Information Security

Governance

Strategy

Risk Management

Metrics and Targets

Decision-Making and Implementation Framework

Board & Management Level

Studio Dragon carries out information security initiatives based on the information security governance framework of its parent company, CJ ENM. Since 2022, Studio Dragon has maintained a unified information security management system by designating its Chief Information Security Officer (CISO) to also serve as CJ ENM's Information Security Officer. In 2025, the company further established a dedicated Information Security Team directly under the CEO, which formulates and implements annual information security plans across the entire content value chain.


Studio Dragon Information Security Organization Chart

Information Security Risks and Opportunities

Studio Dragon recognizes data breaches resulting from hacking, ransomware, and inadequate internal controls as a key risk and continuously manages the resulting impact and response measures. Information security incidents can lead to critical data loss and service disruption, and may result in financial losses including diminished corporate reputation, increased legal costs, and higher incident remediation expenses. Accordingly, Studio Dragon complies with information security regulations and aims to prevent information security risks through technical and administrative security systems. The company also conducts ongoing vulnerability assessments and remediation activities to strengthen its information security posture.
 

Assessment of Information Security Risks and Opportunities

Category

Risks and Opportunities

Potential Financial Impact

Significance

Expected Timeline

Operational Risk

Data breach and security incidents resulting from hacking, ransomware, and inadequate internal controls

Erosion of customer and partner trust

High

Short, medium, and long term

Regulatory Risk

Violation of personal data protection and information security regulations

Fines, penalties, litigation costs, and regulatory sanctions

High

Short, medium, and long term

Strategic Risk

Security control limitations due to dependence on external systems and partners

Delayed response to security incidents and increased risk management costs

Medium

Short and medium term

Strategic Opportunity

Strengthening information security management systems and advancing partner management capabilities

Enhanced risk response capabilities and secured long-term business resilience

Medium

Medium to long term

Information Security Management System

Information Security Policy

Studio Dragon applies CJ Group's information security policies and related guidelines to all employees working at CJ regardless of workplace, role, or position, as well as to third parties acting on behalf of CJ or performing work for CJ. Based on CJ Group's information security standards, Studio Dragon is developing its own information security policies to reflect the characteristics of the data it manages and processes, and plans to formally issue and distribute its Information Security Policy document by 2026. Studio Dragon also conducts regular policy reviews and is committed to continuously distributing and updating related guidelines and implementation procedures to strengthen information security.

Information Security Investment

Studio Dragon establishes, reviews, and refines detailed annual plans for information security operations and publicly discloses staffing levels and investment status through information security disclosures. In 2025, the company is continuing to invest in strengthening information security, including enhancing information security solutions and expanding service security assessments. In particular, to address evolving work environments such as remote work, Studio Dragon has implemented a Zero Trust-based AIP document security system that overcomes the limitations of legacy DRM. This system enables secure document access, prevents data leakage through encryption, and provides monitoring capabilities across borderless work environments, including remote work and cloud settings.

Fostering an Information Security Culture

Information Security Training

Studio Dragon conducts information security training for employees at least once annually to foster a culture of information security. In 2025, the company delivered a one-hour training session on information security and privacy protection, with 160 employees completing the program.


Information Security Day Campaign

To raise awareness of information protection among employees, Studio Dragon held various activities aligned with the official commemorative day, ‘Information Protection Day’. These activities included distributing an information protection card newsletter, sharing practical guidelines, and hosting quiz events.


Studio Dragon Information Security Day

                                                                                                                                                Photo Credit: Studio Dragon

Information Security Risk Prevention

Studio Dragon identifies information security risks through advance inspections and simulation drills, and continuously implements improvement activities to prevent incidents. The company operates a 24/7 information security monitoring system and continuously enhances security equipment to respond to emerging security threats. In addition, Studio Dragon partners with specialized cybersecurity firms to conduct regular vulnerability assessments, review incident response procedures, and maintain an emergency contact network. To strengthen internal information security, the company mandates the installation of information security solutions when accessing internal networks and conducts disaster recovery simulation drills at least once annually to ensure information security risks are minimized even in emergency situations.


