KOR Open menu
Close menu

Information Security

SK Square promotes the establishment and dissemination of information security principles, the operation of an information security organization, and information security training in order to protect the company’s information as well as that of customers.

Information Security Policy

SK Square has established and shared the Information Security Regulations to protect the business and customer information collected during the business process. The Information Security Regulations apply to all employees and include the principles for internal information management and cyber security compliance, and stipulate information security management system operating standards for systematic management of information assets.

Information Security Regulations

  • Information security management system operating standards for systematic management of information assets, etc.

ISO27001
(Information Security Management System Certification)

Information Security Regulations
  • Information security management system operating standards for systematic management of information assets, etc.
ISO27001
(Information Security Management System Certification)

Status of Information Security Policy Establishment for Major Subsidiaries

Proportion of subsidiaries with established information security policies
Unit %
2024 1001)
Category Unit 2024
Proportion of subsidiaries with established information security policies % 1001)

1) Seven major consolidated subsidiaries as the basis for assessment (11STREET, ONE store, SK planet, Dreamus Company, TMAP Mobility, FSK L&S, Incross)

Information Security Organization

SK Square has appointed an executive-level Chief Information Security Officer (CISO), who oversees and manages duties related to the company's information security, including the establishment of information security policy, management of the dedicated information security organization and operation of the Information Security Committee, information security vulnerability assessments, risk evaluations and preventive measures, continuous monitoring of security threats, and response to security incidents and recovery.

[CEO] [Information Security Committee Head of Information Security (executive) Head of HR (executive) Head of Legal Affairs (executive) Head of Ethical Management Information Security/IT Managers] [Information Security (dedicated organization) CISO (executive)] [
  • IT Manager(PL)
  • Information Security Manager(PL)
  • Physical Security Manager(PL)
]

Key Roles

Category Key Roles
Information Security Committee Discuss and approve information security policies, review risk assessment results, and authorize security investments
Chief Information Security Officer (CISO) Oversee vulnerability assessments and risk evaluations, manage security audits, and oversee response to security incidents and recovery
Dedicated organization
(IT, Information Security, Physical Security)
Continuous monitoring and threat detection, vulnerability analysis, security awareness training, and response to security incidents
Category Key Roles
Information Security Committee Discuss and approve information security policies, review risk assessment results, and authorize security investments
Chief Information Security Officer (CISO) Oversee vulnerability assessments and risk evaluations, manage security audits, and oversee response to security incidents and recovery
Dedicated organization
(IT, Information Security, Physical Security)
Continuous monitoring and threat detection, vulnerability analysis, security awareness training, and response to security incidents

Information
Security
Incident
Response
System

SK Square has built and operates a robust information security risk management system to protect information from external threats and prevent internal data leaks. To proactively respond to the rapidly changing security threat landscapes, SK Square has implemented multi-layered security solutions, including endpoint security, monitoring security, network security, data security, and system security, supported by a 24/7 real-time monitoring system. To systematically prevent and respond to information security incidents, SK Square utilizes various solutions to detect and address threats at an early stage. Through a phased response system, the company has established swift and efficient processes for incident recognition and response. In the event of an incident, the Information Security Department assesses the impact and severity level of the incident and established response plans based on its severity to take prompt action. By operating this comprehensive information security risk management system, SK Square ensures the safe protection of critical information assets for both customers and the company while contributing to the establishment of a sustainable business environment.

Severity of Information Security Incidents

Fatal - Disruption of core business functions; severe impact on business operations Critical - Partial disruption of business functions; partial impact on business operations Minor - No or minor damage; no impact on business operations

