Want to Create an Account?
Want to Create an Account?

Contact Us

Search

Important Notice

Towngas recently received customer enquiries on suspicious gas bill. The alleged claim and embedded links have been found to be fraudulent. The matter has since been reported to the police. Please stay alert and do not click on any attachment or link contained in any email or message that appears suspicious. For enquiries, please call 2880 6988 or email towngas.cs@towngas.com
2023-11-28 13:00:00
Data Privacy and Cyber Security

Data Privacy and Cyber Security

We understand the importance of personal data privacy and take every step necessary to protect them. To that end, we have established a Personal Data Privacy Policy that sets out our standards for collection, use, sharing, and protection of personal data. Cyber security has also become a key concern of stakeholders. Our Information Security Policy ensures the protection of confidentiality, integrity and availability of the Group’s information and technology assets.

Cyber security and critical data (financial, customer, and operation) protection, is included as one of the Group’s key risks. This includes unauthorised access to systems and data, which could lead to privacy breaches on personal information of customers, employees and others and would adversely affect the Group’s business. Such risk is regularly assessed through the risk management process.

The major risk exposure and implementation of risk-mitigating measures are regularly reported to and discussed by the Executive Risk Management Committee for monitoring purpose, while top risks and measures would be reported by Corporate Audit and Risk Management Department to the Board Audit and Risk Committee (on behalf of the Board) for review.

The key to successful protection of customer privacy is our employees. If our employees lack the necessary awareness, mishandle customer information or are unaware of cyber security risks, the potential for a customer information leakage incident can be high. To avert this possibility, we have undertaken various initiatives, including seminar training, information security tips and regular phishing simulations. We also host an annual Information Security Week to keep employees up-to-date on personal data protection matters as well as cyber security knowledge.

An example of mitigating the risks of data leakages and maintaining the trust of our customers is that, we make it possible to wipe the data contained in all mobile devices carried by our gas technicians and other frontline employees remotely, in case these devices are lost. We also isolate sensitive information from our customer relationship management system, in order to minimise the impact of possible hacking incidents.
 
Customer Privacy 

We have implemented Privacy Management Programme (PMP) to enhance personal data privacy protection and ensure compliance and accountability to data subjects. The PMP consists of a set of policies and processes reflecting our organisational commitment, system control and ongoing assessment to safeguard data privacy. We also conduct regular internal audits of the privacy policy compliance. 

The Company’s Data Privacy Standing Committee (the “Committee”) reviews strategies for handling personal data. The Committee is chaired by the Head of Legal who reports directly to the Managing Director. Through the concerted effort of the Data Protection Officer and the Departmental Data Protection Coordinators, we have established a formal communication channel to deal with personal data situations such as disseminating up-to-date data protection information and enhancing the effectiveness of the PMP. 

Additionally, the Committee manages potential data breaches. If a data breach does occur, the Committee will conduct an interim assessment on the risk of harm and decide whether the incident will be escalated to top management for their attention. The Committee will also suggest solutions for resolving the incident.

Every department is required to make a declaration to the Company about its compliance with the requirements of data protection principles and any data protection matters that might have arisen during the year.

The Privacy Impact Assessment (PIA) and Data Processor Review Checklist (DPRC) are two important tools for our PMP which aims to assess potential privacy risks for any new projects or processes. PIA ensures our customer data is safeguarded and our compliance with the Person Data (Privacy) Ordinance of Hong Kong is confirmed. A walk-through of DPRC is also required for new or ongoing projects that entail the processing of customer data by a third party on behalf of Towngas. The PMP online platform has been set up to facilitate the submission of DPRC and to build our data inventory.
 


Cyber security 

To address cyber security issues, we have a Cyber Security Committee that is responsible for managing all cyber security matters and is overseen by the Head of Corporate Information Technology who reports directly to the Managing Director who is also a member of the Board.

Early anomaly detection allows suspected activities to be detected in the early stage which effectively minimises the impact. By leveraging on threat intelligence and active monitoring under the ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework, any suspected activities are under tight scrutiny and are validated against its legitimacy and incident response procedures. To further improve cyber security maturity, we have commissioned a third-party consultant to monitor potential cyber incidents around the clock. The consultant has integrated global threat intelligence and built up a platform for detection capability improvement. The platform helps to minimise Towngas cyber risks and enabling Towngas to continue innovating safely on the digital modernisation journey. To further identify potential vulnerabilities and mitigate our cyber security risks, we conduct regular penetration test internally and third-party security assessment annually on our applications. 

In the event of a cyber incident, we have developed a Cybersecurity Incident Response Plan (CIRP) with five response playbooks covering the top five cyber security incidents including data leakages and cyberattacks. The CIRP provides employees with actionable, consistent processes for responding to and recovering from various cyber incident scenarios that would have a severe impact on our business processes. In the event of a suspected cyberattack, our Cyber Security Committee will initiate the incident response process, contain the data leakage and contact the Cyber Security Centre of the Hong Kong Police Force and other security experts. We also test our incident response procedures at least annually. 

To test our recovery capability under the situation of cyber-attack, we conduct an annual disaster recovery drill on a backup site.