Regular Security Vulnerability Assessments

Studio Dragon's Information Security Team conducts technical vulnerability assessments and on-site inspections at least once annually to identify security gaps and implements corrective measures for any vulnerabilities discovered. In 2025, the team divided its information security assessment scope to four functional areas and reported the findings to the CEO for ongoing monitoring.


Risk Factors, Improvement Measures and Effectiveness

Risk Factor

Improvement Measures

Implementation Effectiveness

Risk of internal information disclosure due to technical vulnerabilities in IT systems

Enterprise-wide IT system vulnerability assessment and risk-based remediation measures

Achievement of zero residual security vulnerabilities, minimization of external attack surface1)

Security management gaps at the IT and OT2) boundary

On-site inspection-based security review of IT–OT interfaces and establishment of short-term measures and medium- to long-term improvement roadmap

Identification of unmanaged assets and integration into management framework, proactive prevention of BCP3) disruption factors

Inadequate security configuration on office endpoint devices

Identification and remediation of vulnerable endpoint devices through an endpoint security assessment solution

Standardization of enterprise-wide endpoint security configuration

1) Potential pathways and exposure areas through which external attackers may access or penetrate systems
2) OT (Operational Technology): systems that control production, equipment, and on-site operations
3) BCP (Business Continuity Plan): a plan designed to maintain the continuity of critical operations in the event of a disaster or incident


Security Vulnerability Assessment Framework

Assessment Target

Assessment Method

Assessment Frequency

General IT Systems

System vulnerability assessment of IT systems including ERP and website

Once per year

Content Production IT Systems

On-site vulnerability assessment of content production-specialized systems such as post-production centers

Once per year

General Endpoint Devices

PC security assessment and on-site inspection of office computers

Once per year

Content Production Endpoint Devices

On-site vulnerability assessment of editing and VFX endpoint devices

Once per year


Information Security Risk Management in the Content Production Pipeline

Studio Dragon implements information security risk management activities throughout the content production pipeline, with controls tailored to the characteristics of each production phase.


Information Security Risk Management in the Content Production Pipeline

Stage

Risk Management Measures

Pre-Production

Monitoring system for information leakage from related endpoint devices

Production

NDA1) execution for external collaborations

Post-Production

Access control measures for post-production facilities and content information leakage risk management

Archiving

Security management of archiving centers to prevent external leakage of completed content

1) NDA (Non-Disclosure Agreement)


Information Security Incident Response Framework

Studio Dragon maintains response procedures and emergency contact systems to ensure that information security incidents are reported, received, and escalated immediately upon occurrence. When an information security incident occurs, a dedicated response team is activated according to a tiered response framework to contain the initial spread, secure evidence, analyze root causes, and implement measures for recovery and recurrence prevention. All processes are documented, and significant findings are reported to the CEO. Additionally, Studio Dragon continuously strengthens its incident prevention and response capabilities by analyzing incident cases, training employees, improving policies, and managing its emergency contact network.


Security Incident Response Procedures

Metrics and Targets

Studio Dragon is advancing information security initiatives to ensure business continuity and strengthen brand value. Beyond strengthening foundational IT system security, the company addresses security risks by also enhancing information security in content production environments, and adopting AI technology. Studio Dragon also systematically manages the number of legal sanctions related to information security.


Category


Unit

2023

2024

2025

Number of Sanctions for Information Security Law Violations

Case

0

0

0


Studio Dragon maintains continuous investment in information security each year to sustain its information security standards, and manages its information security investment amount as a key metric. As its information security framework has become stably established, the company has recently shifted its focus from introducing new systems toward operating, maintaining, and enhancing the functionality of existing systems. As a result, the investment amount has decreased; however, Studio Dragon maintains a stable security framework through continuous operation and improvement activities aimed at sustaining and strengthening its information security standards.


Information Security Investment Amount

Category

Unit

2023

2024

2025

Information Technology Sector Investment

KRW 100 million

24.11

30.80

39.78

Information Security Sector Investment

KRW 100 million

1.97

1.31

0.80

Information Security Investment Ratio to IT1)

%

8.2

4.3

2.0

1) Information Security Investment Ratio to IT = Information Security Sector Investment ÷ Information Technology Sector Investment × 100

logo_img

DREAM WITH DRAGON