Information Security | ACER ESG
Information Security Policy
In pursuit of sustainable operation and the protection of our customers’ trust in us, Acer began implementing an information security management system in 2019. At the foundation of this ISMS is Acer’s information security policy, helping ensure the security of information assets and the continuity of information services, thus mitigating the threat from and impact of information security incidents.
This policy applies when accessing Acer IT’s information assets, IT systems, and infrastructure. It applies to all executives and employees of Acer IT, including contractors, consultants, temporary staff, trainees, and any other third parties working for Acer IT (referred to hereafter as “staff”).
- Ensure that Acer’s information assets are protected from any external interference, destruction, attacks, or any impact from other destructive or negative behaviors.
- Ensure Acer is compliant with relevant laws.
- Ensure the continuity of information services.
The policy framework follows and is based on the following regulations:
Trade secrets laws, e.g., the US Defend Trade Secrets Act (DTSA), Taiwan Trade Secrets Acts, and similar laws in other jurisdictions.
Privacy protection laws, e.g., the EU General Data Protection Regulation (GDPR), Taiwan Personal Information Protection Act, and similar laws in other jurisdictions.
This policy is reexamined at least once a year to check for legal compliance with the latest technology and business developments.

Continuously Improving Information Security Systems
The Company is committed to continuously enhancing the information security management system to address evolving risks and threat landscapes. Through a risk-based approach, the Company regularly reviews and updates information security policies, procedures, and controls. The effectiveness of the system is evaluated through internal and external audits, management reviews, and improvement tracking mechanisms to ensure that information security capabilities remain aligned with business needs and resilience objectives.
Ensuring the Integrity and Protection of Data
The Company is committed to ensuring the accuracy, consistency, and security of all information and data throughout its lifecycle, preventing any unauthorized access, tampering, or destruction. Appropriate controls are implemented to restrict access to sensitive information, ensuring that data is only accessed or processed by authorized personnel based on defined roles and responsibilities.
Proactively Monitoring and Responding to Information Security Threats
The Company is committed to proactively monitoring security risks and potential threats and maintaining a structured information security incident management mechanism to ensure prompt detection, classification, reporting, and response. In accordance with applicable regulations and requirements, the Company maintains transparent and timely communication with affected stakeholders. Corrective and preventive actions are implemented to mitigate impacts and prevent recurrence.
Establishing Information Security Responsibilities for the Entire Workforce
The Company defines information security as a shared responsibility of all employees and suppliers, with responsibilities assigned based on their roles and job functions. All personnel are required to comply with the information security policies, remain vigilant against potential risks, and promptly report any suspected incidents or abnormal activities. The Company conducts regular information security awareness training and social engineering exercises to ensure that all members possess the necessary protective capabilities.
Establishing Information Security Requirements for Third Parties
The Company integrates information security and data protection requirements into third-party management (including suppliers and contractors). Information security responsibilities are explicitly defined in contracts to mitigate risks arising from third-party relationships and to ensure that shared information, systems, and infrastructure are adequately protected.
Information Security Risk Management Framework
Acer has established a comprehensive and transparent information security governance framework to ensure that information security issues receive direct oversight at the Board of Directors. To implement professional management practices, the Board of Directors has set up the Risk Management and Sustainability Development Committee (RMSDC), which is established in accordance with the company's Articles of Incorporation and report directly to the Board of Directors. The committee consists of three or more directors appointed by the Board of Directors, with the majority being independent directors to ensure independence and objectivity in the oversight process. Under the guidance of the Risk Management and Sustainability Development Committee, the Information Security Governance Committee (ISGC) has been established as a dedicated governance and execution body to ensure that information security activities are implemented across all operational levels.
The Information Security Governance Committee is led by the Chief Information Security Officer (CISO) and includes representatives such as heads of Acer's IT product lines and the general managers of subsidiaries. The committee has two working groups responsible for Group-wide information security, policy formulation, and risk management. It reports quarterly to the Chairman on governance performance, key issues, and strategic directions, and reports annually to the Board of Directors on the effectiveness of information security risk governance. The CISO also serves as a member of the Risk Management Executive Committee (RMEC) to collaborate on information security risk control.
- Information Security Risk Compliance Team: Conducts regular independent reviews to assess the effectiveness and compliance of information security measures.
- Information Security Incident Response Team: Responsible for planning, preparation, and realtime execution of information security incidents response measures.
