- Conducted a phishing email simulation based on realistic workplace scenarios to assess employees' ability to identify and respond to suspicious emails.
- Continued to strengthen its company-wide information security management system based on the Information Security Management Policy
- Maintained Zero information security incidents since 2023 through continuous preventive information security activities.
OCI Holdings conducted its first-half 2026 phishing email simulation training to proactively respond to increasingly sophisticated email-based cyber threats and further strengthen employees' information security awareness and cyber response capabilities.
The simulation was designed based on realistic phishing scenarios reflecting today's evolving cyber threat landscape and focused on comprehensively evaluating employees' security awareness and ability to respond appropriately to suspicious emails. Based on the results, the Company is implementing follow-up training and improvement initiatives to further enhance employees' information security capabilities.
OCI Holdings operates a comprehensive information security management system based on its Information Security Management Policy, Personal Information Protection Policy, and related subordinate rules. Through this framework, the Company safeguards the confidentiality, integrity, and availability of its information assets and personal information while continuously strengthening preventive, monitoring, and incident response processes against cybersecurity threats. OCI Holdings also applies consistent information security responsibilities and requirements to all employees, business partners, and other external stakeholders, continuously enhancing its company-wide information security framework.
Supported by these ongoing efforts, OCI Holdings has maintained Zero information security incidents since 2023. Going forward, the Company will continue to advance its information security management system, institutionalize regular phishing email simulation training and security awareness programs, and foster a strong information security culture to proactively address evolving cyber threats.