48 SECTION 04 : CORPORATE GOVERNANCE Our Performance The Group’s community investment initiatives and contributions during the reporting period are summarised below: Community Investment FYE 2026 FYE 2025 FYE 2024 Total amount invested (RM) 14,850 Nil 8,193 Estimated number of beneficiaries 1 150 Nil Nil 1. The number of beneficiaries is based on the Group’s best estimate, given the challenges associated with determining the exact number of beneficiaries for certain initiatives. DATA PRIVACY AND CYBERSECURITY Why is it important The Group relies on information systems and digital platforms to support its day-to-day operations, including the management of employee, customer and business information. Cybersecurity incidents, unauthorised access, data breaches or system disruptions may affect operations, expose sensitive information and result in regulatory, financial or reputational consequences. Our Approach The Group maintains information security and cybersecurity policies and controls to support the protection of business information, employee records, financial information and other operational or commercially sensitive data. The Group also recognises the importance of complying with applicable data protection requirements, including the Personal Data Protection Act 2010 (“PDPA”). The Group’s key data privacy and cybersecurity measures are summarised below: Area Key Measures Access Control • Access to systems and information is restricted based on user roles and responsibilities. Cybersecurity and System Protection • Security measures, including firewalls, antivirus protection and other system safeguards, are maintained to reduce the risk of unauthorised access, malware and cyber threats. Backup and Recovery • Backup processes are maintained for critical systems and information to support data recovery and business continuity in the event of system disruption or data loss. Monitoring and Incident Management • IT-related incidents, suspicious activities and potential data-related incidents are monitored and escalated, where appropriate, to support timely response and remediation. • Periodic internal reviews and IT audit activities are conducted over relevant systems and controls, including areas relating to financial information and system access controls. Employee Awareness • Employees are periodically reminded of cybersecurity risks, password security, phishing awareness and the responsible use of company information and systems. Our Performance During the reporting period, the Group received no substantiated complaints from regulatory authorities, customers or other external parties concerning breaches of customer privacy or losses of customer data. Substantiated complaints concerning breaches of customer privacy and losses of customer data 1 FYE 2026 FYE 2025 FYE 2024 Target Nil Nil Nil Maintain zero substantiated complaints 1. Substantiated complaints refer to complaints formally received from regulatory authorities, customers or other external parties relating to confirmed breaches of customer privacy, unauthorised disclosure of personal data, or loss of customer information arising from the Group’s operations, systems or employees during the reporting period. Sustainability Statement (Cont’d)
RkJQdWJsaXNoZXIy NDgzMzc=