Information Security
Governance
Strategy
Risk Management
Metrics and Targets
Studio Dragon carries out information security initiatives based on the information security governance framework of its parent company, CJ ENM. Since 2022, Studio Dragon has maintained a unified information security management system by designating its Chief Information Security Officer (CISO) to also serve as CJ ENM's Information Security Officer. In 2025, the company further established a dedicated Information Security Team directly under the CEO, which formulates and implements annual information security plans across the entire content value chain.
Studio Dragon Information Security Organization Chart

Studio Dragon recognizes data breaches resulting from hacking, ransomware, and inadequate internal controls as a key risk and continuously manages the resulting impact and response measures. Information security incidents can lead to critical data loss and service disruption, and may result in financial losses including diminished corporate reputation, increased legal costs, and higher incident remediation expenses. Accordingly, Studio Dragon complies with information security regulations and aims to prevent information security risks through technical and administrative security systems. The company also conducts ongoing vulnerability assessments and remediation activities to strengthen its information security posture.
Assessment of Information Security Risks and Opportunities
Category | Risks and Opportunities | Potential Financial Impact | Significance | Expected Timeline |
|---|---|---|---|---|
Operational Risk | Data breach and security incidents resulting from hacking, ransomware, and inadequate internal controls | Erosion of customer and partner trust | High | Short, medium, and long term |
Regulatory Risk | Violation of personal data protection and information security regulations | Fines, penalties, litigation costs, and regulatory sanctions | High | Short, medium, and long term |
Strategic Risk | Security control limitations due to dependence on external systems and partners | Delayed response to security incidents and increased risk management costs | Medium | Short and medium term |
Strategic Opportunity | Strengthening information security management systems and advancing partner management capabilities | Enhanced risk response capabilities and secured long-term business resilience | Medium | Medium to long term |
Studio Dragon applies CJ Group's information security policies and related guidelines to all employees working at CJ regardless of workplace, role, or position, as well as to third parties acting on behalf of CJ or performing work for CJ. Based on CJ Group's information security standards, Studio Dragon is developing its own information security policies to reflect the characteristics of the data it manages and processes, and plans to formally issue and distribute its Information Security Policy document by 2026. Studio Dragon also conducts regular policy reviews and is committed to continuously distributing and updating related guidelines and implementation procedures to strengthen information security.
Studio Dragon establishes, reviews, and refines detailed annual plans for information security operations and publicly discloses staffing levels and investment status through information security disclosures. In 2025, the company is continuing to invest in strengthening information security, including enhancing information security solutions and expanding service security assessments. In particular, to address evolving work environments such as remote work, Studio Dragon has implemented a Zero Trust-based AIP document security system that overcomes the limitations of legacy DRM. This system enables secure document access, prevents data leakage through encryption, and provides monitoring capabilities across borderless work environments, including remote work and cloud settings.
Studio Dragon conducts information security training for employees at least once annually to foster a culture of information security. In 2025, the company delivered a one-hour training session on information security and privacy protection, with 160 employees completing the program.
To raise awareness of information protection among employees, Studio Dragon held various activities aligned with the official commemorative day, ‘Information Protection Day’. These activities included distributing an information protection card newsletter, sharing practical guidelines, and hosting quiz events.
Studio Dragon Information Security Day

