Data Security and Privacy
Commitment to data security and privacy by implementing stringent control mechanisms and enhancing our data management systems to mitigate the risk of data breaches while fostering a tech-savvy organisational culture.
Why It Matters to Us
Data drives our operations and enables us to make more effective business decisions. However, we are aware that we risk data breaches and losses without proper data protection measures while mishandling private information entrusted to us will reduce stakeholders’ trust. Thus, we aim to implement tight control mechanisms to reduce privacy violations and data mismanagement. We also want to improve our data management systems to enhance employee work efficiency, fulfil our regional expansion needs and instil a tech-savvy culture within the organisation.
Key Strategies
01
System & SOP Upgrades - To upgrade our data management systems and integrate better SOPs and best practices for greater data efficiency, security and work outcomes.
02
Risk Assessment & Mitigation - To review data management systems against emerging cybersecurity threats and risks, making systematic changes to improve cybersecurity preparedness.
03
Policy & Governance - To implement policies, governance structures and training sessions to ensure adherence to the latest data privacy and security regulations and maintain high standards of data handling ethics throughout.
Initiative Highlights
01
Zero substantiated complaints concerning breaches of customer privacy and losses of customer data in 2023
02
Enhanced our data server security by moving data warehousing offsite, improving accessibility and scalability and reducing on-premises security breach risks.
03
Adopted Microsoft Office 365, which enabled better data centralisation, change tracking, retrieval and sharing
04
Staff training was conducted to promote the adoption of our new SOPs and systems
05
Adopted stricter folder and file privacy access based on superior approval to promote data security.
06
Thorough analysis and assessment of our data management systems and performed penetration to evaluate system resilience against cyberattacks
07
Enacted policies to strengthen data and cybersecurity governance
08
Established procedures such as limiting email attachment size to reduce data exposure risks
09
Suppliers and external partners are evaluated to ensure their data handling procedures and security precautions meet our compliance requirements
In The Pipeline
Conduct necessary data risk assessments, including penetration tests, to identify data security improvement needs
Implement tighter data management control SOPs
Enact data breach and crisis management procedures
Conduct data protection and data management training
