Skip to main content

Information Security

Basic Concept

Recognizing the Importance of Information Security

The use of information and IT is essential to corporate activities, and Konica Minolta understands that ensuring information security is of paramount importance in effectively utilizing the various types of information it holds. Konica Minolta believes that managing information appropriately in light of risks such as information loss, leakage, and destruction contributes to business continuity and enhances customer trust, and is therefore committed to continuous improvement in this area.

Konica Minolta Information Security Policy

Guided by our management philosophy of “The Creation of New Value,” we at the Konica Minolta Group are committed to providing products and services that contribute to the development of society.

We are dedicated to maintaining information security (confidentiality, integrity, and availability), which is one of the most important issues related to business activities. Given this commitment, our basic approach to information security is to continuously make improvements by measuring and assessing risks associated with important information assets, and applying effective measures to mitigate those risks.

“Management Based On Facts”

1. Direction of Information Security Initiatives

We will strive to continually provide products and services and develop sound businesses while recognizing our obligation to protect information assets handled in the course of business activities.

2. Compliance with Laws and Other Requirements

We will comply with the legal requirements of Japan and other countries related to information security as well as social norms, internal company standards and contractual security obligations. On this basis we will properly accommodate agreements made by the international community.

3. Establishment of Information Security Management System

We will establish an information security management system in order to appropriately grasp business risks and changes in the risk environment and to establish and maintain response strategies. We will work to maintain, further develop and revise the system by establishing objectives for information security.

4. Risk Response

As a manufacturer we will deal with a broad range of risks related to activities from development and production to sales and service. For risk assessment, we will establish criteria to assess the relative importance of each information asset and stringently manage our assets based on these assessments.

5. Protection from Threats

We will take appropriate measures in order to protect information assets from threats such as accidents, hindrances or improper activity that would prevent the assets from being properly utilized, and in order to prevent information assets from being lost, damaged, altered or divulged.

6. Information Security Education and Training

We will provide the necessary education and training to all employees and will carry out business while recognizing our societal responsibility to use and manage information assets appropriately.

7. Continuous Improvement

We will strive to continuously make improvements by reviewing this information security policy and our management measures on a regular basis, and as necessary, within the framework of our information security management system.

8. Active Disclosure

We will communicate risks to stakeholders and be accountable to them. This policy will be disclosed to all employees and outside parties.

April 1, 2022

Signature of Toshimitsu Taiko

Toshimitsu Taiko

President and CEO

Konica Minolta, Inc.

Structure

Konica Minolta has established the Security Management Board (SMB), comprising the officers in charge of information security, and the Security Management Office (SMO), which serves as the organization responsible for promoting information security initiatives, as part of its Group-wide information security governance structure. Using this framework, Konica Minolta is continuously working to improve information security levels worldwide.

Konica Minolta Group Global Information Security Governance Structure
Organization chart of the Konica Minolta Group's global information security governance structure. At the top is the President and CEO, followed by the Security Management Board, comprising the officers in charge of technology, quality, IT, legal affairs and production, and the Security Management Office as the promoting body. Under the Security Management Office are the risk management areas of information security, product security, data security and factory security, and the global structure places regional Security Management Offices in Japan, China, APAC, the Americas and Europe.

In the Konica Minolta Group in Japan, an information security management system implementation structure has also been established under the leadership of the President and CEO and the officer in charge of the IT planning and management organization, who has been appointed as the person responsible for overall IT security. .

