Information Security

Date:2025-07-14 Author:SMP Return to List

Data Security Management System

Amid the wave of digital transformation, Huali Industrial Group recognizes data assets as a pivotal component of corporate core competitiveness. In 2025, the Group further strengthened its data security governance framework by establishing a comprehensive protection network in compliance with the ISO/IEC 27001 Information Security Management System standard.


Management Policy and System

Under the supervision of the Board of Directors and executive management, the Group has established an Information Security Management Committee and an Information Security Implementation Team to collectively form the information security governance framework. The Information Security Management Committee, as the supreme leadership and decisionmaking body for the company's information security initiatives, is responsible for planning, formulating, and coordinating information security governance policies. The CEO serves as the convener of this committee, overseeing the overall development and implementation of information security policies. Business unit heads conduct risk identification and management in accordance with brand and corporate information security standards. The Information Security Implementation Team is tasked with the specific execution and audit of these measures across factories and subsidiaries.



Information security organization structure




Data Security Strategy



All operating factories of the Group comply with local data security laws and regulations, ensuring that policies align with the latest legal requirements, including the "Data Security Law", "Personal Information Protection Law", and international standards such as GDPR (General Data Protection Regulations). With the support and oversight of the Information Security Management Committee at the executive level, we have established and continuously update information security policy documents such as the "Information Security Policy", "Group Information Security Management Guidelines", and "Data Lifecycle
Management Procedures".We define the data lifecycle as comprising six distinct phases (as illustrated in the diagram below), including: data creation, data protection, data access, data transmission, data
archiving (backup), and data sanitization (destruction). We implement appropriate oversight and controls at each stage, strengthening security protections for critical processes such as data transmission, storage, and usage. This includes data classification, grading , encryption, and logging of data processing events. The following measures are adopted to ensure data security during storage, processing, and transmission.







Audit and Compliance



We conduct regular internal information security audits. In 2025, we underwent security assessments by Nike's security department and JLA, a third-party professional institution arranged by Adidas. Based on the risks identified in the audits, corresponding rectification plans with completion deadlines were formulated to ensure effective risk management and issue resolution.


Date risk management

Multi-layered Defense


We have established a multi-layered defense mechanism encompassing assets, data, systems, networks, and peripheral environments (as illustrated). All servers, workstations, personal computers, laptops, and other assets are equipped with MDR (Managed Detection and Response)/EDR (Endpoint Detection and Response) endpoint protection systems, providing anti-intrusion detection and antivirus services.
Additionally, we regularly engage professional information security vendors to conduct vulnerability scans and penetration tests. Identified vulnerabilities are promptly remediated through targeted improvements to eliminate potential risks, thereby ensuring the security of our application systems and network infrastructure.

Multi-layered Defense





Information Security Vulnerability Analysis


We engage a third-party vendor on a quarterly basis to conduct internal network vulnerability scans across our group. Scanning is performed using the Nessus platform and the vendor’s proprietary penetration testing tools, targeting the internal networks of specific facilities. Vulnerabilities rated as Critical and High are prioritized for remediation and controlled on an expedited basis.

Risk Description: The risk classification method is based on the CVSS score for critical, high, medium, low, and information scoring. The classification table is as follows:



Scanning Results in 2025




Data Encryption
For outbound transmission of critical data, we deploy the Data Loss Prevention (DLP) system to encrypt files including core R&D data, financial data and employees’ personal information. This prevents corporate data from being leaked via removable storage devices or unauthorised third‑party sharing and storage. During the reporting period, we optimised data‑leakage prevention technologies and implemented full‑life‑cycle encrypted storage and transmission for critical data.
Cybersecurity Management
We enforce strict internet‑usage rules for all personnel. Sangfor internet behaviour management appliances are deployed at all manufacturing sites to restrict access to specified websites, communication software and applications. This mitigates risks of downloading suspicious programmes from unauthorised or malicious websites and software, and safeguards the Group’s internal network security.
Access Control
To secure corporate data stored within information assets, critical systems are protected by two‑factor authentication for SSL‑VPN accounts together with external‑network access prohibition, alongside upgraded on‑premises firewalls.


Security Awareness Training
To strengthen the information‑security awareness of all employees, information‑security modules are mandatory in onboarding training for new hires. The Information Security Department further enhances training and awareness‑raising through weekly information‑security meetings, internal phishing email simulations, targeted training for non‑compliant staff, and monthly site‑level information‑security bulletins. These initiatives equip employees with information‑security knowledge, facilitate risk governance, and build up the protection competency of specialised teams.
In 2025, multiple information‑security training sessions were delivered covering new recruits, employees with information‑security violations, IT staff and system developers, with nearly 300 participations recorded.

Information Security Awareness Enhancement Training




Data Security and Privacy Protection Performance Indicator Table




AI Security and Governance

As artificial intelligence transitions from the exploratory phase to full integration into core business operations, Huali Group has deeply embedded AI into R&D, production, supply chain, and other critical functions. At the same time, risks such as algorithmic bias, data breaches, and model attacks are becoming increasingly prominent. Global regulatory frameworks are gathering pace – the EU AI Act has entered its phased implementation, China's AI Safety Governance Framework 2.0 was officially released in 2025, and the ISO 42001 international standard offers enterprises systematic guidance for AI governance. Huali Group fully recognises that only by advancing intelligent transformation on a foundation of security and trustworthiness can it truly unlock the full potential of AI technology.

In 2026, Huali Group formally established and published its Responsible AI Policy, marking a systematic step forward in the Group's AI governance. The policy is built on core principles of fairness and non‑discrimination, transparency and explainability, security and controllability, privacy protection, and accountability and traceability. It explicitly prohibits algorithmic bias, data leakage, and misuse of AI technologies, and mandates that all AI applications strictly comply with the ISO 42001 standard and the Group's compliance requirements. On the organisational front, the Group has set up an independent AI Safety and Ethics department, reporting directly to the Group CEO, to coordinate AI compliance, risk assessment, and standards implementation. The policy covers the Group and all its subsidiaries, and extends across the entire business lifecycle – from design and development, procurement, production, and sales, to upstream and downstream supply chain partners – demonstrating Huali Group's strong and enduring commitment to responsible AI as it drives forward its intelligent transformation.




More