Cybersecurity organizational structure
Based on the emphasis on cybersecurity risks and the planning of resource allocation for cybersecurity management, the Chief Executive Officer has directed the establishment of a dedicated Information Security Unit responsible for promoting cybersecurity policies and resource coordination, with annual reports to the Board of Directors. The dedicated cybersecurity personnel ensure that all management standards and control measures are effectively and consistently implemented. The organizational structure of the Group's Cybersecurity and Information Department is illustrated below.
The organizational structure of the Group's Cybersecurity Department

Cybersecurity Policy and objectives
To meet internal security standards and the requirements of external regulatory bodies, the Group has established cybersecurity management procedures and set ten cybersecurity objectives, with results tallied each month and relevant records maintained.

The specific information security protection and control measures
- Conducting regular system and equipment vulnerability scans and penetration tests each year, remediating identified medium- and high risk vulnerabilities, and implementing privileged access management, data loss prevention management, computer hard drive encryption, server endpoint detection and response systems, and threat detection and response services. These measures are designed to protect against external intrusion and mitigate the risk of internal leakage of sensitive data. The Group continuously monitors security event logs through a security incident management system to achieve real-time anomaly detection and reinforce overall cybersecurity management mechanisms.
- The Group schedules at least two cybersecurity awareness training sessions each year, offering online E-learning courses and post-training assessments in Chinese, English, and Thai. Additionally, at least six social engineering drills are conducted annually. Awareness initiatives are promoted via email, instant messaging, and digital bulletin boards to strengthen employees' understanding of cybersecurity and share recent incidents and examples to raise awareness. Employees encountering any issues or concerns related to information security incidents, vulnerabilities, or suspicious activities can report them through the internal IT Helpdesk, enabling the Information Security Department to promptly initiate incident investigation and response mechanisms. In the event of any impact, the Company maintains Cyber Risk Insurance / Fraud Protection Insurance to reduce or transfer potential losses related to cybersecurity events.
- The Group plans to conduct annual renewal certification of the Information Security Management System and continuously expand the scope of certification to include engineering and manufacturing processes. In November 2025, the upgraded "ISO 27001:2022" certificate was obtained, with the certificate valid from December 22, 2024, to November 16, 2026. During this period, annual recertification audits by independent verification bodies are conducted to ensure the continued effectiveness of the Information Security Management System. In addition, to comply with automotive cybersecurity regulatory requirements, the Group has adopted the international automotive cybersecurity standard TISAX (Trusted Information Security Assessment Exchange), and obtained certification on August 19, 2025, valid until May 19, 2028. Subsequent regular evaluations by third-party organizations will also be conducted to ensure its continued validity.

Cybersecurity Management Practices and Resource Allocation
The Group has established an Information Security Management System (ISMS) and maintains the validity of its ISO 27001 certification through annual recertification audits. To continuously enhance system security and reduce risks, the Group has formulated a future road map execution plan for the communication security management system, which is reviewed and updated annually. Additionally, the Group strengthens security controls, oversight mechanisms, and the maintenance of security measures.
In accordance with the Cybersecurity Policy and objectives, the Group has developed its Information Security Management System and related information management procedural standards, which are verified annually by independent third parties to ensure the system remains effective. Following the PDCA (Plan-Do-Check-Act) principles of continuous improvement under the Information Security Management System, the Group has established the cybersecurity risk management and continuous improvement framework and the related specific resource allocation and management measures as follows:
.
Internal audit of cybersecurity
The Audit Department defines assessment items based on cybersecurity risks, completed cybersecurity assessments and audits in April and October 2025, and completed follow-up and review of improvement items. The results and all audit reports have been submitted to the Audit Committee and the Board of Directors. In addition, the annual third-party cybersecurity certification audits and external network security computer audits were completed in September and October 2025, respectively.
Product Development and Manufacturing Security
Primax's R&D and manufacturing units strictly adhere to the Group's Cybersecurity Policy and customer expectations, integrating international cybersecurity regulatory trends into core operational processes. For the Group's diverse lines of PC Peripherals and Non-PC Peripherals, the Company implements tiered management based on their information security risk characteristics. For electroacoustic products, OEM brand customer products, and wireless connector products, mandatory code reviews and source code scanning (SAST) are enforced before software or firmware updates go live. This is to proactively identify and reduce information security risks at the source, ensuring Customer Requirement Compliance and relevant third-party certifications.
Throughout the R&D, manufacturing, and final product shipment phases, the Group adheres entirely to the cybersecurity principles required by customers, rigorously safeguarding product confidential information and manufacturing technologies. If any security concerns are identified, corrective and preventive mechanisms are immediately activated, with remediation and optimization conducted while maintaining smooth manufacturing and subsequent processes, to ensure product information security. In addition, the Company places significant emphasis on post-shipment product information security. Depending on product characteristics and customer requirements, preventive measures such as software testing and physical circuit isolation are implemented to rigorously prevent potential security threats during product use, including the insertion of malicious code, thereby reducing the risk of user data breaches.
In aligning with international standards and forward-looking regulations, the Company's wireless products are rigorously designed and verified in accordance with the EU Radio Equipment Directive (RED EN-18031) to ensure compliance with cybersecurity requirements. Subsequently, the Cyber Resilience Act (CRA) of the European Union will be followed to implement "secure design and Production and Manufacturing," providing continuous vulnerability patches and security updates throughout the Product Life Cycle (IEC-62443).

Customer Privacy and Personal Data Protection
Primax Group complies with applicable domestic and international personal data protection laws and regulations and has established a Privacy Policy. This policy applies to: 1. Customers, suppliers, and contractors, 2. Visitors browsing the official website or visiting in person, and 3. Job applicants. The Cybersecurity and Information Department serves as the dedicated unit responsible for personal data protection management. Both Primax and Tymphany each have one designated staff member responsible for establishing relevant regulations, handling complaints, and managing operational processes related to personal data protection.
Primax respects the rights of data subjects to exercise their legal entitlements concerning personal data. A dedicated contact email is provided on the Company website. If complaints are received or any personal data breaches are identified, the matter will be handled in accordance with the applicable policies, including the Personal Data Protection Policy, Supplier Code of Conduct, or Customer Data Confidentiality Agreement, and any necessary corrective or disciplinary actions will be taken. Additionally, personal data protection-related training is planned, and every employee is required to complete an online general course. In 2025, general and cybersecurity-related training sessions included a total of 4,985 participants, and there were zero incidents of personal data violations or customer privacy breaches, including complaints.