Information Security

Basic Approach

In light of the business impact of cyber attacks, system down, and information leaks, the IDEC Group
recognizes information security risks as risks directly related to management, and has established the
“Information Security Basic Policy” to raise employee awareness and take measures against information security-related risks.
We have also established a management system for information security, and are working to ensure
the effectiveness of information security and protect our information assets by continuously improving our basic policy, the various internal rules and procedures formulated based on it, and information security.

Management System

The Information Security Subcommittee was established within the Risk Management Committee, a specialized committee of the Sustainability Committee, to oversee information security management for the entire IDEC Group. The Information Security Subcommittee identifies the information assets of the entire IDEC Group and conducts risk assessment. Based on the results of these assessments, the subcommittee works with the various information security management organizations of each IDEC Group company and their supervisors on a global basis.
We are also working to raise security awareness through education and enlightenment activities for all
employees, and have established a reporting system to ensure prompt response and damage minimization
in the event of incidents such as cyber attacks and information leaks.

info-sec-structure-2026-en-1

Countermeasures against information security risks

To reduce information security-related risks, the IDEC Group works continuously to assess the internal and external environment in relation to information security, with an emphasis on strengthening countermeasures. We work to prevent information security incidents by ensuring that management and all employees understand the importance of information security, not only through technical measures, but also through organizational measures such as rule development, education, enlightenment, and training, etc.
When an information systems department of any IDEC Group company identifies a security incident, it implements initial response measures and simultaneously reports the incident to the CSIRT (Computer Security Incident Response Team), which is composed of IT leaders from each global region.
Upon receiving the report, the CSIRT collects detailed information and provides instructions on additional countermeasures and measures to prevent recurrence. If, after considering the potential impact on business continuity as well as violations of laws or contractual obligations, the incident is determined to be major incident, it is promptly reported to management. At the same time, an Emergency Response taskforce will be
established, consisting of relevant IDEC department heads and presidents of Group companies.Through this taskforce, response measures will be carried out in coordination with the Risk Management Committee and its subordinate body, the BCP Subcommittee, which serve as the secretariat.
All measures related to security incidents will be determined and implemented with due consideration given not only to the IDEC Group’s internal operations but also to their potential impact on stakeholders, including customers and business partners.

Education and Training

The IDEC Group believes that it is important for every employee to understand the importance of information security, and to practice defensive actions. In addition to regular information security
training (e-Learning), we conduct drills against targeted e-mail attacks to raise employee awareness
of information security.

■ Information security e-Learning results (Japan)
FY2024

Participation Rate

1st training

94.0% (1,259)

2nd training

93.8% (1,286)

3rd training

91.2% (1,238)

4th training

85.4% (1,155)


FY2025

Period

Topic

Participation Rate

May 2024

Malware

100% (1,269/1,269)

July 2024

Physical security

100% (1,254 / 1,254)

September 2024

Multi-factor authentication

100% (1,239 / 1,239)

November 2024

AI

100% (1,222/1,222)


FY2026

Period

Topic

Participation Rate

May–June 2025

Information management regulations

100% (1,076 / 1,076)

July–August 2025

Internal IT equipment usage rules and security measures

100% (1,075 / 1,075)

September–October 2025

Security updates

100% (1,091 / 1,091)

November–December 2025

Software installation and screen lock

100% (1,057 / 1,057)

January–February 2026

Threats from malicious use of AI (Deepfakes)

100% (1,076 / 1,076)

Related Policies