Information Security

Policy and Basic Approach

The Nippon Kayaku Group is promoting Digital Transformation (DX) to improve operational efficiency and productivity and to support diverse working styles. However, cyberattacks and unauthorized access are becoming increasingly frequent, sophisticated, and advanced, resulting in growing cyber risks. We regard the risks to business continuity arising from information leakage and computer system disruptions as key management challenges. To earn and maintain the trust of society as a whole, including our customers, business partners, investors, employees, and other stakeholders, we have established the Nippon Kayaku Group Information Security Policy and The Information Security Responsibilities We Bear*, based on the Nippon Kayaku Group Charter of Conduct and Code of Conduct. We continuously incorporate information security into our day-to-day operations to protect corporate information and improve information security awareness and literacy.

Nippon Kayaku Group Information Security Policy

The Nippon Kayaku Group recognizes the information it possesses in the conduct of corporate activities as a key management resource, views information security initiatives as a key management issue, and has determined the following policy approach towards maintaining and improving a system capable of safeguarding its information assets appropriately, continually and across the organization.

Safeguarding our information assets

The Nippon Kayaku Group shall appropriately protect its information assets from threats to their value (in terms of confidentiality, integrity and availability).

Sharing our information assets

The Nippon Kayaku Group shall observe the laws and policies determined by each country, contractual obligations and other social norms when sharing necessary information in the conduct of business and effectively utilizing such information.

Preparation of regulations

The Nippon Kayaku Group shall, in line with the stipulations of its Charter of Conduct and Code of Conduct, both prepare and uphold regulations and standards concerned with the management of the information assets in its possession.

Constructing our system

The Nippon Kayaku Group shall, in order to protect and appropriately manage all information assets in its possession, formulate a system which bears necessary responsibility for information security, and deploy, to each group company and organization, information security managers and security-specialist personnel with the relevant expertise and technical knowledge.

Securing resources

The Nippon Kayaku Group shall view its policy approach to information security as part of its overall management approach, and ensure the necessary staff and budgets are suitably allocated for technical and physical measures.

Risk assessments

The Nippon Kayaku Group shall visualize and assess the hypothetical risks of information leakage and business suspension due to cyberattacks, and continually implement relevant measures which extend to the supply chain.

Responses to critical incidents

The Nippon Kayaku Group shall, in instances of critical information asset incidents, respond promptly to minimize the damage caused, and, based on root cause analyses, formulate recurrence prevention measures.

Implementation of education and training

The Nippon Kayaku Group shall, with respect to every related party in its employ, promote increased information security literacy by periodically and continuously delivering education and training scenarios based on critical information asset incidents.

Continuous initiatives

The Nippon Kayaku Group shall periodically assess and review this policy as it continually enacts information security initiatives.

Jun 26th 2025
Member of the Board Managing Director
Chair of the Information Risk Management Subcommittee

Shinji Inoue
The Information Security Responsibilities We Bear
*The Information Security Responsibilities We Bear (Published in Japanese, English and Chinese)

System

To minimize information security risks, which are a key element of crisis management, and to maintain an appropriate level of security, continuously review countermeasures in response to changing circumstances, and oversee company-wide implementation and awareness, we have established the Information Risk Management Subcommittee.
This subcommittee meets, in principle, twice a year, and additionally as necessary. It is chaired by the Officer in charge of Information Systems, and comprises representatives of every business unit’s planning department plus representatives from general administrative departments unattached to any particular business unit. It also coordinates with the Corporate Information Officer, Person in-charge of Corporate Information, and System Administrator assigned to each company division and workplace.
Important matters discussed by the Subcommittee are reported to the Sustainable Management Meeting and the Board of Directors, which provide feedback as appropriate.
Furthermore, to deal with security incidents that could cause significant damage to the Company’s management or business operations, materially affect its relationships with affiliated companies, business partners, and other customers, or result in a loss of trust, such as cyberattacks and unauthorized access to confidential information, we activate a Computer Security Incident Response Team (CSIRT) to centrally coordinate the response under the leadership of the Information Risk Management Subcommittee Chair. Depending on the anticipated severity of the impact, the President or the Chair of the Risk Management Committee may serve as the CSIRT Leader. The CSIRT works promptly to limit the spread of damage. Once containment has been completed, it focuses on recovery and measures to prevent recurrence.

System

International Certifications

Targets and Results

Scroll horizontally to view more.

