent to a chief-level technology and information security function.

The Head of Digital Technology is responsible for overseeing cybersecurity strategy, information security policies, cybersecurity risk management, security controls, incident response, corrective actions, responsible AI governance, and digital transformation initiatives. The role also serves as the policy owner for relevant cybersecurity, responsible AI, and digital technology policies.

Osotspa has also established a Digital and Cybersecurity Committee, which is chaired by the Chief Executive Officer. The Committee provides executive-level oversight of cybersecurity and digital technology matters, including significant cybersecurity risks, incidents, root causes, corrective and preventive actions, and progress on key cybersecurity initiatives.

Cybersecurity incidents and material information security matters are reviewed through the Company’s governance and escalation process. Significant issues are reported to the Digital and Cybersecurity Committee, escalated to the Risk Management Committee, and subsequently reported to the Board of Directors, as appropriate. This governance structure enables senior management and the Board to maintain oversight of cybersecurity risks, incident management, remediation actions, and organizational resilience.

The Company continuously strengthens its cybersecurity governance and management practices to address evolving cyber threats, regulatory requirements, emerging technologies, and business risks. This includes enhancing cybersecurity risk assessment, incident preparedness and response, employee awareness, technology controls, responsible AI governance, and continuous improvement of the Company’s cybersecurity framework.

Cybersecurity Awareness and Training

Osotspa continuously strengthens cybersecurity awareness among employees through training and awareness-building activities designed to address evolving cyber threats and responsible digital behaviors.

In 2025, the Company conducted a Cybersecurity Live Talk 2025, delivered by an external cybersecurity specialist, covering key topics such as cybersecurity and data privacy, phishing and social engineering, malware and data-stealing threats, secure authentication and multi-factor authentication, data breaches, suspicious links and attachments, safe use of devices and digital platforms, and appropriate reporting of suspicious cybersecurity activities.

The training also addressed emerging technology risks, including AI-powered phishing, deepfake scams, AI-generated malware, sensitive data leakage through AI tools, and cybersecurity risks associated with generative AI. Employees were provided with practical guidance on recognizing cyber threats, protecting sensitive information, using secure authentication practices, and responding appropriately to suspicious activities.

Through regular cybersecurity awareness activities and practical training, Osotspa aims to strengthen employee vigilance, promote responsible use of digital technologies, and reduce human-related cybersecurity risks across the organization.

Information Security Policy

Osotspa has implemented a comprehensive IT policy to effectively manage and oversee various aspects of information technology security within the organization. This policy serves as a guiding framework to ensure the confidentiality, integrity, and availability of IT resources, as well as to mitigate potential risks and threats. Through this policy, Osotspa aims to uphold the highest standards of IT security practices, thereby safeguarding sensitive data, protecting against cyberattacks, and maintaining the overall resilience of its IT infrastructure.

Our Information security policy is internally available to all employees via OSP Life application and Internal Corporate Mail.

Osotspa Cybersecurity Roadmap Toward 2025

Osotspa remains committed to fortifying its cybersecurity infrastructure to ensure the safety and integrity of our operations. Safeguarding our digital assets and data is paramount to sustaining our competitive edge and preserving customer trust. Over the years, Osotspa has implemented comprehensive cybersecurity initiatives to mitigate risks and adapt to evolving threats. Looking ahead to 2025, we recognize the increasing importance of bolstering our defenses to stay ahead of cyber adversaries. Our strategic roadmap for cybersecurity encompasses several key areas:

Osotspa has implemented multi-factor authentication across critical systems and applications, adding an extra layer of security beyond traditional passwords. This helped prevent unauthorized access even in the event of password compromise.

The infrastructure of Osotspa is regularly inspected and updated to ensure compliance with industry best practices, including intrusion detection systems, email security, and encryption.

Osotspa prioritizes the security of cloud-native applications by implementing robust security measures tailored to the cloud environment, including rigorous testing, monitoring, and strict access controls.

