01 | ABOUT NEXG 02 | OUR LEADERSHIP 03| OUR PERSPECTIVE 04 | SUSTAINABILITY 05 | GOVERNANCE 06 | FINANCIAL STATEMENTS 07 | OTHER INFORMATION ANNUAL REPORT 2026 Sustainability STATEMENT (Cont’d) OUR PROGRESS (CONT'D) WHY IS THIS IMPORTANT? OUR PROGRESS OUR APPROACH ETHICAL BUSINESS PRACTICES (CONT'D) DATA PRIVACY AND SECURITY Following a strategic transition in December 2025, NexG adopted a risk-based prioritisation strategy for its ABAC training rollout to ensure immediate impact in the most critical areas of the business. During this initial phase, the Group focused its efforts on High-Risk categories, including Executives, Managers, and office-based personnel, whose roles involve direct oversight of procurement, business development, and corporate governance. The ABAC awareness sessions for Non-Executive employees, particularly in production and operations, were not fully rolled out during the year amid logistical adjustments during the period. While this targeted approach ensures that those with the highest potential exposure to integrity risks are prioritised, NexG remains fully committed to expanding this training to 100.0% of the workforce. We are currently developing a phased execution plan to extend these modules to our non-executive production and operations teams in the upcoming reporting cycle, ensuring a unified culture of ethics and transparency across every level of the organisation. Data security is central to how NexG operates. Given the nature of our work of producing and personalising secure documents for government agencies and financial institutions, the information processed through our operations is sensitive and demands the highest standards of protection. Any compromise, whether through a cyberattack, system vulnerability or human error, could have consequences for our clients and the individuals these documents serve. With this in mind, maintaining robust data privacy and security practices is essential to operating as a trusted partner and sustaining the confidence our clients place in us. In FY2026, we recorded zero (0) substantiated complaints concerning breaches of customer privacy and losses of customer data. Protecting data at NexG requires discipline across people, processes and technology; we approach it as an ongoing operational responsibility. All data handling practices adhere to applicable laws and regulatory standards, including the Personal Data Protection Act 2010 ("PDPA"). Our ICT infrastructure forms the technical backbone of our security posture. We maintain and update firewall protections, access controls and cybersecurity protocols across the Group, supported by routine IT security audits and vulnerability assessments to identify and close gaps before they can be exploited. In FY2026, this included the renewal of firewall licences, periodic updates to network storage systems, and the progressive upgrade of employee devices to the latest operating system versions. For divisions handling customer data directly, additional controls are in place. Within the RPS division under DCSB, the receiving and processing of customers' data are governed by the Group's Data Loss Prevention ("DLP") Policy and SOPs. The division also holds a Payment Card Industry Data Security Standard ("PCI DSS") certification, demonstrating compliance with internationally recognised benchmarks for secure data handling. Employees Received Training on Anti-Corruption FY2024 FY2025 FY2026 Board of Directors (excluding Executive Directors) 100.0% 71.4% 83.3% Top Management 100.0% 61.9% 93.3% Middle Management 65.5% 87.5% 93.3% Executive 79.7% 87.5% 71.3% Non-Executive 72.4% 73.3% 12.4% FY2024 FY2025 FY2026 Number of substantial complaints concerning breaches of customer privacy and losses of customer data 0 0 0 In FY2026, anti-corruption training was conducted across all employee levels. 84
RkJQdWJsaXNoZXIy NDgzMzc=