Thorough Information Security

Basic Concept

The Nisshinbo Group regards information security as one of the most important risks, and in April 2023, the Group revised the "Guidelines for Information Security" to be achieved by the Group and deployed them to group companies to improve information security and establish an information security operation system. These guidelines consist of human and organizational management, physical management, and technical management, and the following three points were particularly emphasized in the revision.

  • ① When outsourcing operations, the responsibilities of the outsourcer regarding information security and the measures to be implemented should be clarified.
  • ② In preparation for the event of an information security incident, an emergency response system and recovery procedures should be established.
  • ③ For backups of important information, backups should be stored in a secure environment and restoration procedures should be established.

In addition, The Group recognizes that one of its key corporate responsibilities is to ensure that all important information related to stakeholders is protected and managed appropriately. In order to fulfill this responsibility, the Group handles personal information in accordance with its "Privacy Policy."

Promotion System

Nisshinbo Holdings Inc. reorganized its organizational structure in April 2025 with the aim of building and overseeing a structure that would lead to urgent change. The Company has appointed an executive officer to take responsibility for each area and strengthened its functional organizations.

About Information Security

In order to ensure the continuation of safe and stable business activities of Nisshinbo Group companies, under a system in which the Executive Officer in charge of Information Systems of Nisshinbo Holdings, Inc. is the supreme authority, the Nisshinbo Group has established a meeting of information system managers, which is overseen by the Information System Group of the Risk Management Department, to confirm the status of information system update plans and management of security measures.

Personal Information Protection

Nisshinbo Holdings, Inc. has established a personal information protection secretariat and is working on personal information protection activities under a system in which its managing officer is the chief privacy officer and personal information protection officers are appointed for each department unit. The Group has also established a personal information consultation service to handle consultations and inquiries regarding personal information from outside the group that is received by telephone, fax, or inquiry form.

The officer responsible of the Company reports on its Group's information security and personal information protection initiatives and status at the Board of Directors or the annual Board of Management* and supervises the targets and progress. The president of the Nisshinbo Group, who is the chief executive officer of the Group, conducts management reviews and issues instructions on the matters necessary for management. Special items are reported to the Board of Directors as appropriate.

* The Board of Management: The committee is composed of Managing Director and Managing Officer. Outside Director and Audit & Supervisory Board Member also participate as observers.

For an overview of our organizational structure for promoting sustainability, please see "Promotion System for Sustainability Activity".

Specific Initiatives of The Nisshinbo Group

6th Sustainability Promotion Plan (to be achieved by FY2027)

Strengthen protection against external threats and continuously training employees on information security

In the 6th Sustainability Promotion Plan, which targets FY2027, the Nisshinbo Group focuses on strengthen information security measures as a priority activity and sets the above goal to achieve defending against external threats.

In FY2025, each core company conducted information security audits of its subsidiaries and vulnerability assessments of servers, network equipment, and other systems.

Nisshinbo also conducted information security training for employees at the group companies that focused primarily on phishing email simulations and e-learning.

Please refer to "Sustainability Promotion Plan and KPIs" for details regarding of the "Sustainability Promotion Plan."

Strengthening Responses to External Threats

Along with subsidiary inspections covering the entire Nisshinbo Group, vulnerabilities in servers and network equipment are checked and systematic vulnerability countermeasures are implemented. In FY2025, the Nisshinbo Group conducted subsidiary audits and vulnerability assessments for 50 companies, including subsidiaries overseas. Going forward, the Group will promote comprehensive countermeasures that take into account early detection, response, and recovery, assuming that it is difficult to completely defend against attacks.

Cyber Security Framework

Cyber Security Framework

Initiatives to Ensure Information Security

The Nisshinbo Group has established the "Guidelines for Information Security" to set forth rules to be followed by all group companies in Japan and overseas. To prevent the leakage of confidential information, including customers' personal information, the Group is continuously promoting education and other measures to enhance information security based on these guidelines.

Initiatives to Ensure Information Security

Compliance with Rules / Implementation of Information Security Education and IT Internal Audits

The Group has compiled rules to be kept by information system users into educational materials and is working to raise awareness of information security measures among all Group users through a Learning Management System that includes periodic education and comprehension tests. At the same time, group training is provided for new employees and those dispatched overseas.

In addition, IT internal audits are regularly conducted on Japan and overseas subsidiaries to confirm compliance with the information security guidelines and to ensure continuous improvement.

Prevention of Internal Fraud

The Group uses an information security management system to monitor access to important data and restrict network access to unauthorized information devices.

Prevention of External Attacks

To counter cyber-attacks, the Group monitors e-mails through its e-mail security system, installs antivirus software on information equipment, and applies security correction programs thoroughly.