Photo Credit: Studio Dragon
Studio Dragon identifies information security risks through advance inspections and simulation drills, and continuously implements improvement activities to prevent incidents. The company operates a 24/7 information security monitoring system and continuously enhances security equipment to respond to emerging security threats. In addition, Studio Dragon partners with specialized cybersecurity firms to conduct regular vulnerability assessments, review incident response procedures, and maintain an emergency contact network. To strengthen internal information security, the company mandates the installation of information security solutions when accessing internal networks and conducts disaster recovery simulation drills at least once annually to ensure information security risks are minimized even in emergency situations.
Studio Dragon's Information Security Team conducts technical vulnerability assessments and on-site inspections at least once annually to identify security gaps and implements corrective measures for any vulnerabilities discovered. In 2025, the team divided its information security assessment scope to four functional areas and reported the findings to the CEO for ongoing monitoring.
Risk Factors, Improvement Measures and Effectiveness
Risk Factor | Improvement Measures | Implementation Effectiveness |
|---|---|---|
Risk of internal information disclosure due to technical vulnerabilities in IT systems | Enterprise-wide IT system vulnerability assessment and risk-based remediation measures | Achievement of zero residual security vulnerabilities, minimization of external attack surface1) |
Security management gaps at the IT and OT2) boundary | On-site inspection-based security review of IT–OT interfaces and establishment of short-term measures and medium- to long-term improvement roadmap | Identification of unmanaged assets and integration into management framework, proactive prevention of BCP3) disruption factors |
Inadequate security configuration on office endpoint devices | Identification and remediation of vulnerable endpoint devices through an endpoint security assessment solution | Standardization of enterprise-wide endpoint security configuration |
1) Potential pathways and exposure areas through which external attackers may access or penetrate systems
2) OT (Operational Technology): systems that control production, equipment, and on-site operations
3) BCP (Business Continuity Plan): a plan designed to maintain the continuity of critical operations in the event of a disaster or incident
Security Vulnerability Assessment Framework
Assessment Target | Assessment Method | Assessment Frequency |
|---|---|---|
General IT Systems | System vulnerability assessment of IT systems including ERP and website | Once per year |
Content Production IT Systems | On-site vulnerability assessment of content production-specialized systems such as post-production centers | Once per year |
General Endpoint Devices | PC security assessment and on-site inspection of office computers | Once per year |
Content Production Endpoint Devices | On-site vulnerability assessment of editing and VFX endpoint devices | Once per year |
Studio Dragon implements information security risk management activities throughout the content production pipeline, with controls tailored to the characteristics of each production phase.
Information Security Risk Management in the Content Production Pipeline
Stage | Risk Management Measures |
|---|---|
Pre-Production | Monitoring system for information leakage from related endpoint devices |
Production | NDA1) execution for external collaborations |
Post-Production | Access control measures for post-production facilities and content information leakage risk management |
Archiving | Security management of archiving centers to prevent external leakage of completed content |
1) NDA (Non-Disclosure Agreement)
Studio Dragon maintains response procedures and emergency contact systems to ensure that information security incidents are reported, received, and escalated immediately upon occurrence. When an information security incident occurs, a dedicated response team is activated according to a tiered response framework to contain the initial spread, secure evidence, analyze root causes, and implement measures for recovery and recurrence prevention. All processes are documented, and significant findings are reported to the CEO. Additionally, Studio Dragon continuously strengthens its incident prevention and response capabilities by analyzing incident cases, training employees, improving policies, and managing its emergency contact network.
Security Incident Response Procedures

Studio Dragon is advancing information security initiatives to ensure business continuity and strengthen brand value. Beyond strengthening foundational IT system security, the company addresses security risks by also enhancing information security in content production environments, and adopting AI technology. Studio Dragon also systematically manages the number of legal sanctions related to information security.
Category | Unit | 2023 | 2024 | 2025 | |
|---|---|---|---|---|---|
Number of Sanctions for Information Security Law Violations | Case | 0 | 0 | 0 | |
Studio Dragon maintains continuous investment in information security each year to sustain its information security standards, and manages its information security investment amount as a key metric. As its information security framework has become stably established, the company has recently shifted its focus from introducing new systems toward operating, maintaining, and enhancing the functionality of existing systems. As a result, the investment amount has decreased; however, Studio Dragon maintains a stable security framework through continuous operation and improvement activities aimed at sustaining and strengthening its information security standards.
Information Security Investment Amount
Category | Unit | 2023 | 2024 | 2025 |
|---|---|---|---|---|
Information Technology Sector Investment | KRW 100 million | 24.11 | 30.80 | 39.78 |
Information Security Sector Investment | KRW 100 million | 1.97 | 1.31 | 0.80 |
Information Security Investment Ratio to IT1) | % | 8.2 | 4.3 | 2.0 |
1) Information Security Investment Ratio to IT = Information Security Sector Investment ÷ Information Technology Sector Investment × 100