Phased Information Security Incident Response System

Prevention
Action Plan
Threat detection
  • 24/7 real-time monitoring system operation
  • Operation of multi-layered security solutions (endpoint, network, data security, etc.)
  • Regular vulnerability scans and assessments
Prevention measures
  • Dissemination of security policies and guidelines
  • Regular training and education for employees
Incident response
Action Plan
Incident recognition
  • Monitoring and checking security events and alerts
  • Immediate reporting of incidents to relevant departments and officer
Incident response
  • Isolation of affected systems and implementation of measures to prevent further damage
  • Identification of the cause and scope of impact of the incident
  • Development and execution of response plans based on severity levels
Follow-up management
  • Preparation of incident analysis reports and reporting to management
  • Establishment and implementation of recurrence prevention measures
  • Improvement of security systems and policies
Stage Action Plan
prevention Threat detection
  • 24/7 real-time monitoring system operation
  • Operation of multi-layered security solutions (endpoint, network, data security, etc.)
  • Regular vulnerability scans and assessments
Prevention measures
  • Dissemination of security policies and guidelines
  • Regular training and education for employees
Incident response Incident recognition
  • Monitoring and checking security events and alerts
  • Immediate reporting of incidents to relevant departments and officer
Incident response
  • Isolation of affected systems and implementation of measures to prevent further damage
  • Identification of the cause and scope of impact of the incident
  • Development and execution of response plans based on severity levels
Follow-up management
  • Preparation of incident analysis reports and reporting to management
  • Establishment and implementation of recurrence prevention measures
  • Improvement of security systems and policies

Step-by-Step Response System

Stage Action Plan
Threat detection
  • Upon detecting signs of an information security incident (hacking, malware, theft/damage/leakage of information assets), immediately report to the Information Security Department
Damage analysis
  • Depending on incident severity, operate the Integrated Information Security Situation Room, assess the level of impact, and analyze the cause and scale of damage
Preventive measures & response
  • Carry out technical and managerial measures for recovery (preventing the spread of damage and restoring systems) and perform company-wide Risk Management duties, including responses to the media, government, and investigative agencies
Results reporting
  • Compile the cause, response details, and recurrence-prevention measures; submit to the Information Security Committee and share company-wide; report to the Board of Directors when necessary
Stage Action Plan
Threat detection
  • Upon detecting signs of an information security incident (hacking, malware, theft/damage/leakage of information assets), immediately report to the Information Security Department
Damage analysis
  • Depending on incident severity, operate the Integrated Information Security Situation Room, assess the level of impact, and analyze the cause and scale of damage
Preventive measures & response
  • Carry out technical and managerial measures for recovery (preventing the spread of damage and restoring systems) and perform company-wide Risk Management duties, including responses to the media, government, and investigative agencies
Results reporting
  • Compile the cause, response details, and recurrence-prevention measures; submit to the Information Security Committee and share company-wide; report to the Board of Directors when necessary

Roles by Function in the Event of a Security Incident

Function Role
Reporting (all employees / unit heads)
  • Immediately report any signs of an information security incident to the Information Security Department; unit heads promptly report any security vulnerabilities in their unit’s information assets
Information Security Department (under the CISO)
  • Control and disseminate incident information and operate the Integrated Information Security Situation Room (depending on severity); analyze the cause and scale of damage and implement technical and managerial measures for recovery
Company-wide Crisis Response Body
  • Monitor the situation with the media, government, and investigative agencies and carry out duties under the company-wide Risk Management framework
Information Security Committee (Chair: CISO)
  • Review breach-response measures and recommend rewards or disciplinary action for those responsible (in consultation with the responsible department)
Function Role
Reporting (all employees / unit heads)
  • Immediately report any signs of an information security incident to the Information Security Department; unit heads promptly report any security vulnerabilities in their unit’s information assets
Information Security Department (under the CISO)
  • Control and disseminate incident information and operate the Integrated Information Security Situation Room (depending on severity); analyze the cause and scale of damage and implement technical and managerial measures for recovery
Company-wide Crisis Response Body
  • Monitor the situation with the media, government, and investigative agencies and carry out duties under the company-wide Risk Management framework
 Information Security Committee (Chair: CISO)
  • Review breach-response measures and recommend rewards or disciplinary action for those responsible (in consultation with the responsible department)

In-place Security Solutions

Endpoint Security - Printout security, Permanent file deletion Monitoring Security - Network IDS (Intrusion Detection System), Antivirus/EDR Network Security - Wireless LAN intrusion prevention, Malicious site blocking, SSL visibility Data Security - DLP (Data Loss Prevention), Email security, File transfer control System Security - Server/DB access control

