Excellence in Governance|Information Security

Information Security

Nuvoton always explore new markets actively, continuously maintaining the profitability of the company's operations, and investing in strategic patent layouts. To ensure integrity in management and compliance with laws, it constantly monitors domestic and international policies and emerging risks that may affect the company. It regularly promotes the core values of integrity in management, establishes a robust corporate culture, and develops a sustainable new situation.

SDGS
SDG 8 Decent Work and Economic Growth
SDG 9 Industry, Innovation and Infrastructure
SDG 12 Responsible Consumption and Production
SDG 13 Climate Action
SDG 16 Peace, Justice and Strong Institutions
SDG 17 Partnerships for the Goals

100

%

Integrity management education and training

5300+

Patents Granted

Accumulated approved patents globally

Information Security

 

Nuvoton has stipulated the "Nuvoton Security Policy" and "Information Security Management Measures," which delineate a robust framework for information security controls. To safeguard both Nuvoton and its clients’ information from theft, cybercrime, industrial espionage, or other forms of harm and loss, Nuvoton engages in confidentiality agreements with its vendors and clients. Furthermore, periodic software inspections are conducted utilizing advanced software tools.

 

Aligned with its established information security control systems, Nuvoton conducts annual internal audits and convenes regular information security management meetings to scrutinize and monitor advancements in improving information security operations. Furthermore, risk assessments are systematically performed concerning both internal and external stakeholders, including clients, suppliers, employees, and regulatory bodies, with processes for monitoring information security and addressing exceptional incidents comprehensively established.

 

In December 2022, Nuvoton Taiwan appointed a Chief Information Security Officer (CISO) and established a dedicated unit for information security, designated as the Information Security Department. In March 2024, this department was elevated to a division-level organization and rebranded as the Information Security Division. The primary responsibilities of this division encompass overseeing group-wide information security governance, enhancing employee awareness, fostering a culture of information security, mitigating the risk of sensitive information leakage, reinforcing cybersecurity defenses & threat detection capabilities, and integrating both internal and external resources to implement effective information security risk management. This comprehensive approach ensures the resilience and continuity of the organization's information security framework. Nuvoton Japan has similarly established an Information Security Section within its Information Systems Department, tasked with managing information security activities to ensure thorough compliance with information security standards.

 

In response to client requirements, Nuvoton Taiwan has successfully obtained certification for the updated ISO 27001:2022 International Information Security Management System and has passed the renewal audit in 2025. Nuvoton Japan has updated its certification to ISO 27001:2022 in 2024. Additionally, given its engagement in integrated circuit card and automotive-related products, Nuvoton Japan has secured certifications for ISO/IEC 15408:2022 and ISO/SAE 21434:2021.