Targeted e-mail drills are conducted once a year for employees of domestic and overseas Group companies with the aim of raising cyber security awareness and cultivating response capabilities. For the FY2025 training program, the Nisshinbo Group prepared and sent simulated phishing emails in both Japanese and English to 13,209 employees across 36 group companies, including overseas subsidiaries. The Group shared the open rates with each company and will use this as an opportunity to identify areas for improvement with the aim of enhancing security education and continuing to conduct phishing training exercises.

In addition, for FY2025, the Group provided information security training to 10,376 employees via e-learning tools. For core companies that do not use e-learning tools, Nisshinbo distributed training materials translated into Japanese, English, and Chinese.

The Nisshinbo Group did not experience any major information security incidents in FY2025.

Countermeasures in the Event of a Large-Scale Disaster

From the standpoint of business continuity in the event of a large-scale disaster, the Group promotes the use of external data centers and cloud systems.

Support for New Normal Lifestyles

To enhance security during telework, the Group eliminated traditional VPN connections and switched to using a cloud-based firewall system. The group is moving from a traditional perimeter security model that keeps the company secure internally to a zero trust security model that monitors the overall status with the same security from outside the group.

Initiatives to Protect Personal Information

To ensure every one of its employees maintains awareness of personal information protection, the Nisshinbo Group conducts training when employees join the company and when they are promoted as well as training at each of its business sites based on its annual plan. The Group also conducts regular internal audits to check the management status of listed personal information (registration, deletion, storage methods, training status, etc.), and is committed to thorough and continuous improvement in preventing external leakage.

Initiatives Related to Generative AI

Generative AI services available to the public are useful for improving operational efficiency and generating new ideas, but concerns about authenticity and copyrights, as well as the risk of leaking confidential information, have also been raised. Therefore, guidelines for the use of generated AI were established in July 2023, and deployed to Group companies. Each company will tune and customize the guidelines to optimize them for their own needs and prohibitions and to ensure appropriate use and management.

Specific Activities of the Group Companies

Preparing for Information Security Incidents

Japan Radio Co., Ltd., actively participates in activities organized by the Nippon CSIRT Association (NCA) to stay abreast of the latest trends in cyberattack countermeasures and to exchange information. In November 2025, a workshop was held in the Hokushinetsu region that was attended by a total of 30 participants, including member organizations and observers.

Under the theme "Educational Design That Bridges the Gap Between Those Who Understand and Those Who Don’t: Overcoming Variations in Internal Literacy," a wide range of practical insights were shared with participants. These insights included approaches to embedding security as an organizational culture rather than a mere mandatory task, case studies on the use of SIM3*1 in university CSIRTs*2 , and strategies for improving awareness.

*1 SIM3: An abbreviation for the Security Incident Management Maturity Model, an international model used to assess and improve the maturity of CSIRTs.

*2 CSIRT: An abbreviation for Computer Security Incident Response Team, referring to a team that addresses computer security issues.

Workshop participants
Workshop participants

Development of Security Policies and Internal Audits

JRC Engineering Co., Ltd., established an information security policy and objectives, conducted risk assessments, and operated in accordance with its organization-wide ISMS*1 Rulebook.

As part of its information security training program for employees, the company provides an orientation session during initial training and regular training to ensure that employees understand the importance of information security and the relevant rules. Furthermore, JRC Engineering verifies the effectiveness of these training programs through post-training surveys and internal audits covering all departments, thereby confirming that employees understand information security and are carrying out their duties accordingly.

JRC Engineering believes that by conducting management reviews to assess new threats arising from the changes in ICT*2, shifts in stakeholder dynamics, and complaints and requests, and by continuously improving its policies, it can prevent serious incidents.

*1 ISMS: Abbreviation for Information Security Management System

*2 ICT: Abbreviation for Information and Communication Technology

Information Security Initiatives in Collaboration with Customers

In response to security check requests from customers, GOYO ELECTRONICS CO., LTD., uses security checklists provided by the customers to verify and evaluate its information security measures and operational status in close collaboration with those customers. Through this initiative, the company mutually confirms information security requirements and strives to reduce risks while maintaining and strengthening its relationship of trust.

In FY2025, GOYO ELECTRONICS conducted security audits with two client companies in May and September, respectively, to mutually verify compliance with the clients’ requirements.

Going forward, GOYO ELECTRONICS will continue to use these initiatives to ensure reliable compliance with client requirements and improve transparency, while also working to maintain and enhance its security standards.

Maintaining and Improving Information Security

Two years ago, Nisshinbo Brake Inc. obtained TISAX® certification, and its information security initiatives are now firmly established.

Since its launch in January 2024, the onboarding training program for all new employees (including interns) of Nisshinbo Brake totaled over 100 participants to date, and the company has maintained a 100% participation rate for its annual training sessions. Through these training initiatives, Nisshinbo Brake deepened the understanding of TISAX® across all locations and job roles to ensure that appropriate judgment and conduct are embedded in its daily operations.

