
SK ecoplant has established information security policies, including information security regulations and personal data management regulations, to safely protect the information assets of both the company and its customers. The information security regulations include detailed rules for each area, such as the “Personnel Security Standards” and “Security Audit Standards.” Under each of these rules, guidelines, manuals, and other documents have been prepared to provide specific standards for performing work tasks. In addition, to protect corporate confidentiality and customer personal data, the company operates a 24-hour monitoring system and controls access to critical data in accordance with the three principles of access control: “Need to Know,” “Least Privilege Policy,” and “Separation of Duties.”
Information security policies are periodically established and revised to reflect relevant laws and regulations as well as technological and industry trends. SK ecoplant verifies policy compliance and the adequacy of protective measures through regular security assessments, inspections, and audits. Based on this, the security management system is being continually enhanced across administrative, physical, and technical aspects. In 2025, the company revised its security regulations and personal data management regulations to clarify the composition and roles of the Information Protection Committee and Information Protection Working Council, while amending the “Physical Security Standards” to strengthen requirements for wearing physical access cards (employee ID cards). Furthermore, SK ecoplant revised the “Security System Security Guidelines” to explicitly specify the minimum retention period for security system audit logs, thereby clarifying compliance standards with relevant laws and regulations.
To strengthen the stability and reliability of its information security framework, SK ecoplant has obtained and maintains domestic and international information security certifications. To ensure a secure management system for personally identifiable information (PII), the company maintains not only ISO 27001 (Information Security Management Systems) and ISO 27701 (Privacy Information Management Systems) certifications but also the Personal information & Information Security Management System (ISMS-P) certification. In 2025, following the addition of new personal data processing systems, the company underwent an initial ISMS-P audit and expansion audits for ISO 27001 as well as ISO 27701 certifications to verify the level of administrative and technical protective measures for the new systems. Moving forward, SK ecoplant plans to continue verifying the adequacy of its management system through follow-up audits.
Status of Information Security Certifications
Category | ISO 27001 | ISO 27701 | ISMS-P |
|---|---|---|---|
Standard | International | International | Domestic |
Validity Period | Sep. 28, 2024 – Sep. 27, 2027 | Sep. 28, 2024 – Sep. 27, 2027 | Jan. 21, 2026 – Jan. 20, 2029 |
Certification | Pre-sale, occupancy, defect repair, and customer support (inquiries) services | ||
Certification |
| ||
SK ecoplant’s information protection and security organization consists of experts in information security, personal data protection, and information and communications technology, each with an average of over 17 years of experience. The organization establishes company-wide security objectives, operates an integrated information protection framework, and conducts continuous monitoring to prevent security incidents. Additionally, it assesses, inspects, and audits policy compliance within organizations responsible for security operations and execution, and responds swiftly to security incidents to prevent further damage.
The Information Protection Council, the highest decision-making body for information protection and security, is chaired by the CISO (Chief Information Security Officer), the CPO (Chief Privacy Officer), and the Location Information Manager. Together with organizations that handle customer personal data and location data—such as IT, Pre-Sales, Customer Service, and Safety—the council discusses key decision-making matters, including the status and plans for security activities in each department. In 2025, a total of four council meetings were held to discuss compliance measures related to the Act on Promotion of Information and Communications Network Utilization and Information Protection, Personal Information Protection Act, and Act on the Protection and Use of Location Information, as well as the results of implementing internal personal data management plans and the outcomes of effectiveness assessments. Starting in 2026, operations will be separated into the Information Protection Committee—a decision-making body composed of senior management—and the Information Protection Working Council, consisting of leaders and members from operational units.
The Chief Information Security Officer (CISO), Chief Privacy Officer (CPO), and Location Information Manager are responsible for directing and supervising all information security and security operations. When appointing these officers, SK ecoplant establishes and adheres to internal standards that reflect the qualification requirements stipulated in relevant laws—such as the Act on Promotion of Information and Communications Network Utilization and Information Protection, Personal Information Protection Act, and Act on the Protection and Use of Location Information—to ensure that their activities are based on professional expertise. Currently, SK ecoplant’s information protection and security officers are experts with over 13 years of experience in their respective fields, exceeding the legal qualification requirements.
Information Security Organizational Chart

Roles and Responsibilities of Information Security Officers
Category | Roles and Responsibilities |
|---|---|
Chief Information Security Officer |
|
Chief Privacy Officer (CPO) |
|
Location Information Manager |
|
SK ecoplant is proactively mitigating information security risks with the goal of achieving “Zero incidents of data breaches and violations of relevant regulations.” To this end, the company has broken down its information security activities into seven areas: personal data management, internal information leakage control, cyber threat response, location information management, cloud security, AI security, and subsidiary security management support. For each area, it has established and is managing mid- to long-term roadmaps to advance information security based on AI and the Zero Trust security model*.
* Zero-Trust security model: A network security model that assumes all internet environments are potentially vulnerable to intrusion and strengthens monitoring, authentication, and access control
Roadmap for Information Security Initiatives
Category | 2026 | 2027 | 2028 |
|---|---|---|---|
Personal Data |
|
|
|
Internal Information |
|
|
|
Cyber Threat |
|
|
|
Location Information Management |
|
|
|
Cloud Security |
|
|
|
AI Security |
|
|
|
Subsidiary Security |
|
|
|
Information Security Framework