Initiatives

Information Security

In order to ensure the security (confidentiality, integrity, and availability) of information under management, including not only information managed through IT systems but also information in paper-based media and information relating to services and personnel, all Group companies in Japan have continuously maintained ISO/IEC 27001 certification, the international standard for information security management, since 2009. As part of these activities, information security risk assessments are conducted once a year, and risk response plans are formulated and implemented for high-risk items. Meetings of information security promotion managers, attended by representatives of each business, are also held quarterly. At these meetings, activities — primarily the progress of risk response plans and summaries of incidents — are reported to the person responsible for overall information security management, who instructs the needed responses, thereby driving the PDCA cycle.
Furthermore, measures to prevent unauthorized use and information leakage are implemented through the establishment and operation of rules for managing confidential information and systems for restricting and monitoring access to and removal of confidential information. Education on personal information protection and information security is also provided at least once a year to all employees of Group companies in Japan, from officers to non-regular employees.
Outside Japan, Group companies are also encouraged to obtain ISO/IEC 27001 certification. In addition, all Group companies outside Japan are required to provide IT security education to all employees at least once a year.
In response to today’s increasingly serious cyberattacks, Konica Minolta implements global IT security measures based on the Cybersecurity Management Guidelines formulated by Japan's Ministry of Economy, Trade and Industry. With management recognizing the importance of addressing cyber risks, Konica Minolta has established a Group-wide incident response structure (KM-CSIRT*) and reporting and response processes for incident and vulnerability information.
In addition, to ensure the continuity of IT services necessary for business continuity at Konica Minolta, IT Service Continuity Management (IT BCM) has been introduced in each organization. Guidelines for developing IT Service Continuity Plans (IT BCP) have been established, and IT BCP assessments are conducted once a year.
Konica Minolta also promotes IT security controls, which form part of the IT controls required under the Financial Instruments and Exchange Act (J-SOX), while ensuring consistency across the Group.

*KM-CSIRT (Computer Security Incident Response Team): Konica Minolta’s security incident response team.

Number of Information Security Incidents Reported to KM-CSIRT*
FY2023FY2024FY2025
Number of information security incidents759

* The figures represent the number of incidents determined to be reportable to KM-CSIRT based on Group-wide reporting criteria, regardless of whether any actual damage occurred. The number of reported incidents may also vary depending on the extent to which incident detection and reporting processes have been established throughout the Group.

All reported incidents are addressed under the leadership of KM-CSIRT through an established response process, including initial response activities (identifying the scope of impact and containing the incident), investigation of the cause, recovery, and the development and implementation of measures to prevent recurrence. Furthermore, in coordination with relevant internal departments, a framework is in place for notifying customers, business partners, and other related parties and reporting to regulatory authorities in accordance with applicable laws, guidelines, contractual obligations, and other requirements. In the fiscal years shown above, there were no incidents determined under the Group's criteria to have a significant impact on business operations or incidents requiring public disclosure under applicable laws and regulations.

Factory Security

Konica Minolta is working to strengthen factory security across the Group. By taking steps such as establishing guidelines that take into account the specific characteristics of each factory, isolating factory networks from IT networks, and strengthening business continuity planning (BCP), Konica Minolta is working to reduce the risk of production stoppages.

Product Security

Konica Minolta is working to strengthen product security across the Group. For details of these initiatives, please refer to the link below.

Protection of Personal Data

Basic Approach to the Protection of Personal Data

Konica Minolta respects the interests and privacy of individuals and is committed to the appropriate handling and protection of the personal data of customers, business partners, officers, and employees.

Personal Data Protection Structure

Under the leadership of the person responsible for overall personal data protection, who is appointed by the President and CEO, Konica Minolta has established a basic framework within the Group and promotes the protection of personal data to ensure that personal data processed by the Group is managed appropriately and in compliance with applicable laws.

Personal Data Protection Initiatives

Konica Minolta has established the Global Personal Data Protection Policy and Regulation for Protection of the Personal Data of Konica Minolta Group in line with Japan’s Act on the Protection of Personal Information and the EU General Data Protection Regulation (GDPR), among other laws and regulations, and appropriately obtains and manages personal data in accordance with applicable laws and regulations in each region.
Konica Minolta also uses various training programs and e-learning to ensure awareness of the policy and regulations, as well as compliance requirements in each region.
Furthermore, if a leak of information held by Konica Minolta, including personal data, is confirmed or suspected, the matter is reported to the officer responsible for overall personal data protection under the KM-CSIRT framework. The facts and extent of the impact are then immediately assessed, and a system is in place for reporting the incident to personal information protection authorities in each country, such as the Personal Information Protection Commission in Japan.