Status of Information Leakage Damage

Number of data leaks or breaches
Unit Case
2023 0
2024 0
2025 0
Category Unit 2023 2024 2025
Number of data leaks
or breaches
Case 0 0 0

Roadmap for Improving Information Security Incident Response System

2023~2024 Stabilize information security system Establish information security system Obtain information security certification 2025~2026 Improve information security system Raising Employees’ Information Security Awareness Continuing to achieve zero information leakage incidents 2027~ Secure a global-level of information security management system

Information Security Management System

SK Square has identified information security as a key priority across all areas of its business operations and continues to strengthen corporate trust by enhancing information security for customers and other stakeholders. In 2026, the company renewed its ISO 27001 certification, the international standard for information security, based on its Information Security Management System (ISMS). The certification scope covers all investment activities and portfolio management operations, which are core business activities of SK Square (covering 100% of the company's total revenue). In addition, SK Square evaluates its security framework through annual surveillance audits and triennial recertification audits based on 14 information security domains and 144 detailed control items. Through this process, the company maintains an operating framework that meets global security standards.
SK Square also encourages major portfolio companies to obtain information security management certifications. As of 2025, portfolio companies representing more than 77.3% of consolidated revenue held either ISO 27001 or ISMS-P certification. Furthermore, SK Square conducts annual group-level security assessments through the SUPEX Council. These assessments evaluate the effectiveness of the company's security policies and systems. In 2025, SK Square received a "Good" rating in the group-level security management assessment.

Scope of SK Square Information Security Management System Certification (2025)

SK Square
Certification Type ISO 27001
Certification Scope Information security and management system related to investment activities and portfolio management
Coverage (% of owned operations), 20251) 100%
Category Certification Type Certification Scope Coverage (% of owned operations), 20251)
SK Square ISO 27001 Information security and management system related to investment activities and portfolio management 100%

1) SK Square operates a single business site—its headquarters—and the entire headquarters, including its core business areas of investment activities and portfolio management, is certified to ISO/IEC 27001. As a result, the certification scope covers 100% of the company's owned operations, and these activities account for 100% of the company's total revenue.

Scope of Information Security Management System Certifications at Portfolio Companies (2025)

Certification Type1) Certification Scope
11STREET
ISO 27001 11STREET service operations
ISMS-P
Coverage
(% of consolidated revenue), 20252)
77.3%
(based on 2025 consolidated revenue)
ONE store
ISMS-P App marketplace service operations
Coverage
(% of consolidated revenue), 20252)
77.3%
(based on 2025 consolidated revenue)
SKPlanet
ISMS External services such as T-Ring and T-Academy
ISMS-P Ok Cashbag, Syrup
Coverage
(% of consolidated revenue), 20252)
77.3%
(based on 2025 consolidated revenue)
TMAP Mobility
ISMS Services including designated driver, payment services, and public transportation
ISMS-P All services of TMAP Mobility
Coverage
(% of consolidated revenue), 20252)
77.3%
(based on 2025 consolidated revenue)
Category Certification Type1) Certification Scope Coverage (% of consolidated revenue), 20252)
11STREET ISO 27001 11STREET service operations 77.3%
(based on 2025 consolidated revenue)
ISMS-P
ONE store ISMS-P App marketplace service operations
SKPlanet ISMS External services such as T-Ring and T-Academy
ISMS-P OK Cashbag, Syrup
TMAP Mobility ISMS Services including designated driver, payment services, and public transportation
ISMS-P All services of TMAP Mobility

1) ISMS-P is a certification administered by the Korea Internet & Security Agency (KISA) that verifies whether information security and personal data protection measures and activities comply with certification standards. It includes the control requirements covered under ISO 27001.

2) On a consolidated-revenue basis, 11STREET (which holds ISO 27001) accounts for 31.0% of revenue.

