Information Security and Cybersecurity

Basic Approach

At the Nikon Group, we believe that our information assets are the foundation of our corporate activities, and we treat information assets in accordance with the Nikon Group Information Security Policy. We have established several internal rules based on this policy and pursue information management that complies with the laws and regulations of each country and region. These rules and regulations are always available to employees via the corporate intranet portal. We continue to improve the level of operation through periodic education and compliance status checks.

Related Policies

Strategy

The Nikon Group engages in systematic information security measures and information asset management to ensure business continuity and to enhance the trust of society. In the short-to-medium term, we intend to improve governance and cyber resilience incorporating zero-trust thinking, in addition to enhancing risk response and global security structure in connection with the use of AI. Over the long term, we will pursue preemptive risk management and the establishment of a security culture throughout the company. In this way, we aim to establish a company-wide risk management system that supports sustainable improvements in enterprise value.

Main Initiatives

Response to Information Security Incidents

The Nikon Group clearly defines information security incidents under the Nikon Group Information Management Rules. These regulations require the reporting of incidents from the department impacted to the Information Security Department. The Information Security Department works with relevant divisions to unify procedures from initial response to containment, impact assessment, and recovery, striving to minimize damage and impact, while resuming business operations promptly. Serious cases are promptly escalated to the responsible officer (CISO) for systematic decision-making and response.
In fiscal year 2025, we conducted an incident response drill with relevant divisions to confirm the effectiveness of our response procedures and communication system.
We have noted no serious information security incidents involving fines or compensation payments over the past three years.

Personal Information Protection

The Nikon Group has established the Nikon Group Privacy Protection Statement based on our respect for privacy and acknowledgment that processing personal data in a lawful and proper manner is an important social responsibility.
Additionally, under this statement, we established the Nikon Group Personal Data Processing Rules as a common set of rules covering the entire Group. We are now working to make these rules known within the Group and ensure that personal data is handled in accordance with these rules under the information management system. We conduct a questionnaire-based survey on the status of compliance with the Nikon Group Personal Data Processing Rules roughly once a year.

In addition, the Compliance Department oversees matters related to personal information and manages risk related to privacy and personal information for the entire Nikon Group.

Our specific initiatives include posting privacy notices on the website of each Nikon Group company in accordance with relevant laws and regulations, and notifying customers of contact information for support regarding privacy and individual rights. This includes the purpose of use of personal information and how to delete their personal information.

In addition, we request that procurement partners follow the Nikon CSR Procurement Standards in order to maintain information security, including privacy protection.

Featured

Information Security Education

The Nikon Group conducts information security e-learning education programs as part of new employee training, etc., in order to raise employee awareness of information security and improve skills related to information security management. Beyond information management policies and rules, educational programs are designed to teach risk recognition and response methods based on actual case studies.

In addition, the Nikon Group Information Security Handbook, an educational document that provides easy-to-understand explanations of internal rules and the latest policies, is published on the portal site for all employees to refer to at any time. In this way, we make sure that every employee understands the importance of information asset management and complies with the rules based on a high level of awareness.

In fiscal year 2025, we started to roll out the information security education platform introduced to the Nikon Group in Japan in fiscal year 2024 to Group companies outside Japan, and began regular global e-learning education.

Sustainability Report 2026

See the Information Security and Cybersecurity section of our Sustainability Report for more information.

Sustainability Report 2026 Data Index

View data related to our governance initiatives.