Annual Report 2020

070 Corporate Governance Report Annual Report 2020 Miramar Hotel and Investment Company, Limited Risk Categories Key Risks Key Measures in Risk Mitigations Risk Level (Risk Velocity) Risk Momentum Information Technology (“IT”) Business operations may be adversely affected and sensitive information may be leaked out under Cyberattack by internal/external hackers or security breach due to information technology infrastructure/system failure – Enforce security measures such as periodic change of password, updating antivirus and firewall protection – Establish information technology security policy on use of information technology equipment and installation of application software – Business continuity plan and disaster recovery plan on major information technology systems have been formulated and can be quickly applied to ensure business continuity – Recovery drills are conducted periodically to ensure its effectiveness Low (Rapid to Very Rapid)  The Group IT team stays alert with IT security issues and the risk level remains at a low level Brand and Reputation The Group’s brand and reputation may be affected by negative public attention which could result in significant decline in our tenant and customer base, and subsequent financial loss – Guidelines on handling media enquiries to all level of staff have been established – Continuous monitoring of media coverages, with actions taken where necessary – Crisis management mechanism is in place with the formation of Crisis Management Committee – Spokesperson hierarchy and principles of corporate communications are in place Low to Medium (Very Rapid)  Marketing team closely monitors various media channels, social platforms and incidents, and when necessary escalates to the Crisis Management Committee promptly. The risk level broadly remains unchanged

RkJQdWJsaXNoZXIy NTk2Nzg=