Cybersecurity

Basic Policy

Cybersecurity is one of Aozora’s main areas of focus as a bank that has a responsibility for its customers’ important assets and information. Incidents such as information leaks and service outages caused by cyberattacks could have a material impact not only on Aozora’s management, including damage to our customers and affecting business continuity, but also on society as a whole. In order to provide reliable financial services, Aozora considers the stable operation of information systems to be one of its most important management responsibilities. We work to maintain the cybersecurity system and reduce risks across the entire Aozora Group.

Management Structure

Aozora has established a security policy and a systems risk management policy, and conducts cybersecurity management with the active engagement of senior management based on a risk appetite statement approved by the Board of Directors.
To strengthen our cybersecurity management framework, we have appointed a CISO*1, who is responsible for overall cybersecurity management. With this initiative, we have established a system through which the CISO reports to the CIO*2 as well as the CRO*3 from a Risk Management Group’s checks and balances perspective. The Cyber Security Office, a dedicated cybersecurity department formed within the IT Control Division, is responsible for establishing systems, strengthening countermeasures, monitoring, and emergency responses. We have also established a Cyber Security Incident Response Team “Aozora CSIRT,” which spans across the related groups/divisions and Group companies. By sharing cybersecurity trends and risks inherent within the Group as well as conducting ongoing cybersecurity training, the entire Group is prepared for emergency situations. Moreover, the Aozora cybersecurity management framework regularly undergoes third-party assessments based on the CRI Profile*4 and other external cybersecurity frameworks.

  1. Chief Information Security Officer
  2. Chief Information Officer
  3. Chief Risk Officer
  4. A cybersecurity framework established for financial institutions, which the Cyber Risk Institute, a not-for-profit organization, maintains and updates

Cybersecurity Management Structure

an image about Cybersecurity Management System an image about Cybersecurity Management System

Initiatives to Enhance Security

Multi-layered Technical Countermeasures and
Verification of Effectiveness

  • Entrance measures to prevent unauthorized network intrusion
  • Exit measures to prevent the leakage of information
  • Internal measures that presume attacks on the internal network
  • Verification of effectiveness of technical countermeasures through TLPT*5 by external experts

Strengthening of Cyber-resilience

  • Regular cybersecurity exercises involving members of the management team
  • Recovery tests using actual systems and equipment on the assumption that an incident has occurred

Analysis of Threat Trends

  • Gathering information such as vulnerabilities, attack strategies, and case studies of damage suffered by other companies
  • Systematic responses based on a study of potential impacts affecting Aozora and related risks

Security Training for Employees

  • Enhancement of ability to identify suspicious emails and ability to respond when opening them through targeted email training
  • Training through e-learning, videos, and online seminars based on the results of targeted email training and threat trends
  1. Threat-Led Penetration Testing (attack tests based on the threat analysis results to evaluate technical countermeasures and response procedures)
(As of July 2026)