- Home
- Sustainability
- Governance
- Information Security/DX
Information Security/DX
Information Security Policy
In order to ensure the confidentiality, integrity and availability of its information, information assets and information systems, the Sumitomo Forestry Group is raising its information security level through the enhancement of both the operational rules and technology aspects of information security. Recognizing that the protection of customer information is of particular and utmost importance, the Group continues to conduct employee training to raise their awareness of the rules and check their level of awareness. Furthermore, we are continuously making improvements on our information security measures to maintain a system to respond to the latest threats at all times.
Development of a System for Security Operations
Concerning operational rules, we have compiled the guidelines and checklists covering Group companies in Japan. The person in charge at the information system department of each Group company in Japan checks their information security level every year. Moreover, we developed similar guidelines for overseas Group companies.
Increasing Employees’ Information Security Awareness
All employees of Group companies in Japan, including temporary employees and part-time workers, are required to receive training on information security every year through the intranet and pass a test to complete the training. We also established a contact point for employees to consult with any information security issues by phone or by email. Moreover, we have attached the adhesive labels on which the telephone number of the contact point is indicated to all our PCs. We are thereby raising employees’ awareness of the reporting flow for security issues and encouraging them to escalate any security issues enabling us to take appropriate initial response. Furthermore, in fiscal 2025, we conducted internal information security audits in collaboration with the Internal Audit Department in order to ensure on-site compliance with the guidelines and strengthen on-site security measures. Specifically, we audited 32 branch departments of Sumitomo Forestry and 16 Group companies in Japan.
Strengthening Information Security Measures
For the technical aspects of information security, the Group has introduced encrypted computer start-ups and imposes data export restrictions on computers that are taken outside the company.
Additionally, in fiscal 2023, we developed a support system for overseas Group companies and have been working to help them strengthen their information security measures in line with the guidelines. In fiscal 2025, overseas Group companies continued efforts to raise their information security standards to the level specified by Sumitomo Forestry. For companies that have not yet achieved the predefined target, we will continue helping them reach the standard level by the end of fiscal 2027.
In fiscal 2025, the Sumitomo Forestry Group had some security incidents, including an attack by ransomware on an overseas affiliate and a targeted attack on an affiliate in Japan. However, we were able to prevent the incidents from badly affecting our business by detecting and responding to the incidents in a prompt manner. By making use of the findings from these incidents, we will enhance our information security risk detection and prevention system, review our process to deal with security incidents, and continue providing employees with education on information security.
Protecting the Privacy of Customers (Protection of Personal Information)
Sumitomo Forestry has formulated internal rules to safeguard the personal information of customers, such as the Personal Information Protection Policy and the Personal Information Protection Regulations. In addition, the divisional manager of the Corporate Division, who also serves as the executive officer responsible for general administration, is designated as the chief executive in charge of protection of personal information, and the head of each department is assigned as the supervisor for the protection of personal information. Also, an information security manager is assigned at each department. In these ways, we have established a protection system that covers the head office and all other business sites of the company.
We have also established a help desk within the Customer Service Department to respond to inquiries regarding the handling of personal information. In addition, collective training is provided for the head and general administration representative of each department. E-learning is provided for all other employees, and efforts are made to increase awareness among subcontractors in order to prevent personal information leaks. Employees at Group companies are also required to undergo e-learning training on the treatment of personal information.
- Click here for related information
Information Security Management Systems
Management System Implemented at the Executive Management Level
The head of the IT Solutions Department, under the supervision of the divisional manager of the Corporate Division who also serves as the executive officer in charge of IT solutions and information security, is responsible for promoting information security measures for the Sumitomo Forestry Group, including formulating and managing rules and regulations, proposing and implementing technical measures, educating and training employees, and conducting the investigation of incidents and implementing countermeasures. The IT Strategy Committee is convened by the divisional manager of the Corporate Division and the results are shared with the president and the heads of each division. At the meetings of the committee, regular reports are provided on social trends related to information security and the status of implementation of the Sumitomo Forestry Group’s measures, and instructions are given for further action.
Management System Implemented On-site
The manager serving as the information security supervisor in each department provides guidance and management for the department's operations. Also, an information security facilitator is assigned as a working-level manager for the department's information security.
Furthermore, the Group also holds regular meetings of the Information Security Promotion Personnel Council with the participation of persons responsible for information security at the departments of Sumitomo Forestry as well as the regular meetings of the Affiliates IT Personnel Council, which are attended by information system managers of Group companies in Japan. These councils raise employees’ awareness of the information security guidelines, ensure thorough compliance with the guidelines, and promotes the introduction of information security systems.
The Risk Management Committee regards the risk of confidential information leaks caused by attacks from outside the company and other factors as one of its priority management items. The committee members share information and discuss ways to prevent and reduce the impact of such leaks at the committee meetings held every quarter. In fiscal 2025, we newly added "Strengthening Information Security at Outsourced Partners" (supply chain measures) as a priority item and are actively working on this initiative. These activities are reported to the Board of Directors and a system to reflect this in business execution is put in place. In fiscal 2026, we have newly added the risk of business suspension caused by a ransomware infection to our information security risks in light of the changes made to the external environment, and are working to enhance our security infrastructure to ensure business continuity against cyberattacks.
In addition, the BCM Subcommittee, established under the Risk Management Committee, conducts activities aimed to raise the efficacy of measures to mitigate Group-wide, IT-related business interruption risks.