FY2025 Targets FY2025 Results
Develop a BCP manual and conduct a cyberattack response exercise in accordance with the Detailed Rules for the Information Risk Management Regulations. A cybersecurity incident response exercise was conducted in accordance with the Detailed Rules for the Information Risk Management Regulations (CSIRT Manual).
FY2026 Targets
Through further enhancement and expansion of information security policies, rules, and standards, ensure compliance with the requirements of the “Supply Chain Security Assessment System ” laid down by Japan’s Ministry of Economy, Trade and Industry (METI)

Initiatives

Information security measures

Scroll horizontally to view more.

Classification of measures Details
(1) Organizational Measures
  • Maintenance of the information security governance structure
  • Periodic reviews of information security-related internal rules and standards
(2) Human and Legal Measures
  • Information system security and IT literacy education, incident response exercises, and awareness-raising activities
  • Entering into confidentiality agreements with external service providers
  • Ensuring compliance with confidentiality obligations by newly hired and departing employees
(3) Physical Measures
  • Access management for facilities, buildings and areas etc.
  • Management of PCs and external storage devices taken outside of company premises
  • Control of the removal of highly confidential information from Company premises, secure storage under lock and key, and access control
(4) Technical Measures
  • Malware protection for information devices and hard drive encryption
  • Establishment of systems to detect unauthorized access and tampering attempts from external sources

Education and Training

The Nippon Kayaku Group communicates its information security rules to all executives, employees, including contract and part-time employees, and temporary staff, and regularly provides information security training and phishing email response exercises.

Training Program Main Contents Target Audience FY Delivery style Frequency
Executive Cybersecurity Training
  • Cybersecurity as a business management issue
  • Case studies of cyberattack incidents
  • Impact of cyberattacks on our company
  • Executive awareness and responsibilities
Executives 2025 Seminar 1
Information Security Awareness Training
  • Distribution of the comic-style guide "IT and Security: Your First Step"
  • Overview of the "10 Major Information Security Threats 2025"
Executives, employees, and external parties using company IT tools 2025 e-Learning, distribution of materials, group training 1
Phishing Email Awareness Training
  • Characteristics of phishing emails
  • Appropriate response when a phishing email is received
Executives, employees, and external parties using company IT tools 2025 e-Learning 1
Phishing Email Simulation Exercise
  • Conducting phishing email simulation exercises
Executives, employees, and external parties using company IT tools 2025 Exercise 4
Cybersecurity Incident Response Exercise
  • Scenario-based incident response exercise in accordance with the Information Risk Management Regulations (CSIRT Manual)
CSIRT and Information Risk Management Subcommittee members 2025 Exercise 1

Number of Major Information Security Incidents

The number of major information security incidents that occurred within the Nippon Kayaku Group over the past three years is shown below.

Scroll horizontally to view more.

Indicators Scope Unit 2021 2022 2023 2024 2025
Number of Major Information Security Incidents * consolidated cases - - 0 0 0
  • *Levels of security incident criticality are determined by our Information Risk Management Subcommittee.

Protecting Personal Information

The Nippon Kayaku Group recognizes the importance of personal information and complies with the Act on the Protection of Personal Information and other applicable laws and regulations concerning the personal information it handles. We consider the protection of personal information to be a social responsibility and are committed to ensuring its proper management and protection.
We have also established our Personal Information Protection Policy for external stakeholders, with purposes of use, security control measures and contact details for consultations and complaints all published on our website so that the information is readily accessible to the public.

Personal Information Protection Management System

We have established the Personal Information Management Regulations and, under the supervision of the Chief Personal Information Protection Officer, appointed Personal Information Managers in each department. Personal information handled in the workplace is classified according to its level of importance on an ongoing basis and registered in a management database.
We also provide training to all personnel three times a year, conduct an annual inventory of personal information, and perform an annual audit. Through these activities, we raise awareness of personal information protection and enhance the effectiveness of our protection measures.

Personal Information Protection Management System

Education and Training on Protecting Personal Information

Training Program Main Content Target Audience FY Delivery Method Frequency Completion Rate
Legal training
  • Overview of security controls (organizational, human, physical, and technical)
  • Understanding the external environment
  • Q&A on security controls
Executives, employees (including contract and part-time employees), and temporary staff 2025 e-Learning, Group Training 3 Ave: 84.8%

Response to Personal Information Breaches

In the event of a personal information breach, we will respond in accordance with our Information Leakage Incident Response Procedures.

Personal Information Breach Incidents

As of March 31, 2026, no personal information breach incidents had occurred.

PageTop
Our Business
R&D
Corporate Information
Global Network
Investor Relations
Integrated report
Sustainability