External independent audit

SK Square conducts regular external independent audits of its information security policies and overall cybersecurity to ensure systematic management of information protection and security. As part of the ISO 27001 certification renewal process for its Information Security Management System, external professional organizations review the adequacy of the company's information security policies and management systems. In addition, the company regularly conducts vulnerability analysis and assessments in collaboration with external experts to proactively respond to security threats. SK Square will continue to advance its information protection and security management systems through close collaboration with external experts.

Expert verification Verification frequency Verification & Audit Coverage
Information Security Management System (ISMS)
Verification of the adequacy of management systems including information security policies through the ISO 27001 certification renewal process Annually 100%
(including major business activities such as investment operations)
Cybersecurity
Verification of information security level through vulnerability analysis and assessment processes in collaboration with external experts Annually 100%
(including major business activities such as investment operations)
Category Expert verification Verification frequency Verification & Audit Coverage
Information Security Management System (ISMS) Verification of the adequacy of management systems including information security policies through the ISO 27001 certification renewal process Annually 100%
(including major business activities such as investment operations)
Cybersecurity Verification of information security level through vulnerability analysis and assessment processes in collaboration with external experts

Information Security Monitoring

SK Square conducts a variety of monitoring activities to assess compliance with information security policies and processes and to verify the implementation status of information security measures. To this end, the company performs security diagnostics and audits of its information security management system and carries out simulation exercises and inspections for employees to continuously evaluate and improve its internal security posture. In addition, annual activities such as penetration testing, phishing email simulation training, and DDoS response drills help strengthen practical response capabilities against real-world security threats. Through these efforts, SK Square prevents damage caused by data breaches and cyberattacks and reduces the likelihood of information security incidents.

Information Security Monitoring Activities

[Diagnosis & Audits]
Diagnosing security policy and process implementation (annually)
Security diagnosis for information system (annually)
Audits of information security policies and systems by the group audit organization (annually)
[Training & inspection]
Breach response training such as DDOS simulation training (annually)
Detection of events such as malicious mail and malicious code inflow (as needed)
Mail security, file import / export, print security check (monthly)
PC security check (as needed)

Status of Information Security Incident Response Training and Monitoring

Company’s own information security training sessions
Unit Session
2022 1
2023 1
2024 1
Company’s own information security monitoring / checks
Number of detected events Number of actions taken for issues
Unit Event Action
2022 752 7
2023 585 9
2024 4,275* 11
Category Unit 2022 2023 2024
Company’s own information security training sessions Session 1 1 1
Company’s own information security monitoring / checks Number of detected events Event 752 585 4,275*
Number of actions taken for issues Action 7 9 11

* The number of detected events increased due to the expanded scope of monitored solutions compared to 2022 and 2023.

Personal Information Management

As an investment-focused company, SK Square does not directly collect personal information from individual customers in the ordinary course of its business operations. However, in the process of providing online streaming services for shareholders' meetings, the company collects certain personal information—including name, date of birth, gender, mobile phone number, and email address—to verify eligible viewers and issue authentication codes. All collected personal information is managed in accordance with strict protection standards.
When collecting personal information, SK Square provides prior notice of the purpose of collection and obtains consent before processing the data. Once the intended purpose has been fulfilled, the information is deleted without delay to minimize risks associated with unnecessary data retention. The company's Privacy Policy is publicly available on its official website (www.sksquare.com), ensuring easy access for all stakeholders. In addition, SK Square regularly reviews the information security systems of its subsidiaries to strengthen their personal data protection capabilities. SK Square has established and strictly applies an opt-in principle, under which the explicit prior consent of data subjects must be obtained whenever personal information is used for purposes other than the original purpose of collection or provided to third parties.
SK Square also continues to advance its standards for identifying and managing security risks. To support these efforts, the company operates an Information Security Council composed of executive officers and has designated an executive-level Chief Information Security Officer (CISO) to ensure clear accountability for personal information and data protection.

