Information Security Management

NSK’s Approach

The use of digital technology is expanding across an increasingly wide range of fields. At the same time, the volume of information and data is also increasing dramatically with the forms in which it is held and used continuing to diversify. In this business environment, in addition to the risks associated with information leaks and violations of laws due to the improper handling of information, there is also a higher risk of increasingly sophisticated cyberattacks, which could bring supply chain operations to a halt. Positioning information security management as one of its important management tasks, the NSK Group has established the NSK Group Basic Policy on Information Security and is working to reduce a variety of risks while strengthening its response to relevant laws and regulations. Moreover, we are promoting initiatives for more robust mechanisms and organizational structures, such as network countermeasures, against increasingly sophisticated cyberattacks.

◆Basic Policy and Management Standards and Rules

The NSK Group has established a basic information security policy with the approval of senior management and put in place subordinate rules and regulations. We review and expand this policy, as well as rules and regulations, in line with the enforcement and revision of statutory and regulatory requirements and changes in our operating environment. Moreover, we are working to ensure that information security rules and risk countermeasures are implemented throughout the organization via increased awareness, development, and education, as well as periodic checks on the status of their penetration. These rules and regulations apply to all personnel who handle information within NSK Group companies, including officers, employees, and temporary staff. Furthermore, we require that appropriate information security measures are in place whenever confidential information is shared with third parties. These measures include clearly defining information security requirements through contractual agreements.

Major Information Security-Related Regulations
NSK Group Basic Policy on Information SecurityThis policy sets out the objectives for the NSK Group’s information security (information security initiatives, handling of information assets, compliance with laws, regulations, and contracts, as well as education and continuous improvement).
NSK Group Basic Policy on Information Security
NSK Group Information Security Management StandardsAs the top information security directives in the NSK Group, these standards outline the principles for bringing the levels of information security management across the Group up to the same high standard.
NSK Group Information Security Procedural StandardsThese rules stipulate measures to protect information assets, such as proper methods for handling information assets that need to be adopted across the NSK Group.
AI Utilization Management Procedural StandardsThese standards stipulate the basic policy and operating guidelines to ensure that risks associated with business use of AI are appropriately managed at the NSK Group and that AI can be used safely and securely.

System

◆Information Security Management System (ISMS)

The key priorities of the NSK Group’s Mid-Term Management Plan, MTP2028, include the continued development of a platform for data-driven management and provision of value in business by expanding utilization of digital technology, including AI, and the Group has been working to address these priorities. We established the Information Security Division (Digital Trust Security Department) under the Digital Transformation Division Headquarters at NSK Ltd., the Group headquarters, to enable the safe use of digital technology and to globally deploy information security enhancement measures that take into account the relationship between digital technology and cybersecurity. As of April 2026, the person responsible for executing information security initiatives across the NSK Group is the Head of the Digital Transformation Division Headquarters (Operating Executive). Moreover, information security-related risks are supervised under the Corporate Risk Management System and are reviewed and discussed by the Board of Directors as a group-wide issue. Senior management, including the Representative Directors, also receive reports on the status of security risks, countermeasures, and other related issues at the NSK Group from the Information Security Division at quarterly meetings of the Digital Transformation Committee, and they issue instructions for improvement as necessary.

Risk Management | NSK Global

The Information Security Division regularly holds global meetings, working in cooperation with information security management committees in Japan, the Americas, Europe, China, ASEAN and Oceania, India, and South Korea. NSK is working to improve the information security management level of the entire NSK Group, and to plan and implement information security measures.

Furthermore, NSK has established a CSIRT* organization to quickly and appropriately respond to cyberattacks, aimed at preventing the spread of damage and facilitating swift recovery. NSK is also a member of the Nippon CSIRT Association.

* CSIRT is an abbreviation for Computer Security Incident Response Team, an organization that rapidly responds to computer security incidents.