Information Security Risk Control Measures

ItemSpecific MeasuresAchievements in 2025
Identity access control
  • For cloud services, we utilize conditional access and multi-factor authentication, allowing access only to compliant devices and using specific programs
  • For remote connections, we implement identity verification, multi-factor authentication, and device whitelisting, ensuring connection under specified conditions
  • Regular password updates are conducted as well
  • The user login notification feature has been enhanced to provide users with real-time alerts upon successful login, thereby facilitating the verification of the legitimacy of login activities
  • We added a notification for VPN login multi-factor authentication failure. If the user finds it to be abnormal behavior upon receiving the notification, they can directly report it to the information security unit for handling
  • In 2025, neither Nuvoton Taiwan nor Nuvoton Japan experienced any major/high-risk incidents
Physical security protection 
  • Access to different areas is restricted based on employee roles, requiring the use of access cards for identity verification when entering each designated area
  • Access control, CCTV surveillance, and fire protection systems have been established to monitor personnel access through card and password control mechanisms. These systems ensure localized imaging surveillance and recording in critical areas. In the event of a fire or emergency situation, alarms are activated immediately, and compliance with access security requirements is maintained in accordance with the ISO/IEC 15408:2022 international standard
System Security Monitoring 
and Vulnerability 
Management
  • Endpoint detection, defense tools, and Security Operations Center (SOC) solutions are employed to implement detection and response measures
  • Local servers undergo quarterly vulnerability scans, with regular maintenance scheduled monthly
  • Occasional updates for significant Microsoft patches are being executed to address potential security risks
  • Risk monitoring is conducted utilizing the Panorays external cloud scanning tool to identify vulnerabilities
  • Third-party vendors are engaged to perform penetration testing to assess security vulnerabilities
  • The average score on the Panorays cloud monitoring platform is maintained at over 97, with a total of 87 risks mitigated, representing a 156% increase from the previous year, of which 26 are classified as high or critical risks
  • In 2025, Nuvoton processed a total of 4,123 alerts, with no significant cybersecurity incidents or virus infections reported
Code Security
  • For new systems, external service systems, and substantial version upgrades, the application department is mandated to conduct code security assessments and address high-risk code vulnerabilities to enhance the overall security of program deployment.
  • Regular updates to the code scanning database are performed to improve code detection efficiency
  • In 2025, Nuvoton Taiwan successfully launched 49 new systems, achieving a 100% remediation rate for high-risk code modifications, with a complete coverage rate for executed source code scans. Concurrently, Nuvoton Japan conducted code inspections with a focus on discrepancies to support system development and remediation efforts
Email security
  • Enhance the email server security settings by configuring SPF to authorize designated mail servers for sending emails on behalf of the Company, and implement DKIM and DMARC settings to prevent email spoofing and tampering
  • Utilize secure Outlook plug-ins to verify recipients, content, and attachments before sending emails, thereby preventing erroneous email transmissions, the email monitoring feature of the IT equipment management tool (AssetView) is used to oversee the sending of inappropriate emails
  • The DKIM KeySize has been elevated to 2048 bits to mitigate the risk of RSA key compromise and the subsequent potential for email spoofing.
  • The incidence of erroneously sent emails in 2025 has decreased by 5% compared to the preceding year

Customer Privacy Protection

 

Nuvoton has expanded the scope of its compliance with international information security and personal data protection standards, thereby enhancing operational security and personal data protection. The Company has fortified its information security measures to ensure customer privacy and to prevent the unauthorized disclosure of trade secrets and intellectual property rights.

 

Nuvoton Taiwan has enforced and successfully verified the latest ISO 27001:2022 International Information Security Management System certification, maintaining its compliance through the renewal assessment conducted in 2025. Nuvoton Japan strictly complies with Japan's Personal Information Protection Act, along with ISO 21434 and ISO 27001 standards governing the management of personal information. 

ISO 27001
Customer confidentiality and information security are top priorities for Nuvoton. Customer-related information and documentations are strictly controlled and stored within Nuvoton's highly secure internal systems. Confidentiality agreements are signed with key partners and customers to protect sensitive information and prevent unauthorized disclosure of trade secrets or proprietary information. According to the ISO 27001 Information Security Management System, Nuvoton has established a comprehensive information security protection system. In 2025, Nuvoton did not encounter any complaints regarding violations of customer privacy rights or loss of customer data.
Privacy Protection Laws and Regulations
Nuvoton adheres to various privacy protection regulations, including the "Personal Data Protection Act," the "General Data Protection Regulation (GDPR)" applicable in the European Union, and the "California Consumer Privacy Act (CCPA)" in the United States, Nuvoton Taiwan provides trainings on the "Personal Data Protection Act" for all employees, covering the overview of both GDPR and Taiwan Personal Data Protection Act, achieving a 100% attendance rate. Nuvoton Japan uploads data protection training materials (including GDPR) on the Company's online learning platform, ensuring easy access for all employees.
Signing a confidentiality agreement
Confidentiality agreements are signed with customers to protect sensitive information, and confidential data protection procedures are established to ensure there is no risk of leakage of sensitive information, thereby safeguarding customer privacy effectively