Osotspa recognizes that human error remains a significant cybersecurity risk. Therefore, Osotspa prioritizes continuous education and training for employees. Regular cybersecurity awareness programs help ensure that employees have the necessary knowledge and skills to handle cyber threats effectively.

Osotspa regularly conducts phishing simulations to assess and improve employees’ knowledge and resilience against phishing attacks. These simulations mimic real-world phishing scenarios, allowing us to identify vulnerabilities and provide targeted training to effectively reduce risks.

Osotspa regularly conducts risk assessments and penetration testing to identify and address potential vulnerabilities in its data and network security systems. By simulating various penetration scenarios, we gain a better understanding and can enhance our defenses, effectively reducing the risk of data breaches.

Osotspa has a comprehensive incident response plan to quickly and effectively mitigate the impact of security incidents. Our response team is regularly simulated and drilled to ensure readiness in the event of a cyber incident, minimizing business operation disruptions.

Osotspa has developed a comprehensive disaster recovery plan to ensure business continuity in the event of natural disasters or other unexpected disruptions. These plans include backup strategies, data recovery procedures, and failover mechanisms to minimize downtime and mitigate the impact of adverse events. The recovery plans are tested semi-annually to verify their effectiveness and identify areas for improvement.

As part of Osotspa’s commitment to end-to-end security, Osotspa closely collaborates with partners and allies to maintain cybersecurity standards throughout the supply chain. Regular assessments are conducted to evaluate third-party providers and enforce compliance with Osotspa’s security requirements.

Osotspa conducts annual risk assessments through both internal and external audits to evaluate operational effectiveness. These assessments provide insights into emerging threats and areas for improvement in the security system, guiding the enhancement of cybersecurity measures.

Company Process for Potential Information Security Incidents:

There are seven steps for identifying and managing actual or potential Information Security Incidents within the Company:

  1. The Company has a clear and documented incident management process.
  2. The Company’s IT security system is regularly assessed according to the plan.
  3. The Digitization department serves as the point of contact and is responsible for ensuring the escalation process is followed.
  4. Employees encountering actual or potential IT security threats must report to their supervisor and the Digitization department.
  5. The Digitization department collects, analyzes, and stores evidence as soon as it is reported, while the IT Services sub-function assists the employee in recovering from any damage in parallel.
  6. All actions taken throughout the process are recorded and stored in written format.
  7. The IT security incident report is included in the system and process improvement study conducted after the case is closed.

Targets

Description 2024 Performance Long-term Target(2025)
Data breaches 0 0
Total number of clients, customers, and employees affected by the breaches 0 0
Protection coverage
%
protected against virus and malware threats
devices
emails protected against email threats.
million

Responsible Artificial Intelligence at Osotspa

Osotspa has established a Guideline for Using Generative AI and is developing an AI Governance Policy to promote the responsible, secure, transparent and ethical use of artificial intelligence across the organization. Together, these documents provide a framework for employees and relevant stakeholders to use AI appropriately while managing risks related to data privacy, cybersecurity, accuracy, fairness and non-discrimination, transparency and explainability, human oversight, accountability, and the protection of confidential information. They also define appropriate and prohibited uses of AI, establish governance and oversight responsibilities, and support the continuous monitoring and improvement of AI applications throughout their lifecycle. Through these guidelines and governance principles, Osotspa aims to harness the benefits of AI while safeguarding stakeholders, strengthening trust, and ensuring that AI is used in alignment with the Company’s values, applicable laws and responsible business practices.

Responsible Artificial Intelligence Program

Osotspa implements a Responsible Artificial Intelligence Program to support the secure, ethical, transparent and responsible development, deployment and use of artificial intelligence across the organization. The program translates the principles of the Company’s AI Governance Policy into operational controls and practices throughout the AI lifecycle.

The program incorporates AI application inventory management, technical access and security controls, continuous monitoring of AI usage and model performance, fairness and bias assessments, human oversight, stakeholder feedback and appeal mechanisms, employee training, and management oversight.