Information Security Governance
Information Security Management Strategy
To effectively implement information security management, Acer obtained the ISO/IEC 27001:2013 international information security management system certification in 2019 and has passed third-party annual audits each year to maintain the validity of the ISO 27001 certification. In 2025, Acer successfully completed the transition to ISO/IEC 27001:2022 and the 3-year reverification process. The current certification is valid from November 18, 2025, to November 17, 2028. This achievement further demonstrates Acer’s ongoing commitment and maturity in implementing Information Security Management System (ISMS) and ensuring the long-term, robust operation on information security management practices.
In addition to regular reporting by the Information Security Governance Committee to management and the Board of Directors on performance and risks, the following regular working group meetings are also held:
- Quarterly Group Information Security Working Group Meeting
- Quarterly Acer Product Software Development Security Working Group Meeting
- Monthly Regional Information Security Working Group Meeting
- Bi-weekly ISMS (Information Security Management System, ISMS) Routine Meeting
Following the Plan-Do-Check-Act (PDCA) management cycle, Acer reviews the applicability of security policies and protective measures, verifies implementation status, and conducts annual internal and external audits to ensure compliance and maintain confidentiality, integrity, and availability of critical assets.
Acer also adheres to both the ISMS and the NIST Cybersecurity Framework (CSF). In addition to maintaining ISO 27001 certification for infrastructure and core systems, Acer has built a multi-layered security protection system covering six core functions of security management: Govern (define security governance strategies, roles, and responsibilities), Identify (manage information assets, systems, personnel, and data, assessing and identifying risks), Protect (implement measures to ensure service availability and security), Detect (establish mechanisms to identify and alert on cybersecurity events), Respond (plan and execute actions to address detected incidents), and Recover (implement measures to restore functions and services impacted by cybersecurity incidents). This approach enforces risk management throughout the cybersecurity lifecycle, integrating innovative security technologies into hardware/software operations and daily workflows. Acer also leverages the NIST CSF framework to continuously assess cybersecurity maturity as a basis for strengthening security.
Information Security Risk Management and Continuous Improvement Framework
Acer adopts the Plan–Do–Check–Act (PDCA) management cycle to establish a systematic and continuously improving information security governance framework. Through comprehensive risk identification, layered defense mechanisms, performance monitoring, and continuous improvement processes, Acer ensures that its business operations and critical information assets are comprehensively protected.


2025 Information Security Management Enhancement Highlights
To further control evolving cybersecurity risks, Acer adopts the following strategies:
- Secure Software Development Lifecycle Management: Adopt a "Shift Left" approach by integrating security controls into the earliest stages of software development, incorporating secure development lifecycle management and pre-launch onboarding security checks.
- Automated Vulnerability Management: Establish a comprehensive vulnerability reporting and system lifecycle management mechanism.
- Supply Chain Information Security Risk Management: Implement information outsourcing management and supplier security risk monitoring.
- AI Application Security: Develop AI security guidelines and risk assessments.
- Adopt Cybersecurity Insurance to establish a risk transfer mechanism for information security threats.
- In 2025, we implemented business continuity plan (BCP) exercises in accordance with the business continuity management procedures. A total of 34% of all systems completed BCP drills, all of which met their defined Recovery Time Objectives (RTOs).
- Risk assessments were conducted in 2025. Acceptable risks accounted for 97.2% of total assessed risks in H1 and increased to 100% in H2. All identified unacceptable risks have been scheduled for remediation in 2026.
Implement information security management and cultivate a strong security culture
Acer is committed to implementing information security management and cultivating a deep understanding of the purpose behind security activities. To enhance the awareness of information personnel and ensure that frontline employees executing security activities are well-informed, Acer organizes the annual ISMS Workshop and security activity briefings. This ensures that they have the knowledge to act accordingly and continuously provide recommendations to the management departments for optimizing future security implementation plans. This creates a positive cycle of security and fosters a culture of information security within the organization.
Information Security Training
Acer Corporation has implemented personnel education and training programs to strengthen information protection mechanisms and information security management. In the second quarter of 2024, all IT personnel in the global IT department successfully completed security education and training. Furthermore, comprehensive security education and training sessions were conducted for all employees across all departments worldwide, addressing important topics such as passwords, phishing, remote work, ransomware, business email attacks, and the reporting procedures for phishing incidents.
In 2024, the Acer Headquarters Cybersecurity Center provided cybersecurity awareness training to a total of 6,148 Acer employees worldwide, including those from unlisted subsidiaries. Of these, 5,728 employees successfully completed the training, resulting in a completion rate of approximately 93%. The standard for completion required passing a post-training assessment, with all test scores needing to reach 100%.