Dalian Sumirin Information Technology Service Co, Ltd. (ITS) , which provides CAD design, system operation, back-office, and other BPO services for the Sumitomo Forestry Group and other entities, has acquired ISMS*1 (ISO/IEC 27001) certification.
Moreover, we sent IT governance managers from the Head Office to our overseas Group company in the U.S. to improve its IT governance management systems, including the information security system.
In fiscal 2024, the Timber and Building Materials Division obtained ISMS*1 (ISO/IEC 27001) certification in connection with the industry-specific quotation service (JUCORE Estimate) that it launched.
*1An information security management system (ISMS) is a system designed for an organization to manage the security of its information assets.
- Click here for related information
Initiatives to Strengthen Information Security
With threats to information security growing because of the spate of incidents involving leaks of personal information, targeted email attacks and other incidents, the Sumitomo Forestry Group installed EDR*1 (next-generation security software) to the PCs used by Group companies in Japan, including Sumitomo Forestry, for the introduction of EDR to its operational system infrastructure. In this manner, we continue to invest in solutions that will further enhance the information security of the Group. We have been conducting information security diagnostics through simulated attack methods at least once a year on any system infrastructure with Internet access. We have also adopted the ASM service*2 for constant monitoring of information security vulnerabilities and enhance our measures to deal with the vulnerabilities. In addition, a training program on targeted email attacks is implemented for all employees in Japan at least twice a year.
*1Abbreviation for Endpoint Detection and Response. A security solution that detects suspicious behavior on the user's computer or server (endpoint) and facilitates a quick response to it.
*2Attack surface management (AMS) is designed to identify the IT assets that are accessible from outside the organization via the Internet and manage their vulnerabilities and other risks on a continual basis.
Establishment of a CSIRT
Sumitomo Forestry established a CSIRT*1 in October 2022 to conduct monitoring for the prevention of security incidents and to have an organization in place to make an appropriate response in case of an incident. In November 2023, we joined the Nippon CSIRT Association (NCA). In fiscal 2025, we participated in the NCO/NCA joint tabletop exercise *2 provided by the NCA. We will continue to improve our incident response capabilities, mitigate information security risks, and promote information sharing and collaboration in the field.
*1Abbreviation for Computer Security Incident Response Team. A dedicated team that addresses incidents considered to pose security threats
*2The NCA provides its members with the cross-sectoral tabletop exercise provided by the Japanese government’s National Cybersecurity Office (NCO) to companies operating in 15 important infrastructure fields. This exercise, conducted in collaboration with NCO, aims to strengthen cybersecurity measures for critical infrastructure.
Promotion of DX
The Sumitomo Forestry Group focuses on “digital” and “innovation” as keywords in "Striving for transformation and the creation of new value," which is one of the business polices of Mission TREEING 2030, and has positioned the promotion of DX as an important initiative to achieve its long-term vision.
Sumitomo Forestry has launched a dedicated digital transformation (DX) website to share its policies and focus areas related to IT and DX externally. By publishing DX case studies and insights gained on the website, we aim to promote dialogue with stakeholders—including customers and partner companies—and deepen information sharing and mutual understanding concerning DX.
- Click here for related information
Renewal of the Timber and Building Materials Division’s Core System, and Introduction of Infrastructure for Effective Data Utilization
We renewed the core system of the Timber and Building Materials Division from the conventional system customized for our operations to a standard system based on the “Fit to Standard” concept. We have also introduced infrastructure to store and make multifaceted analysis of all data concerning our business activities for more effective data utilization.
Through these measures we will foster data-driven business operation by the management team as well as by on-site staff, thereby increasing our decision-making speed and transparency in business operations.
Development of DX Talent
In fiscal 2025, we started to provide employees with basic DX training to develop “DX talent” according to our own definition, and a total of about 80 employees participated in the training in the fiscal year.
DX Talent
DX Planning and Promotion Talent:Drives the creation of new businesses, transformation of existing businesses, and the advancement and efficiency of operations through the use of digital technologies.
Data Utilization Talent:Translates data utilization strategies into concrete actions and applies expertise in AI and data science to properly analyze and visualize data.
We will continue to provide employees with the basic training on DX in and after fiscal 2026 and also work to provide them with practical and more advanced training to foster DX at the initiative of each business department.
Promotion of Citizen Development
Starting in fiscal 2024, we have been gradually expanding RPA-based*1 citizen development at domestic Group companies, enabling employees engaged in non-IT operations to independently automate and streamline their own tasks.
A total of 263 employees participated in the hands-on training sessions organized by the IT department as of the end of fiscal 2025, which led to the reduction of a total of about 37,000 working hours a year and the steady spread of a culture of employee-driven operational innovation.
From fiscal 2026 onward, we will continue to increase the number of participants in these training sessions to reduce the maximum number of working hours.
*1Abbreviation for Robotic Process Automation. Technology to automate PC operations using software robots
Further Utilization of Generative AI in Operations
In the area of generative AI, we have developed and launched an AI platform available for use by our employees across the Group.
The platform operates in a closed environment, isolated from external systems, allowing the use of internal information that should not be input into public AI services. It supports not only text input but also the analysis of images, Excel files, and other formats, thereby broadening its range of applications.
Moreover, we have added the function to generate answers in reference to the details of the files registered with the AI platform (RAG*1) to further increase our operational efficiency through the effective use of in-house knowledge.
*1Retrieval-Augmented Generation (RAG) is a technology to increase the precision and reliability of answers generated by a large language model (LLM) by making it search for and refer to the latest external information as well as in-house documents.
- Home
- Sustainability
- Governance
- Information Security/DX