Through internal audits and risk assessments conducted by external organizations last year, Nisshinbo Brake is working to continuously monitor its operational status, address revised requirements, and enhance its training programs.

Through these company-wide initiatives, Nisshinbo Brake has worked to maintain and enhance information security in both the policy and operational aspects, thereby earning the trust of customers and suppliers. Furthermore, the company has established an operational framework that meets TISAX® requirements, which enable it to respond flexibly and swiftly to evolving threats. Nisshinbo Brake views information security as one of its key corporate social responsibilities, contributing to the development of a sustainable business foundation.

TISAX training for new employees
TISAX® training for new employees

Strengthening Sustainable Information Security and Trade Secret Protection

Saeron Automotive Corporation of South Korea operates an effective security training program and a confidentiality agreement system to protect its core technologies and trade secrets.

The company regularly provides information security training for all employees. During the training held from November to December 2025, 105 managers participated and completed training on practical information security procedures, including how to respond to cyberattacks and the procedures for cloud and email security. In addition, new employees are required to complete security training and solution training as part of the on-the-job training (OJT) program. In April 2025, Saeron Automotive conducted on-the-job training for new employees to impart knowledge on preventing security incidents. Additionally, it strengthened human security by having new hires sign a confidentiality agreement upon joining the company. Through this combination of training and the signing process, the company implemented real-time monitoring of internal policy violations with advance notification, thereby fostering a culture of security awareness among employees.

Saeron Automotive will continue to ensure the reliability of its security measures and strive to establish a sustainable security culture through company-wide information security training held at least once a year.

Personal Information Protection Training Session

In May 2025, PT. Standard Indonesia Industry conducted a training program for its 287 employees to raise awareness of personal data protection.

The training not only covered the company’s data protection policies but also emphasized employees’ responsibility to properly manage their own personal information, such as ID numbers, contact details, and financial information, and to avoid carelessly sharing the information. The training also served as an opportunity for employees to reaffirm the risks that seemingly innocuous actions, such as sharing documents via unsecure channels or responding to suspicious requests, can pose in terms of data breaches.

The company clarified its responsibility to comply with laws and regulations and to handle personal information collected through human resources and general affairs operations in a secure and ethical manner. Following the implementation of an educational program, PT. Standard Indonesia Industry obtained formal consent by explaining to employees how their information would be collected and used before requesting their signatures, thereby strengthening transparency and trust.

In addition, the training covered such practical methods as precautions for sharing information and understanding access permissions, thereby enhancing the transparency of the company’s internal management system. Overall, this initiative heightened the sense of responsibility among both employees and the company and contributed to the establishment of a foundation for honest and transparent personal information management.

Workshop on the Indonesia's Personal Data Protection Law
Workshop on the Indonesia's Personal Data Protection Law

Information Sharing and Exchange of Views on Preventing Information Leaks with Asahi Police Station (Chiba Prefectural Police)

Twice a year (in January and September of FY2025), officers from the Asahi Police Station visit the Asahi Plant of Nisshinbo Chemical Inc. to provide guidance on preventing information leaks and updates on the latest trends, as well as to exchange views with its staff.

The plant regularly invites officials from the Chiba Prefectural Police to attend these sessions where they discuss past incidents in Chiba Prefecture and other areas, as well as recent trends. Specifically, the police share insights on such risks as the unauthorized removal of information by former employees, as well as cases where individuals attempt to extract information by establishing trust through casual interactions in daily life. These sessions serve as an opportunity to reaffirm key precautions for preventing information leaks.

In addition, when visitors come to the company’s offices, Nisshinbo Chemical invites IT staff from the Asahi Plant and the Nisshinbo Brake Inc. Asahi Office to participate. By directly exchanging views on concerns and questions they encounter in their daily work, Nisshinbo Chemical aims to alleviate anxiety and raise awareness. The information gathered during these meetings is shared with department heads and others within the plant and is used to support ongoing efforts to prevent data leaks.

Implementation of Information Security Training

To enhance its ability to respond to cyberattacks, such as phishing emails and unauthorized access, which are becoming increasingly sophisticated each year, Nisshinbo Do Brasil Industria Textil LTDA. in Brazil provided information security training for all 39 computer users in October 2025.

Threats targeting information assets are ever-present and can suddenly infiltrate daily operations without warning. Many security incidents are caused by system issues as well as by human error and a lack of awareness. A single lapse in attention can lead to problems across the entire organization and, in some cases, may even extend to business partners. By providing training to ensure that every employee acquires the proper knowledge and follows the appropriate response protocols, the company can prevent incidents and raise security awareness throughout the organization.

Employees who participated in the training expressed surprise upon learning, through real-world examples and the scale of potential damage, that even the slightest lapse in attention could lead to a major incident. The company maintains a high level of security by conducting regular training sessions.

Management Message
Sustainability Management
Contribution to the Environment and Energy Sector
Creating a Safe and Secure Society
Global Compliance
Sustainability Data