SK ecoplant has obtained domestic and international certifications related to information security and the protection of customer personal data, including ISO 27001, ISO 27701, and ISMS-P, and operates a management system based on these certifications to safely protect customers’ valuable information assets. To improve stakeholders’ access to information regarding personal data management, a user-friendly version of the Privacy Policy has been posted to the company website. The company has also incorporated amendments to the Personal Information Protection Act into internal management plans and conducted inspections as well as improvements to further strengthen personal data protection standards. In 2025, SK ecoplant strengthened the management of personal data processing for subsidiary employees and external parties*, and conducted internal audits and improvement activities covering all personal data of customers, employees, and external parties. In 2026, the company plans to continue strengthening security systems to ensure that the personal data of employees and external parties is managed as securely as that of customers.
* External parties: Non-employees who work at or have access to SK ecoplant’s offices and sites, or who have authorization to access the company’s systems
SK ecoplant constantly detects abnormal attempts and signs of internal information leaks through its anomaly monitoring system. By optimizing internal information leakage monitoring scenarios, false positives and negatives have been reduced, while monitoring accuracy has been enhanced. Additionally, measures are being implemented to reduce the risk of external document leaks to raise employees’ security awareness. In 2025, SK ecoplant established a security model for 3D design drawings at semiconductor sites, and plans to build an information leakage monitoring system for these sites in 2026.
SK ecoplant operates a multi-layered security system and professional security monitoring 24/7 to respond to cybersecurity threats. These measures block hacking and intrusion attempts targeting IT infrastructure and information systems, while comprehensive assessments of information leakage risks are conducted and used as foundational data to advance the risk response framework. To detect security threats in real time, the company monitors monitor the dark web, ASM (Attack Surface Management)*, EDR (Endpoint Detection & Response)**, and Active Directory (AD) security solutions. Additionally, it proactively identifies and addresses hidden security risks through penetration testing conducted by white-hat hackers. In 2026, SK ecoplant plans to enhance the stability of real-time monitoring by upgrading its aging security monitoring platform and strengthen real-world response capabilities through cyber simulation exercises involving senior management.
* ASM (Attack Surface Management): A security approach that continuously discovers and manages all externally exposed assets, such as servers, domains, IP addresses, and cloud resources ** EDR (Endpoint Detection & Response): A security system that detects and responds to threats originating from PCs, servers, and other devices in real time
SK ecoplant protects customers’ location information in compliance with relevant laws and regulations. In particular, to enhance the security of customer location information, the company has established and is implementing an internal management plan that includes self-assessments of location information handling practices and related training. In 2025, the company further strengthened the security of personal location information by refining its location information protection guidelines and developing an inspection checklist that incorporates requirements for compliance with relevant laws and regulations. In 2026, SK ecoplant seeks to continue conducting internal audits of location information handling practices and pursuing improvement initiatives.
When building new cloud-based IT systems, SK ecoplant conducts a pre-assessment of security measures and, after deployment, continuously monitors system security using a Cloud Security Posture Management (CSPM) solution to manage the overall security level of its cloud environment.
In step with the proliferation of generative AI technology, SK ecoplant is establishing an AI security governance framework that balances productivity innovation with information protection. The company comprehensively reviews security controls to ensure AI is utilized primarily through approved services, while continuously evaluating the security and utility of new AI services through a whitelist management system (which allows only permitted items to pass while blocking all others).
In particular, SK ecoplant applies differentiated usage standards based on sensitivity levels for critical data, such as personal data and industrial technology data, and is strengthening post-implementation management system based on monitoring and user behavior analysis. Through the establishment of an AI security framework, employee training, and verification of generated results, the company is fostering a culture of responsible AI use, while also identifying and managing risks arising from the use of generative AI or external AI services without proper approval or control. Going forward, SK ecoplant seeks to proactively respond to environmental changes that pose threats to AI technology and security, further advancing the safety and reliability of its AI security framework.
SK ecoplant is striving to establish a company-wide, advanced information security framework by providing tailored support to strengthen the information security capabilities of its subsidiaries. For subsidiaries with relatively limited control over cybersecurity threats, the company provides a “Security Shared Service” that leverages headquarters resources, such as training and inspections. CISO councils are held with subsidiaries in the first and second halves of the year to regularly share security support measures. Additionally, cyber simulation exercises are conducted to raise information security awareness among subsidiary employees and develop improvement plans that reflect IT system vulnerability assessments and security requirements for each subsidiary.
For newly acquired subsidiaries, SK ecoplant assesses their security levels in accordance with its security management system. Based on the results, assistance is provided to establish improvement goals, identify improvement tasks, and implement them. In addition, the company assists subsidiaries in setting medium- to long-term security goals tailored to their business environment and autonomously operating their information protection and security systems.
Subsidiary Security Management System

SK ecoplant is investing in information security to strengthen its internal capabilities and respond to external security incidents. In 2025, information security investment accounted for approximately 7.2% of the total IT budget.
SK ecoplant conducts annual online information security training for all employees in addition to providing job-specific security training, such as secure coding and training for personnel handling personal data. To proactively respond to increasingly sophisticated cyber threats, the company also conducts various types of simulation exercises every year. To internalize cyber attack response capabilities, SK ecoplant conducts training that reflects real-world scenarios, such as DDoS attack response, system recovery, and encryption key changes. The company has also objectively assessed its security level through participation in two simulation exercises organized by the Korea Internet & Security Agency (KISA).