XML 17 R7.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Risk Management and Strategy
We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats as part of our overall enterprise risk management system and processes. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and our enterprise risk professionals consult with company subject matter experts to gather information necessary to identify cybersecurity risks, and evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. Our cybersecurity risk management practices include development, implementation, and improvement of policies and procedures to safeguard information and ensure availability of critical data and systems.
We understand the importance of preserving trust and protecting personal information. To assist us, we have a cybersecurity governance framework in place, which is designed to protect information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction. The program is built upon a foundation of advanced security technology and overseen by an experienced and trained team of experts with substantial knowledge of cybersecurity best practices. Our cybersecurity program consists of controls designed to identify, protect against, detect, respond to and recover from information and cybersecurity incidents. Our framework leverages Trusted Information Security Assessment Exchange (TISAX) standards for general information technology controls. Key components of our cybersecurity risk management processes include the following:
 
 
Asset analysis:
Identify information assets, including information and information systems related to our business, and evaluate their value by considering the impact that loss of confidentiality, integrity and availability of the assets may have on the company.
 
 
 
Threat analysis:
Identify threats to assets and measure the likelihood of occurrence through interviews and due diligence.
 
 
 
Vulnerability analysis:
Analyze the extent to which assets are vulnerable to identified threats through interviews or due diligence.
 
 
 
Risk assessment:
Assess the risk level based on identified assets, threats and vulnerabilities and identify existing protection measures. Evaluate risk by categorizing threats, vulnerabilities and risk levels for each identified asset.
 
 
 
Risk treatment:
Based on the risk assessment results, implement measures to mitigate risks to an acceptable level.
We maintain an
in-house
IT service management system, and we conduct technical security review during the designing stage of our system development. We utilize policies, software, training programs and hardware solutions to protect and monitor our environment, including multifactor authentication on all critical systems, firewalls, intrusion detection and prevention systems, vulnerability and penetration testing and identity management systems. Our platform includes a host of encryption, antivirus, multi-factor authentication, firewall and patch-management technologies designed to protect and maintain the systems and computers across our business.
Our cybersecurity team regularly tests our controls through penetration testing, vulnerability scanning and attack simulation. We conduct risk assessments periodically to identify threats and vulnerabilities, and then determine the likelihood and impact for each risk using a qualitative risk assessment methodology. Risks are identified from various sources, including vulnerability scans,
 
penetration tests, vendors risk assessments, product and services audits, internal compliance assessments and threat-hunting operations. We monitor our infrastructure and applications to identify evolving cyber threats, scan for vulnerabilities and mitigate risks. We also operate an integrated security control room through a third-party company, through which we detect and defend against hacking attacks from outside in real time.
We also maintain a robust cybersecurity incident response plan, which provides a framework for handling cybersecurity incidents based on the severity of the incident and facilitates cross-functional coordination across the company. Our incident response plan coordinates the activities we take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity for, escalate, contain, investigate and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
We value collaboration with external evaluators, consultants, auditors and other third parties to strengthen and continually improve our cybersecurity risk management processes. In connection with our cybersecurity risk management processes, we engage:
 
 
External evaluators and consultants:
We engage external consultants from security companies to assist in the design and implementation of our cybersecurity risk assessment and management processes. In particular, they provide the expertise necessary to (i) identify and analyze new cybersecurity threats, (ii) identify and improve vulnerabilities through mock hacking and (iii) analyze and respond to new threats in real time through integrated security control.
 
 
 
Auditors:
Our program includes review and assessment by external, independent third-parties, who assess and report on our internal incident response preparedness and help identify areas for continued focus and improvement. We engage in regular external audits to maintain our TISAX certification, which are performed by certified auditors.
 