AI Application Inventory and Risk Oversight

Osotspa maintains an AI Application Inventory to provide visibility over AI applications and use cases deployed or used within the organization. The inventory supports the identification, monitoring and management of AI-related risks and enables relevant functions to apply appropriate governance and controls based on the nature and risk profile of each AI application.

Information relating to AI adoption, associated risks and applicable controls is periodically consolidated and reported to the Risk Management Committee (RMC) for oversight and monitoring. This process supports the continuous enhancement of the Company’s AI governance framework and its alignment with evolving technology risks and business requirements.

Access Controls and Protection of Sensitive Information

Osotspa implements technical controls to manage access to external AI services and reduce risks associated with inappropriate AI usage or unauthorized disclosure of Company information.

The Company applies AI Secure Access Rules through Trend Micro Vision One, including controls addressing file uploads, access to malicious URLs, inappropriate content, prompt injection and events that could result in data leakage.

For file uploads to public AI services, Osotspa applies a default-deny approach to prevent Company information or documents from being uploaded without authorization. Where access is required for legitimate business purposes, exceptions may be granted only to specifically authorized users or user groups following appropriate review.

These measures support risk-based access to AI capabilities while protecting confidential, personal and business-sensitive information.

Continuous Monitoring of AI Usage and Security Events

Osotspa continuously monitors the use of AI services through corporate devices using Trend Micro Vision One. Monitoring covers relevant indicators such as AI service usage, types of AI services accessed, file-upload activities and events that do not comply with established control rules.

The system maintains information to support investigation and retrospective review, including the relevant user, device, AI service, date and time of the event, applicable control rule and system action, such as Allow or Block.

The information generated through this monitoring process is analyzed to identify potential incidents, usage trends and areas where controls may need to be strengthened or adjusted.

AI Model Performance Monitoring and Continuous Improvement

Osotspa regularly monitors and evaluates relevant AI models to help maintain their reliability, accuracy and effectiveness throughout their operational lifecycle.

Model reviews include, as applicable, assessment of performance, accuracy, fairness and potential bias, as well as identification of material deterioration, unexpected behavior or changes in model performance.

Where issues are identified, responsible teams investigate the underlying cause and implement appropriate corrective measures. Depending on the nature of the issue, these actions may include adjustment of model parameters, review or enhancement of datasets, additional validation, recalibration or retraining of the AI model.

Employees using relevant AI-enabled systems are also provided with an embedded feedback or reporting mechanism through which they can flag inaccurate, inappropriate or unexpected AI outputs. Reported issues are reviewed by the responsible team and may be incorporated into model investigation, correction and continuous improvement activities.

Fairness and Bias Assessment

Osotspa regularly assesses relevant AI models for potential bias and fairness-related risks.

Reviews consider whether AI-generated outputs demonstrate inappropriate bias, systematic distortion or potentially discriminatory outcomes. Fairness and bias considerations form part of the Company’s broader model performance and quality review process.

Where a potential bias or fairness issue is identified, responsible teams investigate the cause and apply appropriate mitigation measures, which may include review of training data, model adjustment, retraining, additional testing or strengthened human oversight.

Human Oversight, Complaints and Appeals

Osotspa maintains mechanisms that enable employees and external stakeholders to raise concerns about AI-generated information or AI-supported outcomes.

Employees may report inaccurate, inappropriate or unexpected AI outputs directly through feedback or reporting functions available within relevant AI-enabled applications.

In addition, both employees and external stakeholders may use Osotspa’s Integrity Hotline or Company Call Center to report concerns, request clarification or seek a review when they believe AI-generated information, recommendations or outcomes are inaccurate, inappropriate or require reconsideration.

Relevant cases are reviewed by responsible personnel and, where appropriate, escalated for human review, correction, clarification or remedial action. These mechanisms provide stakeholders with accessible channels to challenge AI-related outcomes and seek appropriate review or redress.

