▶ Information Security Policy | https://www.sumitomocorp.com/en/jp/security ▶ Privacy Policy | https://www.sumitomocorp.com/en/jp/privacy ▶ Annual Financial Report| https://www.sumitomocorp.com/-/media/Files/hq/ir/report/yuho/2025/202603yuho.pdf?sc_lang=en
To respond appropriately to risks related to information security, we have built a management structure centered on the IT Strategy Committee, which is chaired by Chief Information Officer (CIO). The IT Strategy Committee considers the development and revision of the Information Security Policy and other internal rules and systems related to information security as well as individual information security measures. With respect to personal information, we have established the Privacy Policy and have put in place related rules and an organizational structure to ensure appropriate protection.
Important matters considered by this committee are submitted to the Management Council for decision-making and supervision. The implementation status of information security measures and the status of information security incidents are reported annually by the IT Strategy Committee to the Management Council and the Board of Directors.
In addition, as information security measures at major subsidiaries, we are continuously working on improvement and monitoring through the Groupʼs internal control framework with respect to such matters as the development of rules on information assets, the provision of education and training for officers and employees, and the establishment of a structure for crisis management response and recovery planning.
As cyberattacks become increasingly sophisticated and advanced, information leakage or business suspensions could have a seriously adverse impact on the Companyʼs business activities and business performance. We also recognize that strengthening information security measures contributes not only to reducing risks related to cyberattacks but also to enhancing trust from customers and business partners, ensuring business continuity, and maintaining and enhancing competitiveness. In our IT services business, we are creating new opportunities and driving growth by capturing demand for security products and services while expanding solutions that leverage leading-edge technologies. For more information on our strategy and risk management related to information security risks and opportunities, please refer to our Annual Financial Report.