   
Third-party organizations:
We collaborate with the Korea Internet & Security Agency, the National Intelligence Service and the Korea Industrial Technology Security Association, which develop and maintain cybersecurity-related standards in Korea. Guidelines and best practices from such organizations assist us in improving our cybersecurity strategies and processes.
Our cybersecurity risk management processes extend to the oversight and identification of threats associated with our use of third-party service providers. We have a third-party risk management program that assesses risks from service providers.
Our cybersecurity risk management program includes due diligence of service providers’ information security programs. We review our service providers’ cybersecurity practices before we enter into business transactions with them, and we seek to contractually obligate them to operate their environments in accordance with strict cybersecurity standards. We also develop contingency plans for business continuity in case our service providers are subject to a cyberattack that impacts our use of their systems.
Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previous cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks and any future material incidents.
See “Item 3.D. Risk Factors — Significant breaches of information security could lead to legal and financial exposure, damage to our reputation and a loss of confidence by our customers” for more information on risks from cybersecurity threats that are reasonably likely to materially affect our business strategy, results of operations and financial condition.
Governance
Management
The cybersecurity risk management processes described above are managed by the Head of Technology, who is the Chief Technology Officer of the POSCO Group and reports to our Chief 
 
Executive Officer. The Head of Technology works with our Chief Information Security Officer and chairs the Information Security Committee, which discusses the latest trends in cybersecurity, changes in expectations of our stakeholders, risks identified, security measures implemented, and effectiveness of security protocols.
The Information Security Committee annually reviews and approves our cybersecurity risk management processes, including updates to our internal regulations and guidelines. Our Chief Information Security Officer is supported by the company at the highest levels and regularly engages with cross-functional teams, including Communications, Digital Technology, Human Resources and Strategic Technology.
Board of Directors
The role of our board of directors and the ESG Committee is one of oversight, recognizing that management is responsible for the design, implementation and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks. The Head of Technology, as the chair of the Information Security Committee, may provide updates to the ESG Committee on an annual basis and, as necessary, to the board of directors. These updates may include detailed information on our performance preparing for, preventing, detecting, responding to and recovering from cyber incidents. The compliance officer reviews the information security management framework as part of an assessment of the effectiveness of the compliance control standards and reports the resulting findings and plans to the board of directors, as necessary. The Head of Technology may also promptly inform and update the board of directors about any information security incidents that may pose significant risk to the POSCO Group. Members of the board of directors stay apprised of the rapidly evolving cyber threat landscape and provide guidance to management as appropriate in order to address the effectiveness of our overall data privacy and cybersecurity program.
 
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
We maintain a comprehensive process for assessing, identifying and managing material risks from cybersecurity threats as part of our overall enterprise risk management system and processes. Our enterprise risk management program considers cybersecurity risks alongside other company risks, and our enterprise risk professionals consult with company subject matter experts to gather information necessary to identify cybersecurity risks, and evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk. Our cybersecurity risk management practices include development, implementation, and improvement of policies and procedures to safeguard information and ensure availability of critical data and systems.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previous cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks and any future material incidents.
See “Item 3.D. Risk Factors — Significant breaches of information security could lead to legal and financial exposure, damage to our reputation and a loss of confidence by our customers” for more information on risks from cybersecurity threats that are reasonably likely to materially affect our business strategy, results of operations and financial condition.
Cybersecurity Risk Board of Directors Oversight [Text Block]
Governance
Management
The cybersecurity risk management processes described above are managed by the Head of Technology, who is the Chief Technology Officer of the POSCO Group and reports to our Chief 
 
Executive Officer. The Head of Technology works with our Chief Information Security Officer and chairs the Information Security Committee, which discusses the latest trends in cybersecurity, changes in expectations of our stakeholders, risks identified, security measures implemented, and effectiveness of security protocols.
The Information Security Committee annually reviews and approves our cybersecurity risk management processes, including updates to our internal regulations and guidelines. Our Chief Information Security Officer is supported by the company at the highest levels and regularly engages with cross-functional teams, including Communications, Digital Technology, Human Resources and Strategic Technology.
Board of Directors
The role of our board of directors and the ESG Committee is one of oversight, recognizing that management is responsible for the design, implementation and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks. The Head of Technology, as the chair of the Information Security Committee, may provide updates to the ESG Committee on an annual basis and, as necessary, to the board of directors. These updates may include detailed information on our performance preparing for, preventing, detecting, responding to and recovering from cyber incidents. The compliance officer reviews the information security management framework as part of an assessment of the effectiveness of the compliance control standards and reports the resulting findings and plans to the board of directors, as necessary. The Head of Technology may also promptly inform and update the board of directors about any information security incidents that may pose significant risk to the POSCO Group. Members of the board of directors stay apprised of the rapidly evolving cyber threat landscape and provide guidance to management as appropriate in order to address the effectiveness of our overall data privacy and cybersecurity program.
 
