Significant risks of the Fujitsu Group
Critical risks
1. Security risks
Overview and impact of risks
In recent years, cyberattack techniques have become increasingly sophisticated, and it has become difficult to completely prevent incidents such as malware infections, intrusions, and unauthorized access that may result in outages, information leaks, or unauthorized use of customer systems and the Group’s internal networks and systems.
If a data breach occurs and this results in the violation of individual rights or the leakage of customer information, trust in the Group could be significantly undermined, and the company may be subject to fines or penalties under laws and regulations such as the Act on the Protection of Personal Information and the GDPR (General Data Protection Regulation).
Furthermore, the rapid advancement of AI technologies in recent years is giving rise to new and constantly evolving cyber risks that are difficult to anticipate with conventional security measures. These risks are driven by factors such as the increasing sophistication of attacks exploiting generative AI and the proliferation of AI agents capable of autonomous judgment and action. In addition, the Group has implemented a multi-layered physical security framework including site, building, and floor-level controls. However, it remains difficult to completely prevent business interruptions or information leakage resulting from physical incidents. If such risks materialize, the consequences could include the exposure of confidential information, damage to corporate brand value, and loss of business opportunities, all of which could adversely affect the Group’s operations.
Measures against risks
To protect the confidential information and personal information of our customers, business partners, and the Group, we are strengthening the operation of our information protection management system. This includes establishing internal rules, providing employee training, conducting on-site inspections and audits, and offering guidance to contractors as well.
We have clearly stipulated security inspection systems in the rules that all organizations and projects must follow, and we thoroughly formulate and execute security response plans based on global information security standards to ensure robust system construction.
In order for its executive management, Business units, and CISO organization (governance function) to work together as a unified body to address security measures as a key management issue, the Group has established a "Company-Wide Security Risk Management Scheme" focused on the objective identification and visualization of security risks and the implementation of appropriate corrective measures. The Group has introduced information management dashboards and other tools to digitally visualize risks such as residual vulnerabilities in information systems and inappropriate information management, and we implement corrective actions.
Our internal network, a key foundation of the Group's business operations, is managed based on a zero-trust framework, implementing measures tailored to the characteristics of our IT infrastructure. To counter targeted attacks, we have established an authentication and authorization framework that combines measures such as unauthorized access prevention, malware countermeasures, device management, identity management, and data leak prevention, enabling us to address the increasingly sophisticated, diverse, and complex cyber threats we face.
In addition, we have centralized and visualized the management of IT assets for IT systems used by our global customers and our internal operations, enabling us to quickly identify and address security risks across the entire Group.
In addition, to address cyber risks that continue to evolve on a daily basis, including those associated with AI, we are enhancing our capabilities to analyze and detect attack methods and strengthening security governance for new forms of system use, including AI agents.
Furthermore, to address security risks at contractors, we are promoting measures to strengthen the security of our supply chain from both institutional and technical perspectives.
We have also established a physical security environment combining "human security" and "system security" across three layers: sites, buildings, and floors. To further enhance physical security, we are deploying security gates equipped with vein authentication devices capable of preventing impersonation throughout our sites.
2. Deficiencies or flaws in products and services
Overview and impact of risks
The Fujitsu Group regards quality as a core part of our business activities and works continuously to maintain and improve a networked society where people can live comfortably with peace of mind.
In entrusted system development, as well as the operation and maintenance of products and services, and the design, development, and manufacturing of products, customer requirements are becoming more sophisticated, and systems are becoming more complex. This raises the difficulty of developing products and increases the risk of defects and flaws in products. In addition, a decline in price due to intensifying competition may result in delivery delays and unprofitable projects.
If such defects, flaws, or delivery delays occur, product recalls and repairs, system recovery work, compensation to customers, and opportunity losses may impact the Group’s revenue and profitability.
Furthermore, if there are errors in judgment or inappropriate conduct in the course of responding to defects or flaws in our products or services, the Group’s corporate reputation may be damaged, potentially amplifying the negative impact on the Group’s profitability.
Loading component...
Significant risks
3. Risks of natural disasters and unforeseen incidents
(1) Risks related to natural disasters, infectious diseases, fires, etc.
Overview and impact of risks
In recent years, the frequency and impact of natural disasters, such as typhoons, flooding, and heavy snow, have been increasing due to global climate change. In addition, unforeseen events, such as major earthquakes in the Tokyo metropolitan area or along the Nankai Trough, outbreaks of infectious diseases, or volcanic eruptions, may occur on a scale that exceeds damage estimates. If such events occur, they may result in the suspension of business functions, the suspension of Internet Data Center (IDC) functions, damage to facilities, interruptions in the supply of electricity, water, and gas, suspension of public transportation and communication networks, shortages or delays in the supply of components from manufacturers, and disruption of the supply chain. These impacts could lead to the suspension of service delivery, including cloud services, and the shipment of products, thereby hindering the Group’s ability to continue business activities.

