Information Security

Based on our "Management Philosophy" and "Basic approach to corporate ethics and compliance," Hamamatsu Photonics Group believes that the safe use of information technology (IT) is essential to promoting management.

Additionally, our group recognizes that protecting information assets from security risks is an important management issue.

From this perspective, in order to implement information security initiatives in a organized and continuous manner, we have formulated a "Hamamatsu Photonics Group Information Security Policy" (hereinafter referred to as this policy), and those who use information technology and information assets within our group, such as our group's executives, employees, and temporary staff (hereinafter referred to as internal users), are required to comply with this policy.

 

Hamamatsu Photonics Group Information Security Policy

1. Implementation of information security measures

In order to prevent incidents related to information technology and information assets (unauthorized access, destruction, leakage, falsification, etc.), our group will continue to implement the necessary organizational, human, physical, and technical measures. Additionally, in the event that an incident occurs, we will promptly recover and resolve the incident and take measures to minimize damage.

2. Legal compliance

We will comply with laws and rules regarding information security.

3. Establishment of internal regulations regarding information security

We will formulate internal regulations (hereinafter referred to as "regulations") regarding information security based on this policy, and will revise them as necessary. We will also disseminate its contents to internal users.

4. Implementation of education on information security

We will provide information security education to internal users to ensure thorough compliance with this policy and regulations and to improve information security literacy.

5. Conducting information security audits

In order to confirm and verify that this policy and laws and regulations are being complied with, we will conduct information security audits of internal users.

6. Implementing continuous improvement

The contents of this policy will be periodically reviewed by external and internal parties to continuously improve information security management within our group.

Established: April 1, 2025

Governace structure

We establish an information security management system, with our Officer in charge of information security.

We have established an Information Network Committee that meets monthly to deliberate on key matters regarding the operation and management of company-wide information systems, prevent security incidents, and ensure a rapid response should an incident occur.

The Officer in charge of information security holds ultimate responsibility for the committee; they submit proposals and reports to the Board of Executive Officers for approval as needed and provide regular updates to the Board of Directors—such as through reports issued by the Sustainability Office—while the Board of Directors supervises activities by providing instructions and guidance as required.

 

Sustainability Promotion structure

【Officer in charge of information security】

Fumio Iwase(Senior Executive Officer, Chief of BPR General Headquarters)

Initiatives

■ Raising awareness of information security

 

To raise information security awareness among our officers and employees, we implement the following measures:

・We conduct information security training as part of new employee training program.

・We conduct information security training once a year for all officers, employees, and dispatched employees.

・We conduct information security training twice a year for security representatives (person in charge of IT)selected from each department.

 

■ Assessing the actual state of information security

 

We are implementing the following measures to assess the actual state of information security within the company.

・We conduct an "information security audit" led by the Internal Audit Department once a year, with the support of the Information Network Committee.

・We include information security audit items in the routine internal audits conducted for each department.