Information Security
Management
As a leading developer of test instrument equipment, Chroma is committed to deepening its information security architecture through innovative technology and close collaboration with key partners, protecting the Company's critical information assets and customer data security. Facing increasingly severe cybersecurity threats, we obtained ISO 27001 information security certification in January 2022 and implemented a cycle of continuous improvement through the Plan-Do-Check-Act (PDCA) model. In December 2024, the ISO 27001:2022 certification audit was completed, with its scope extended to include subsidiary ADIVIC TECHNOLOGY CO., LTD. and the Netherlands branch. In 2025, the Company continued to develop, operate, maintain, and enhance its information security management system in accordance with the ISO 27001:2022 standard.
To enhance group-wide security management, Chroma ATE Inc. reports the implementation status of information security management to the Board of Directors on a regular basis, with the most recent report submitted at the Board meeting on October 30, 2025. The Information Security Management Office currently consists of the Information Security Audit Team, the Information Security Management Team, the Information Security Emergency Response Team, and designated information security management contacts within each business unit.
The Information Security Management Office is responsible for promoting the information security management system and executing various information security management tasks. It convenes at least one management review meeting per year to regularly review the handling of issues raised in previous audits and to examine both internal and external issues related to the information security management system, ensuring their integration into the management system.

Information Security Management Practices

According to Chroma's information security implementation model, the specific actions of information security management are as follows:
1. Cybersecurity:
- Introduce advanced detection technologies to perform network monitoring, block malicious cyberattacks, and collect cybersecurity threat intelligence to prevent the spread of computer viruses.
2. Device Security:
- Deploy endpoint behavior detection mechanisms and introduce behavior analysis management platforms for real-time monitoring and anomaly response.
- Enhance endpoint antivirus and scanning mechanisms to prevent ransomware and malicious software.
- Strengthen email systems to detect malicious software, Trojan attachments, and phishing emails.
- Monitor internet behavior and block highly dangerous malicious websites, malicious links, or file downloads.
3. Application Security:
- Establish security inspection procedures, evaluation standards, and improvement targets for application development processes. Continuously strengthen security control mechanisms for applications and patch potential vulnerabilities.
- Introduce source code scanning software to detect vulnerabilities prior to system go-live.
- Adopt multi-factor authentication for external-facing service applications.
4. Data Protection:
- Establish user password management mechanisms and network security zone segmentation to maintain access control and data security.
5. Account Management and Employee Education & Training:
- Establish password policies and require periodic updates, and regularly conduct employee information security awareness education and testing.
6. Information Security Incident Management:
- Continuously monitor and collect records of information security protection operations, collect and analyze cybersecurity intelligence, and establish information security incident reporting and handling procedures.
- Centralized monitoring of all security incidents, supported by correlation analysis and rapid response.
Chroma Information Security Implementation Model
Information security management actions are based on three key elements―personnel, technology, and processes―following the five aspects of information security management: Identify, Protect, Detect, Respond, and Recover. Combined with various information security management solutions and processes, and adopting the concept of information security maturity, the life cycle of network security risk management is covered to establish assessment benchmarks and further enhance the level of cybersecurity defense.

Information security management execution performance in 2025:
- · Conducted one drill on data center infrastructure backup functionality, including ICT infrastructure.
- Executed one business continuity drill per year covering 15 major items, including backup functionality or backup mechanisms of key information systems used in daily operations.
- Completed 64 backup data restoration verifications to ensure the availability of backup data.
- Conducted 2 internal and external system vulnerability scans and 4 social engineering drills.
- Information personnel completed 6 information security education training sessions (totaling 14 hours).
- Conducted weekly information security incident awareness campaigns (48 sessions in total) to raise employee cybersecurity awareness.
- The information unit currently holds two ISO 27001:2022 Lead Auditor certifications and one CEH (Certified Ethical Hacker) certification.
- Since October 23, 2025, multi-factor authentication (MFA) has been fully implemented across external service websites to enhance account security and reduce the risk of unauthorized access resulting from credential leakage or brute-force attacks.
- General employee information security awareness education training conducted once (2 hours). Monthly information security policy awareness and information security awareness testing are conducted to improve employees' response and alertness to information security risks. The Information Security Management Office has implemented security measures across various stages, from new employee onboarding training to daily promotion and testing. These initiatives strengthen the Company's security awareness and ensure that employees can promptly handle and respond to incidents, implement information security response mechanisms, prevent unauthorized access, reduce cybersecurity risks, and protect customer privacy.
Information security education and training

From the night of September 13 to the early morning of September 14, 2025, the Company's information security monitoring mechanism detected unauthorized access attempts to internal systems. Information security response and enhancement procedures were immediately activated. International information security partners were engaged to conduct forensic analysis, provide 24/7 monitoring, and investigate the cyberattacks. Meanwhile, the Company continues to review and strengthen security controls of its network and information infrastructure to ensure data security and integrity. Upon assessment and audit, there was no leakage of personal information or confidential or important documents or data, and the incident had no significant impact on the Company's operations.
Annual audits and supervision of information security management are conducted by an external ISO 27001 auditing organization.
Information Security Office
Richard Lin
Privacy Protection

To implement personal data protection and management, Chroma has established a Privacy Policy as the highest guiding principle for privacy protection. This Privacy Policy applies to all employees, contract personnel, suppliers, customers involved in business dealings with the Company, and any third parties using the Company's website, including subsidiaries. Subsidiaries shall supervise their respective subordinate subsidiaries in accordance with this Policy, with the aim of reducing privacy risks or mitigating the impact of privacy incidents through remedial measures.
Chroma adopts a zero-tolerance policy toward any conduct that infringes on privacy rights and personal data protection. In the event of a personal data breach, the Company will impose penalties according to the severity of the incident in accordance with the "Employee Incentive Management Procedure." Supervisors who are aware of such incidents but fail to correct or address them will also be subject to penalties. Chroma has established an internal audit mechanism, conducting regular audits to continuously improve relevant systems, and engages external professional organizations to perform periodic external audits to ensure the effective implementation of privacy protection.
