PHC Group Cybersecurity Policy
PHC Group has prepared policies and standards for the entire Group based on the framework of the ISO 27001 international information security standard. We operate and manage these standards on a global basis through a unified system and set of rules.
Cybersecurity Committee
PHC Group holds meetings of our Cybersecurity Committee, where members discuss the Group’s cybersecurity policy, key performance indicator (KPI) reviews, incident reports, and remedial measures to address any potential security vulnerabilities. These meetings are attended by all PHC Group Corporate Officers, including the CEO. At the meetings, members discuss any cybersecurity concerns and potential responses related to our business and determine necessary response measures.
Training and Education
As part of cybersecurity training in fiscal year 2025, PHC Group conducted two e-learning training sessions for employees at all Group companies globally: (1) Information security training (general education) and (2) targeted email attack countermeasures training. The completion rate was 100% for both training programs (excluding employees without an email address). In addition, training on data protection is conducted annually for the entire Group. The training participation rate in fiscal year 2025 was 100% (excluding employees who do not have an email address). The attendance rate of training and education related to cybersecurity and data protection has increased due to active engagement by employees. Our cybersecurity efforts are widely disseminated among employees, and we continue to work together to build a secure digital environment.
Information Security Reviews for Vendors
PHC Group is actively working to reduce potential cybersecurity risk by conducting annual information security reviews for high-risk vendors. Specifically, we investigate the status of ISO 27001 and Privacy Mark certifications for outsourced vendors, as applicable. If vendors are not certified, we use a cybersecurity standard checklist and require that vendors have a score of 90 out of 100 or higher, or that they have security standards that are equivalent to or higher than those of PHC Group. If compliance standards are not met, we consult with the outsourced vendors and take measures to avoid and reduce risks.
We implemented these initiatives for 174 companies after identifying high-risk vendors based on three criteria: the level of confidential information they handle, their degree of access to the critical systems and networks involved, and the key business processes involved. We achieved a 100% implementation rate, successfully reducing our cybersecurity risks.