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
The role of our board of directors and the ESG Committee is one of oversight, recognizing that management is responsible for the design, implementation and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks. The Head of Technology, as the chair of the Information Security Committee, may provide updates to the ESG Committee on an annual basis and, as necessary, to the board of directors. These updates may include detailed information on our performance preparing for, preventing, detecting, responding to and recovering from cyber incidents. The compliance officer reviews the information security management framework as part of an assessment of the effectiveness of the compliance control standards and reports the resulting findings and plans to the board of directors, as necessary. The Head of Technology may also promptly inform and update the board of directors about any information security incidents that may pose significant risk to the POSCO Group. Members of the board of directors stay apprised of the rapidly evolving cyber threat landscape and provide guidance to management as appropriate in order to address the effectiveness of our overall data privacy and cybersecurity program.
 
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The Head of Technology, as the chair of the Information Security Committee, may provide updates to the ESG Committee on an annual basis and, as necessary, to the board of directors. These updates may include detailed information on our performance preparing for, preventing, detecting, responding to and recovering from cyber incidents. The compliance officer reviews the information security management framework as part of an assessment of the effectiveness of the compliance control standards and reports the resulting findings and plans to the board of directors, as necessary. The Head of Technology may also promptly inform and update the board of directors about any information security incidents that may pose significant risk to the POSCO Group. Members of the board of directors stay apprised of the rapidly evolving cyber threat landscape and provide guidance to management as appropriate in order to address the effectiveness of our overall data privacy and cybersecurity program.
Cybersecurity Risk Role of Management [Text Block]
Management
The cybersecurity risk management processes described above are managed by the Head of Technology, who is the Chief Technology Officer of the POSCO Group and reports to our Chief 
 
Executive Officer. The Head of Technology works with our Chief Information Security Officer and chairs the Information Security Committee, which discusses the latest trends in cybersecurity, changes in expectations of our stakeholders, risks identified, security measures implemented, and effectiveness of security protocols.
The Information Security Committee annually reviews and approves our cybersecurity risk management processes, including updates to our internal regulations and guidelines. Our Chief Information Security Officer is supported by the company at the highest levels and regularly engages with cross-functional teams, including Communications, Digital Technology, Human Resources and Strategic Technology.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Head of Technology, as the chair of the Information Security Committee, may provide updates to the ESG Committee on an annual basis and, as necessary, to the board of directors. These updates may include detailed information on our performance preparing for, preventing, detecting, responding to and recovering from cyber incidents.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
We understand the importance of preserving trust and protecting personal information. To assist us, we have a cybersecurity governance framework in place, which is designed to protect information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction. The program is built upon a foundation of advanced security technology and overseen by an experienced and trained team of experts with substantial knowledge of cybersecurity best practices. Our cybersecurity program consists of controls designed to identify, protect against, detect, respond to and recover from information and cybersecurity incidents. Our framework leverages Trusted Information Security Assessment Exchange (TISAX) standards for general information technology controls. Key components of our cybersecurity risk management processes include the following:
 
 
Asset analysis:
Identify information assets, including information and information systems related to our business, and evaluate their value by considering the impact that loss of confidentiality, integrity and availability of the assets may have on the company.
 
 
 
Threat analysis:
Identify threats to assets and measure the likelihood of occurrence through interviews and due diligence.
 
 
 
Vulnerability analysis:
Analyze the extent to which assets are vulnerable to identified threats through interviews or due diligence.
 
 
 
Risk assessment:
Assess the risk level based on identified assets, threats and vulnerabilities and identify existing protection measures. Evaluate risk by categorizing threats, vulnerabilities and risk levels for each identified asset.
 
 
 
Risk treatment:
Based on the risk assessment results, implement measures to mitigate risks to an acceptable level.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Head of Technology may also promptly inform and update the board of directors about any information security incidents that may pose significant risk to the POSCO Group. Members of the board of directors stay apprised of the rapidly evolving cyber threat landscape and provide guidance to management as appropriate in order to address the effectiveness of our overall data privacy and cybersecurity program.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true