Customer Information & User Data

Instances of customer information used for secondary purposes
Unit Cases
2023 0
2024 0
2025 0
Category Unit 2023 2024 2025
Instances of customer information used for secondary purposes Cases 0 0 0

Personal Information Management System

Collection and Use of Personal Information
  • Article 1(1) of the Privacy Policy specifies the categories of personal information collected, purpose of collection, processing methods, and retention period
  • Explicit prior consent (opt-in) from the data subject must be obtained when personal information is used for purposes other than those originally intended
  • Consent is required if the purpose of use changes (Personal Information Protection Act, Article 18)
  • Retention and usage periods must comply with applicable laws and agreed terms
  • For children under the age of 14, consent from a legal guardian is required
Management of Personal Information
(Deletion, Correction, Supplementation, Change Requests, etc.)
  • Guarantee of right to request access to personal information (Privacy Policy Article 9, Paragraph 3)
  • Guarantee of data subject’s right to self-determination (Privacy Policy Article 10, Paragraph 2)
Access Control for Personal Information
  • Management of work-related information via virtual desktops with access control for non-employees
  • Restriction of data access via document passwords and server access controls
Mechanism for Raising Concerns Related to Personal Information
  • Operation of inquiry channels for personal information protection-related issues, complaints, and remedies through the personal information protection officer and relevant departments
  • Specification of the personal information protection officer and contact information, including phone number and e-mail (Privacy Policy Article 9, Paragraph 1)
Provision of Personal Information to Third Parties
  • Prohibition on provision of personal information to third parties without the data subject’s opt-in or legal basis (Privacy Policy Article 2, Paragraph 1)
Deletion of Personal Information
  • Specification of a two-year retention period in Privacy Policy Article 1, Paragraph 1
  • Specification of deletion procedures and methods for personal information after retention period expiration (Privacy Policy Article 4, Paragraphs 1 and 3)
Category Description
Collection and Use of Personal Information
  • Article 1(1) of the Privacy Policy specifies the categories of personal information collected, purpose of collection, processing methods, and retention period.
  • Explicit prior consent (opt-in) from the data subject must be obtained when personal information is used for purposes other than those originally intended.
  • Consent is required if the purpose of use changes (Personal Information Protection Act, Article 18).
  • Retention and usage periods must comply with applicable laws and agreed terms.
  • For children under the age of 14, consent from a legal guardian is required.
Management of Personal Information
(Deletion, Correction, Supplementation, Change Requests, etc.)
  • Guarantee of right to request access to personal information (Privacy Policy Article 9, Paragraph 3)
  • Guarantee of data subject’s right to self-determination (Privacy Policy Article 10, Paragraph 2)
Access Control for Personal Information
  • Management of work-related information via virtual desktops with access control for non-employees
  • Restriction of data access via document passwords and server access controls
Mechanism for Raising Concerns Related to Personal Information
  • Operation of inquiry channels for personal information protection-related issues, complaints, and remedies through the personal information protection officer and relevant departments
  • Specification of the personal information protection officer and contact information, including phone number and e-mail (Privacy Policy Article 9, Paragraph 1)
Provision of Personal Information to Third Parties
  • Prohibition on provision of personal information to third parties without the data subject’s opt-in or legal basis (Privacy Policy Article 2, Paragraph 1)
Deletion of Personal Information
  • Specification of a two-year retention period in Privacy Policy Article 1, Paragraph 1
  • Specification of deletion procedures and methods for personal information after retention period expiration (Privacy Policy Article 4, Paragraphs 1 and 3)

Security Diagnosis for Subsidiaries

SK Square conducts annual security assessments covering personal data protection and IT security to enhance the security management capabilities of its subsidiaries and manage security incident risks. Through these assessments, the company identifies information security vulnerabilities and carries out improvement recommendations and follow-up reviews of implementation status. In 2025, in accordance with the Group’s security management framework, SK Square conducted document-based assessments of 11STREET, TMAP Mobility, ONE store, SK planet, and FSK L&S. In addition, one penetration test was performed on externally exposed systems, and corrective actions were implemented to address identified vulnerabilities. In 2026, SK Square plans to further strengthen information security management by adding on-site assessments and increasing penetration testing to twice a year.