ISMS Workshop
Besides the existing ISA training, to implement the key information security work of Acer’s IT personnel, IT ISO & ITSM Office (ISO Office) of Acer Global IT regularly organizes ISMS workshops of information system account inventory, business impact analysis, objective effectiveness measurement, risk assessment and other key ISMS work items. ISO Office publishes ISMS Workshop presentation slides, FAQs, and teaching video materials to ensure information security work can keep pace with the times.

2025 Information Security Management Focus
- Achieved ISO 27001:2022 transition certification in March 2025; in September, passed re-verification by third-party information security certification company BSI.
- The Group Information Security Governance Committee shall convene quarterly to improve information security.
- Achieve a 90% completion rate for cybersecurity awareness education and training for employees worldwide.
- Achieve a 100% completion rate for cybersecurity training among colleagues in the IT department worldwide.
- The average score for the 2025 Scorecard exceeded 90.
- Operations continue to conduct mock drills that simulate both cloud and on-premises scenarios.
- Strengthen information security control policies, processes and frameworks, and establish standards to identify information security maturity.
- Strengthen network firewall and network control to prevent malware from spreading horizontally across the network through network architecture micro-segmentation.
- Implement a multi-level control mechanism for privileged accounts to prevent leakage of privileges.
- Implement endpoint management mechanism to manage, protect and deploy enterprise resources and applications.
- Strengthen information protection mechanisms and data leakage prevention controls, continuously enhancing the capability to safeguard confidential information.
- Perform regular information security drills and continuously optimize the mechanism.
- Build cloud information security automation control framework.
- Enhance backup effectiveness and provide a recovery solution that can be rebuilt quickly.
Information Security Drill
To ensure staff can respond promptly to and handle issues resulting from the impact of major system failures, negative human factors, or natural disasters, Acer holds annual vulnerability scans, penetration tests, and business continuity drills to examine the risk coefficient of all processes and establish recovery plans that strengthen the Company’s emergency response capability and tolerance against cyber attacks. The details of this are as below:
Acer regularly conducts annual disaster response drills for fire, power outage, earthquake, etc. In addition, Acer also conducts quarterly drills for the core systems (including the ERP system, order management system, and accounting system) and more than 100 sub-systems to implement different levels of recovery control measures according to the plan, so as to minimize the impact of a disaster.
Vulnerability scansAcer annually examines OS and network equipment security issues to discover vulnerabilities in system operations in time via vulnerability scans, implementing follow-up fixes to prevent vulnerability to attacks. | |
Penetration testsAcer commissions a third-party cyber security institution to implement drills. The penetration test team tries to break through network or system defenses with minimal information, such as searching the issues of web page programs or operating systems, to obtain further permissions or access unauthorized data. From the results of these tests, Acer is able to understand security blind spots in the system building or programming process and thus take action to correct or prevent them, enhancing the security level of the enterprise network and reducing security risk. | |
Business continuity drillsAcer has set out the Information Security Continuity Management Guidelines to provide guidance to all units in Acer IT in implementing business continuity strategies during adverse situations. Acer follows ISO 27001 and ISMS to routinely execute drills to examine the effectiveness of business continuity drills. Meanwhile, the Company also evaluates the index of RTO, RPO, and service-level functions of all due systems to implement resource integration and business continuity, ensuring the effectiveness of systems and protecting the best interests of our customers and stakeholders. |
Evaluation Mechanism
ISO 27001 third-party audits are conducted annually, with regular internal and external ISMS audits following the PDCA continuous improvement cycle. In 2024, four audits identified 59 findings: 14 non-conformities and 45 recommendations. (Please refer to the following figure) By December 31, 2024, 80% (47 items) have been resolved. The organization is implementing automation tools to improve information security management, with remaining issues planned for resolution in 2025.
- Regularly implement information security drills, stress tests, and data recovery drills during non-audit periods
- Regularly conduct: personal data inventory and risk assessment and handling of personal data for equipment security control
Occasionally conduct: Training of personal data processing managers, implementation of data security test drills, and supervision of outsourced vendors to comply with personal data protection regulations.
2025 Information Security Events
- 2023/09/14 The audit objectives have been achieved and the certificate scope remains appropriate. Acer’s ISO 27001: 2013 remains valid.
- 2024/03/08 The audit objectives have been achieved and the certificate scope remains appropriate. Acer’s ISO 27001: 2013 remains valid.
2025/03/12 Acer successfully completed the audit process, achieving the transition from ISO 27001:2013 to the updated ISO 27001:2022 standard. The audit objectives were fully met, and the certification under the new version is now in effect
Corporate information security management strategy and framework