We understand the importance of personal data privacy and take every step necessary to protect them. To that end, we have established a Personal Data Privacy Policy that sets out our standards for collection, use, sharing, and protection of personal data. Cyber security has also become a key concern of stakeholders. Our Information Security Policy ensures the protection of confidentiality, integrity and availability of the Group's information and technology assets.
Cyber security and critical data (financial, customer, and operations) protection is included as one of the Group's key risks. These risks include unauthorised access to systems and data, which could lead to privacy breaches on personal information of customers, employees and others and would adversely affect the Group's business. We regularly assess risks through our risk management process.
The major risk exposure and implementation of risk-mitigating measures are regularly discussed by and reported to the Executive Risk Management Committee for monitoring purposes, while top risks and measures would be reported by Group Audit and Risk Management Department to the Board Audit and Risk Committee (on behalf of the Board) for review.
The key to successful protection of customer privacy is our employees. If our employees lack the necessary awareness, mishandle customer information or are unaware of cyber security risks, the risk of customer information leakage increases accordingly. To avert this possibility, we have undertaken various initiatives, such as organising seminars and training, sharing cyber security tips and conducting phishing simulations. We also hold an annual Information Security Week to keep employees up-to-date on personal data protection matters as well as cyber security awareness.
To mitigate the risk of personal data leakage and maintain customer trust, we have established a remote data deletion mechanism for mobile devices in case they are lost by our gas technicians or other frontline employees. We also have strict control over the data storage mechanism in our customer relationship management system in order to minimise the impact of possible hacking incidents.
Towngas has implemented Privacy Management Programme (PMP) to enhance personal data privacy protection and ensure compliance and accountability to data subjects. The PMP consists of a set of policies and procedures reflecting our organisational commitment, system control and ongoing assessment to safeguard data privacy. We also conduct regular internal audits to review compliance with our privacy policies.
The Group's Data Privacy Standing Committee (the "Committee") reviews strategies for handling personal data. The Committee is chaired by the Head of Legal who reports directly to the Managing Director. Through the ongoing efforts of the Data Protection Officer and the Departmental Data Protection Coordinators, we have established a formal communication channel to jointly deal with personal data situations such as disseminating up-to-date data protection information and enhancing the effectiveness of the PMP.
Additionally, the Committee manages potential data breaches. If a data breach does occur, the Committee will conduct an immediate assessment of the risk of harm and decide whether the incident will be escalated to senior management for their attention. The Committee will also suggest solutions for resolving the incident.
Every department is required to make a declaration to the Group about its compliance with the requirements of data protection principles and any data protection matters that might have arisen during the year.
The Privacy Impact Assessment (PIA) and Data Processor Review Checklist (DPRC) are two important tools for our PMP which aim to assess potential privacy risks for any new projects or processes. PIA ensures our customer data is safeguarded and our compliance with the Personal Data (Privacy) Ordinance of Hong Kong is confirmed. A walk-through of DPRC is also required for new or ongoing projects that entail the processing of customer data by a third party on behalf of the Group. The PMP online platform has been set up to facilitate the submission of DPRC and to build our data inventory.
To address cyber security issues, we have a Cyber Security Committee that is responsible for managing all cyber security matters and is overseen by the General Manager of Corporate Information Technology who reports directly to the Executive Director and Chief Financial Officer.
Through early anomaly detection, we can identify suspected activities at an early stage which effectively minimises the impact. By leveraging threat intelligence and active monitoring under the ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework, any suspected activities are under tight scrutiny and are validated against their legitimacy and incident response procedures. To further improve cyber security maturity, we have commissioned a third-party consultant to monitor potential cyber incidents around the clock. The consultant has integrated global threat intelligence and built up a platform for detection capability improvement. The platform helps to minimise Towngas’ cyber risks and enables Towngas to continue innovating safely on the digital modernisation journey. To further identify potential vulnerabilities and mitigate our cyber security risks, we conduct regular penetration tests internally and third-party security assessment annually on our applications.
In the event of a cyber incident, we have developed a Cybersecurity Incident Response Plan (CIRP) with five response playbooks covering the top five cyber security incidents including data leakages and cyberattacks. The CIRP provides employees with standardised and consistent processes for responding to and recovering from various cyber incident scenarios that would have a severe impact on our business processes. In the event of a suspected cyberattack, our Cyber Security Committee will initiate the incident response process, contain the data leakage and contact the Cyber Security Centre of the Hong Kong Police Force and other security experts. We also test our incident response procedures at least annually.
To ensure business continuity and disaster recovery capability, we conduct an annual disaster recovery drill on a backup site.