
We continue to develop and innovate to achieve our vision of becoming a World Class Green Energy Company with the Largest Geothermal Capacity Globally by digital transformation. Nevertheless, with the increasing development and information technology utilization to support the management and operational activities of the Company, the Company became more vulnerable to cyber-attacks.
Cyber-attacks have serious consequences on the operational activities of the Company, which will eventually extend to the financial performance and reputation of the Company. We conduct regular training and dissemination sessions to increase employees’ awareness of digital security. In addition, we are consistently increasing our digital security which includes system and data protection as well as penetration test on applications used by the Company.
PGE undergoes external assessment and assurance of its information security management through ISO 27001:2022 certification, issued by the British Standards Institution (BSI) and valid until December 2026. The certification provides external assurance that PGE’s Information Security Management System is assessed against the requirements of the internationally recognized ISO 27001 standard. The ISO 27001 certification follows a three-year certification cycle, with annual surveillance audits conducted to verify continued conformity and effectiveness of the Information Security Management System, while recertification is conducted at the end of the three-year cycle.
PGE also manages and monitors its management system certifications through the Geothermal Integrated Management System (GIMS). As disclosed in the PGE Annual Report 2024, pages 228–229, GIMS is an integrated management framework that includes ISO 27001:2022 for Information Security Management, together with other relevant management standards. GIMS provides an integrated approach to audit, documentation, compliance monitoring, and continuous improvement across the Company’s management systems.
Furthermore, PGE’s GIMS roadmap shows that ISO 27001:2022 certification is maintained as part of the Company’s management system certification activities, with certification included in the roadmap for successive years. This demonstrates that information security is subject to an ongoing external certification and internal monitoring process rather than a one-time assessment

