Information security
Policy
The world is facing more frequent and severe cyberattacks than ever before, which result in a wide range of damages. With advancements in technology that enable the discovery of internet-facing system, it has become easy for any attacker to identify vulnerabilities and launch attacks. Meanwhile, the threats and methods of attack—which we must now be prepared for—are becoming increasingly sophisticated, including exploitation of unknown vulnerabilities and attacks launched within days from public disclosure of vulnerability.
Given this environment, the Fujitsu Group conducts its activities based on Our Purpose which is to “make the world more sustainable by building trust in society through innovation.” Fujitsu works with many customers to create value for society. We recognize that if Fujitsu were to encounter a cyber incident, the impact would not be limited to our company alone but could extend to our customers and society as a whole. As such, cybersecurity is positioned as a critical management issue. From top executives to the field organization, the entire organization is united in addressing this challenge. To achieve our information security goals, we have established a “Company-Wide Security Risk Management Scheme.”
Approach to security management
Since 2021, Fujitsu has experienced multiple serious security incidents, and those in the field organization who are responding to them have faced various internal issues. Addressing these issues, we recognized the need to become—and remain—an organization that is attack-resilient. Being “attack-resilient” means creating a situation where attackers perceive that attacking our organization is not easy and that the likelihood of a successful attack is low.
To become an organization that is attack-resilient, we are thoroughly eliminating security risks that could serve as potential entry points for external attacks, such as vulnerabilities in internet-facing assets. By doing so, we aim to create a state where it is extremely difficult for attackers to even identify potential entry points, and even if one is found, executing an attack becomes highly challenging.
Security risk management as an attack-resilient company
Fujitsu’s conventional approach to security risk management was rooted in standard risk management practices, with an emphasis on minimizing damages through post-incident response. As a result, potential risks that went unrecognized by field organization gradually enlarged, and the severity of those risks only became apparent after an incident had occurred.
In light of this, we believe it is necessary to proactively identify and materialize potential risks from attackers perspective, and to implement countermeasures in advance. This approach is essential to minimizing the impact of cyber threats. Given the increasingly short window between risk discovery and actual attacks in today’s threat landscape, it is imperative to adopt a management framework that enables early risk detection and swift response.
To achieve this, Fujitsu has established mechanisms to proactively identify potential risks by anticipating a wide range of risk scenarios. These mechanisms enable the comprehensive identification of potential risks and the determination of the field organizations responsible for addressing them. Identified risks are analyzed (e.g., attack difficulty) and assessed (e.g., likelihood and potential impact) to determine response strategies and priorities. For high-priority risks, the organization responsible for company-wide security control (CISO organization) under the CISO (Chief Information Security Officer) directly guides the relevant field organizations in implementing the necessary countermeasures.

Scope of security measures
To support the realization of Our Purpose, Fujitsu is implementing security measures based on the assumption that cyber attackers may target not only Fujitsu itself but also our partners and SaaS offerings on our cloud infrastructure. These measures are designed to safeguard customer information across the entire supply chain, both domestically and internationally. Our efforts span cybersecurity for systems that deliver value to our customers (business systems) and those that support internal operations (corporate systems). In addition, we focus on robust information management to ensure proper handling and protection of data and extend our security initiatives to the products we provide as well as to partner companies that form part of our supply chain.

Company-wide Security Risk Management Scheme
Loading component...
Scheme overview
Loading component...
Loading component...
Loading component...
<Company-wide security risk management in accordance with the scheme>
Loading component...
Structure and communication of security measures during implementation
Loading component...
- (*1)
- System Security Manager: Person responsible for overseeing the maintenance and management of information systems security.
- Information Manager: Person responsible for overseeing information management and protection.
- PSIRT Manager: Person responsible for overseeing the management of product related vulnerabilities.
Loading component...
<Policies/Standards>
Loading component...
- (*2) NIST: National Institute of Standards and Technology
- (*3) SP800-37: NIST SP800-37 Rev.2 Risk Management Framework
- (*4) CSF: Cybersecurity Framework
- (*5) SP800-53: NIST SP800-53 Rev.5 Security and Privacy Controls for Information Systems and Organizations
Visualization of security risks
Loading component...
Cybersecurity measures
Loading component...
Measures linked to centralized IT asset management
<Autonomous risk remediation through centralized and visualized IT asset management>
Loading component...
Loading component...
<Vulnerability detection and remediation>
Loading component...
Loading component...
<Utilization of threat intelligence and attack surface management>
Loading component...
<Establishment of an emergency vulnerability response process>
Loading component...
Thorough monitoring
Loading component...
Protection of important information
Loading component...
Response to incidents
Loading component...
Loading component...
<Sophistication of incident response>
Loading component...
Risk prevention in our products and services
<xSIRT regime>
Loading component...
- (*6) xSIRT: Security Incident Response Team
An organization or regime that handles incidents that affect products and services offered by Fujitsu.
<Process formulation>
Loading component...
- (*7) CISA: The U.S. Cybersecurity and Infrastructure Security Agency
Loading component...
Information management
Loading component...
Loading component...
<Information Protection Management System>
Loading component...
Loading component...
Loading component...
Loading component...
Protection of personal information
Loading component...
Loading component...
- (*9) The PrivacyMark:
The PrivacyMark is granted to businesses that handle personal information appropriately under a personal information protection management system that conforms to JIS Q 15001.
In FY2025, Fujitsu Customer Service Center Personal Information Protection Desk did not receive any consultations or complaints regarding customers’ privacy. No customer information was provided to government or administrative agencies in accordance with the Act on the Protection of Personal Information.
Acquisition of information security/information system certification
Fujitsu Group is actively promoting the acquisition of third-party evaluation and certification in our information security efforts.
Initiative to promote autonomous improvement at the operational level
Loading component...
Visualization of organizational maturity
<Maturity monitor>
Loading component...
- (*10) C2M2: Cybersecurity Capability Maturity Model
- (*11) SIM3: Security Incident Management Maturity Model
Loading component...
Loading component...
Third-party assessments
Loading component...
Loading component...
(As of April 2026)
Loading component...
Security-related human resource development
Loading component...
<Security education and training>
Loading component...
<Strengthening information security structure and human resource development>