Status of Security Assessments for Subsidiaries (2025)

Targets
  • 11STREET
  • TMAP Mobility
  • ONE store
  • SK planet
  • FSK L&S
Assessment Scope
  • Personal Data Protection
  • Personal information lifecycle management, measures to ensure data security, etc.
  •  IT Security
  • Security governance, cyber threat management, system security management, internal data leakage controls, physical security
Targets Assessment Scope
  • 11STREET
  • TMAP Mobility
  • ONE store
  • SK planet
  • FSK L&S
Personal Data Protection
  • Personal information lifecycle management, measures to ensure data security, etc.
 IT Security
  • Security governance, cyber threat management, system security management, internal data leakage controls, physical security

Awareness Improvement

SK Square provides regular information security and personal data protection training to all full-time and contract employees at least once a year. The company offers tailored training programs that reflect employees’ job responsibilities and work environments, covering topics such as personal data processing principles and procedures, incident reporting and response processes for data breaches, and internal information access control policies. Through these programs, SK Square supports the enhancement of practical security capabilities across the organization. To maximize training effectiveness, the company continuously improves its training programs by incorporating employee feedback. In 2025, a focused training program was conducted over approximately three weeks from April to May. In addition, all full-time and contract employees are required to sign an annual Information Security Pledge to reinforce accountability and encourage compliance with internal security policies. More recently, SK Square has also required Business Partners engaged in information security-related activities to complete information security training and regularly reviews their completion status. Going forward, the company will continue to strengthen security awareness among both employees and Business Partners and remain committed to building a secure information protection environment.

Information Security Training Target and Frequency

Information Security Training
Training Frequency At least once a year
Training Target Permanent /
Contract employees /
Business Partners
Malicious Email Simulation Training
Training Frequency As needed
Training Target Permanent /
Contract employees
Breach response training, such as DDOS simulation training
Training Frequency Annually
Training Target Permanent /
Contract employees
Category Training Frequency Training Target
Information Security Training At least once a year Permanent / Contract employees / Business Partners
Malicious Email Simulation Training As needed Permanent / Contract employees
Breach response training, such as DDOS simulation training Annually Permanent / Contract employees

Information Security Training Performance

Participation Rate in Information Security Training
Permanent employees
2025 100%
Contract employees
2025 100%
Business Partners
2025 100%
Category 2025
Participation Rate in Information Security Training Permanent employees 100%
Contract employees 100%
Business Partners 100%

Business Partner Information Security Management

SK Square operates a systematic management framework to strengthen the security of information handled by its business partners. All business partners collaborating with the company are required to sign information security pledges. Furthermore, the company has specified information security compliance requirements in its Supplier ESG Code of Conduct, requires partner signatures acknowledging these requirements, and conducts regular inspections to verify Code of Conduct adherence. In addition, business partners working on-site are mandated to complete information security training. Through this management framework, SK Square continuously strengthens business partner information security and data protection capabilities and proactively manages information security risks.

Status of Information Security Management for Business Partners

Information Security Pledge
Execution of an Information Security Pledge by Business Partners
Verification
Method
Verification of signed pledge at the time of contract execution
Inspection
Frequency 
As needed
Unit %
2025 100
Compliance with the ESG Code of Conduct
Compliance with information security requirements, including establishment of data protection policies, under the Code of Conduct.
Verification
Method
Regular inspections to verify compliance with data protection/​information security requirements
Inspection
Frequency 
Annually
Unit %
2025 100
Information Security Training
Mandatory completion of information security training for on-site Business Partners
Verification
Method
Review of training completion status
Inspection
Frequency 
Annually
Unit %
2025 100
Category Key Activities Verification Method Inspection Frequency Unit 2025
Information Security Pledge Execution of an Information Security Pledge by Business Partners Verification of signed pledge at the time of contract execution As needed % 100
Compliance with the ESG Code of Conduct Compliance with information security requirements, including establishment of data protection policies, under the Code of Conduct. Regular inspections to verify compliance with data protection/information security requirements Annually % 100
Information Security Training Mandatory training completion for on-site business partners Review of training completion status Annually % 100