모트렉스

Main Menu Shortcut Main Menu Shortcut

KEY POLICIES & ACTIVITIES

Information Security and Privacy

Information Security and Privacy Strategy

MOTREX respects fundamental human rights, including personal data protection and privacy, and strictly manages the Company's information assets, facilities, and IT systems.

Qualitative Goals

Enhance the information security and personal data protection management framework to global standards while ensuring data integrity and reliability.

Quantitative Goals

Establish an ISO 27001-based Information Security Management System and maintain zero security incidents.

Strategic Initiatives and KPIs

01

Information Security Management System based on ISO 27001

Establish and operate an Information Security Management System and maintain certification.

02

Security Response Drills and Corrective Measures

Enhance security preparedness through regular response drills (at least once per year).

Information Security and Privacy Governance

MOTREX operates an integrated security governance framework comprising an Information Security Committee, an Information Security Management Department, and a working-level council, under the leadership of the Chief Information Security Officer (CISO). The CISO oversees the establishment and operation of information security policies, while the Information Security Committee deliberates on key issues, develops countermeasures, and strengthens interdepartmental coordination. The Information Security Management Department is responsible for establishing and operating the information asset protection framework, ensuring the systematic implementation of information security measures.

Information Security and Privacy Policy

MOTREX has established an Information Security Policy and defined the scope of management to include all company-wide information assets, including personal information, customer and business partner information, R&D data, and trade secrets.

Information Protection Declaration

Recognizing the importance of information and data, MOTREX has established and disclosed its Information Security Declaration, which defines principles for protecting information assets, employee responsibilities, regulatory compliance, and the information security risk management framework.

Information Protection Declaration

MOTREX Co., Ltd., together with its affiliates and related companies, recognizes that information and data are core drivers of corporate competitiveness and sustainable growth.

Based on trust with customers, employees, and suppliers, the Company pledges to establish an information security management framework aligned with international standards and industry best practices, thereby enabling safe and reliable business operations.

Fundamental Principles of Information Protection

1. The Company ensures strict protection of all critical information assets against external and internal threats.

2. Information is used only within the minimum scope necessary for business purposes.

3. All systems and data are protected against unauthorized access, alteration, disclosure, and destruction.

Governance and Responsibility

1. The Company appoints a Chief Information Security Officer (CISO) to oversee information security policies and frameworks.

2. The Information Security Committee regularly supervises the implementation and performance of information security policies.

3. The Company strengthens security awareness through regular education and training and ensures that a security-conscious culture is embedded throughout the organization.

Employee Responsibilities

1. All employees shall faithfully comply with information security policies and guidelines.

2. Customer and partner information must be strictly protected, and personal use or unauthorized disclosure is prohibited.

3. Employees must immediately report any security violations or suspicious activities and actively cooperate in improvement efforts.

Compliance with Laws and Regulations

1. The Company strictly complies with applicable laws and regulations in each country and region.

2. Personal data, trade secrets, and industrial confidential information are managed in accordance with international regulatory standards and internal company policies.

Risk Management and Incident Response

1. The Company regularly conducts information security risk assessments and continuously improves its management system to address emerging threats and technological changes.

2. In the event of a security incident, the Company implements prompt response and recovery procedures to minimize damage and prevent recurrence.

This Declaration represents a commitment to be practiced by all employees of MOTREX Co., Ltd. and its subsidiaries and related companies.

We pledge to secure corporate trust, fulfill our social responsibilities, and ensure sustainable growth through these commitments.

September 18, 2025

Lee Hyung-hwan, CEO, MOTREX Co., Ltd.

Information Security Certifications

ISO 27001

Initial Certification
December 5, 2025
Application Scope

Overall IT operations, including manufacturing, R&D, design, and customer support of automotive electronic components and systems, as well as the manufacturing of vehicle chargers.

ISO/SAE 21434

Initial Certification
May 31, 2023
Certification Scope

Automotive cybersecurity management for automotive products

Information Security Reporting Channel

MOTREX operates an Information Security Reporting Center on a 24/7 basis to enable the early detection of security incidents and ensure prompt response. Potential threats—including indicators of hacking or information asset leakage—may be reported at any time through the reporting channels. All reporting channels ensure strict confidentiality regarding the identity of reporting parties and the contents of reports, and any adverse treatment or retaliation resulting from legitimate reporting is strictly prohibited.

How to Submit Information Security Reports
Submission through the MOTREX Online Cyber Reporting System Go to Cyber Reporting System
Information Security Reporting Center