Employee Training and Responsible AI Awareness

Osotspa provides AI-related training and awareness activities to strengthen employees’ ability to use artificial intelligence responsibly, ethically and securely.

Training and guidance cover relevant topics such as appropriate use of generative AI, information security, personal and confidential data protection, verification of AI-generated information, limitations of AI, responsible human oversight, fairness and bias considerations, and mechanisms for reporting concerns or inaccurate AI outputs.

The Company also provides AI capability-building activities as part of its broader digital and future-readiness agenda and continues to strengthen AI literacy across the organization.

Transparency and Identification of AI-Generated Content

Osotspa applies transparency measures to enable users to clearly identify when they are interacting with an AI-enabled system or receiving AI-generated or AI-supported information.

AI-enabled applications that directly interact with employees, customers or other stakeholders are required to provide an appropriate user-facing notification, such as an “AI Assistant” identifier, “AI-generated” label or other clear notification indicating the involvement of artificial intelligence.

Where appropriate, AI-generated responses also include a notice reminding users that AI-generated information may contain inaccuracies and should be reviewed or verified before being relied upon for material decisions.

Users are provided with a feedback or reporting mechanism to flag inaccurate, inappropriate or unexpected AI-generated outputs. Reported issues are reviewed by the responsible team and incorporated into the Company’s AI monitoring and continuous improvement process.

Environmental Considerations in AI

Osotspa integrates environmental considerations into the management and operation of its AI-enabled digital infrastructure as part of the Company’s responsible technology approach.

The Company operates AI applications primarily through its consolidated and scalable cloud infrastructure, enabling computing resources to be allocated according to actual business requirements rather than maintaining unnecessary dedicated computing capacity.

To reduce the environmental footprint associated with AI workloads, Osotspa applies measures including:

  • optimizing computing and cloud-resource utilization according to actual workload requirements;
  • avoiding unnecessary or duplicated AI processing and computational demand;
  • leveraging shared and scalable cloud infrastructure rather than maintaining underutilized standalone computing resources;
  • considering energy efficiency and environmental performance when evaluating relevant cloud and AI technology solutions; and
  • periodically reviewing AI applications through the AI Application Inventory to identify opportunities for consolidation, optimization or retirement of redundant applications.

These measures build on Osotspa’s broader green technology approach, including the use of energy-efficient cloud solutions, optimization of server utilization and sustainable digital infrastructure.

Measuring Sustainability Outcomes from AI

Osotspa evaluates measurable environmental and operational outcomes from selected AI-enabled initiatives to understand how artificial intelligence contributes to the Company’s sustainability objectives.

One application is the use of AI-enabled Order Recommendations with Full Truck Load (FTL) to optimize transport planning and improve vehicle utilization. The solution supports more efficient consolidation of orders and transportation requirements, helping to reduce unnecessary trips, delivery costs and resource consumption.

The Company monitors relevant performance indicators associated with the initiative, including:

  • Full Truck Load utilization
  • Reduction in transportation trips
  • Transportation distance avoided
  • Fuel consumption avoided
  • Estimated greenhouse gas emissions avoided

During 2025, the use of AI-enabled transport optimization resulted in cost efficiency and GHG emission reduction in the transportation and logistics, demonstrating how AI can support both operational efficiency and environmental performance.

Osotspa will progressively extend the measurement of environmental and social outcomes to other material AI use cases where impacts can be reliably quantified.

Management Oversight and Continuous Improvement

Osotspa consolidates information on AI applications, emerging risks, control measures and relevant monitoring results for management oversight. Material AI-related matters are reported through established governance channels, including the Risk Management Committee, to support informed oversight and continuous improvement of the Company’s AI governance and risk-management framework.

The Responsible Artificial Intelligence Program will continue to evolve in line with technological developments, emerging risks, regulatory requirements and recognized responsible-AI practices.