In an increasingly digitalised operating environment, cybersecurity and IT resource management have become essential components of corporate resilience.
SAMEE Group adopts a structured approach to IT and cybersecurity governance, recognising its critical role in protecting data integrity, ensuring operational continuity, and maintaining stakeholder trust in an increasingly digitised business environment. Our strategy is underpinned by principles of risk minimisation, system availability, user accountability, and compliance with applicable data protection laws across all jurisdictions in which we operate.
Cybersecurity oversight is centralised under our Corporate IT, which is supported by external consultants and periodic compliance reviews. IT infrastructure is designed with redundancy, security, and disaster recovery in mind, while access to mission-critical systems is tightly governed through role-based permissions, user activity monitoring, and escalation protocols.
To protect sensitive and business-critical information, SAMEE Group enforces encryption standards, firewall protection, and cloud-based backups where applicable. All digital systems undergo both internal and external vulnerability assessments to identify and address potential security gaps. Our multi-layered defence approach extends beyond technology to include people and processes, with strong emphasis placed on user education and behavioural risk reduction.
Our cybersecurity and IT governance strategy is structured around five core focus areas:
• Infrastructure Security and Uptime – We ensure robust protection of enterprise systems, servers, and automation platforms through access controls, regular security patching, and performance monitoring.
• Data Privacy and Protection – We safeguard employee, customer, and business data through encryption, data retention protocols, and compliance with local and international privacy regulations.
• User Training and Awareness – Cybersecurity briefings, phishing simulations, and IT policy refreshers are conducted regularly to reduce human-related risks and instil responsible digital behaviours.
• Disaster Recovery and Business Continuity – SAMEE Group follows the 3-2-1 Backup Rule, maintains offsite backups, and tests system restoration procedures annually to ensure business resilience in the event of a cyberattack or IT failure.
• Policy Enforcement and Audit – Our cybersecurity policies are formalised and enforced through regular internal audits, with a structured approach to reporting, remediation, and compliance tracking.
In FY2025, SAMEE Group implemented several initiatives to strengthen our cybersecurity posture. Multi-Factor Authentication (“MFA”) was enforced for all administrator access, particularly to safeguard remote and hybrid work environments. Email security was significantly enhanced through the deployment of an enterpriseclass email gateway solution and the implementation of Domain-based Message Authentication, Reporting and Conformance (“DMARC”) protocols to prevent domain spoofing and reduce phishing threats. All new hires underwent Cybersecurity Awareness Training and were briefed on IT Acceptable Use Guidelines during onboarding. In addition, all employees completed annual compliance modules through SAMEE Group’s internal platform, reinforcing knowledge of evolving threats and personal responsibilities.
To test and improve our defences, we conducted vulnerability assessments, social engineering simulations, and cybersecurity gap analyses across our internal systems and third-party interfaces. These exercises identified improvement areas that were promptly addressed, including closing legacy system exposures, enhancing endpoint security controls, and hardening system configurations across operating units.
SAMEE Group also enhanced backup resilience by extending data retention periods and implementing robust restoration validation processes. Backup and disaster recovery protocols were tested to ensure rapid response readiness, particularly in the context of rising ransomware and data breach risks. Real-time security bulletins, system tips, and threat alerts were also disseminated via our internal mobile platform, SAM eHub, to maintain awareness and engagement across the workforce.
Through these integrated and proactive measures, SAMEE Group continues to elevate its cybersecurity maturity, protect stakeholder interests, and ensure that our digital ecosystem remains secure, resilient, and fit for the future.
In FY2025, we upheld our commitment to customer privacy and data security, ensuring strict compliance with data protection regulations and internal governance frameworks. A key milestone was the successful achievement of ISO/IEC 27001 certification for our Singapore sites, demonstrating our adherence to internationally recognised standards for information security management. To ensure comprehensive coverage across all operations, the Group has achieved ISO/IEC 27001 certification for its Malaysia and Thailand sites.
As a testament to our robust data protection measures, no substantiated complaint from external parties, regulatory bodies, or internal investigations concerning breaches of customer privacy or losses of customer data was received. By maintaining zero incidents in FY2025, SAMEE Group reaffirmed its commitment to safeguarding customer trust, strengthening regulatory compliance, and upholding the highest standards of data privacy. This outcome reflects the successful achievement of our internal target of zero data breaches.