Governance
Information Security Management System (ISMS)

Goals, Targets, and Achievements

◆Mid-Term Management Plan 2026 (MTP2026) Goals, with Targets and Achievements for Each Fiscal Year
Policy
  • Respond to risks associated with the convenience of information handling due to the rapid development of information and communication technology and strengthen compliance with relevant laws and regulations
  • Establish a highly secure IT infrastructure to address increasingly sophisticated cyberattacks and take initiatives to strengthen the incident response structure
MTP2026Goals
  • Strengthen security governance management operations
  • Strengthen cybersecurity risk countermeasures
  • Strengthen infrastructure security
FY2025Targets
  • Strengthen standardization at the global level
  • Strengthen security governance for group companies
  • Improve cybersecurity response capabilities through education and training
  • Deploy global standard tools and platforms

Achievements

 

  • Strengthened cybersecurity response capabilities across the NSK Group
  • Strengthened the security governance system at the global level
  • Took part in FY2025 “collaborative drill” (security incident response drill) organized by National center of Incident readiness and Strategy for Cybersecurity (currently the National Cybersecurity Office) and Nippon CSIRT Association 
  • Ran incident response training at plants and Group companies in Japan
  • Implemented information security inspections of suppliers, including Group companies, and conducted monitoring utilizing an external assessment service
  • Regularly held various types of education and training for all officers and employees
  • Deployed standard security tools and services (monitoring platforms, PC protection, etc.) at the global level
  • Deployed security shared services in sites at some overseas regions 
  • Held global information-sharing meetings on security risk management
◆Mid-Term Management Plan 2028 (MTP2028) Goals, with Targets and Achievements for Each Fiscal Year
Policy
  • Prevent large-scale damage due to cyberattacks, and develop business continuity plans (BCP) and strengthen responses to be implemented in event of disaster
  • Strengthen security at Group companies inside and outside Japan and comply with applicable laws and regulations (Supply Chain Security (SCS) Evaluation System and Cabinet Office’s AI Act in Japan, Cyber Resilience Act in the EU, etc.)
MTP2028Goals
  • Strengthen response to cybersecurity risks
  • Establish AI governance
  • Strengthen security at Group companies inside and outside Japan
  • Comply with new applicable laws and regulations
FY2026Targets
  • Expand deployment of standard security tools and services
  • Complete the development of cyber BCP in Japan
  • Provide security education related to use of AI
  • Deploy security shared service to major Group companies
  • Address the Supply Chain Security (SCS) Evaluation System and the Cabinet Office’s AI Act in Japan, the Cyber Resilience Act in the EU, etc.

Initiatives

◆Enhancing Information Security Management

By utilizing globally adopted guidelines and frameworks (NIST Cyber Security Framework 2.0, CIS Controls, etc.) developed by professional cybersecurity organizations, NSK is forging a balanced approach to information security management in the context of people and organizations, processes, and technologies, while incorporating the concept of cyber resilience and working to strengthen these initiatives.

Status of Security Certifications

NSK has established a PDCA cycle for its information security management system, which includes periodic inventory and risk assessments (internal audits) of information assets and develop plans to handle and mitigate identified risks. As a result, based on demands from customers, NSK Group companies in Europe, China, and Japan acquired TISAX,* a security certification widely adopted in Germany’s automobile industry.

* Trusted Information Security Assessment Exchange (TISAX): A corporate assessment and certification system based on the VDA Information Security Assessment (VDA ISA) framework developed by the German Association of the Automotive Industry (VDA).

Enhancing Incident Response Capabilities

We are advancing technical measures to detect suspicious activities and security threats on information devices and networks. Information about detected incidents is analyzed by the Security Operations Center,*1 which then implements countermeasures. With this structure, we have established mechanisms for swiftly responding to security incidents. In addition, vulnerabilities that affect the entire NSK Group are monitored utilizing security rating services*2 and attack surface management (ASM) tools.*3
In view of the significant impact of recent security incidents on the supply chains of other companies, we also carry out information security inspections at suppliers and strive to enhance their security level. Efforts are also underway to enhance the incident response structure at NSK plants to enable not only an IT response, but an OT*4 response to incidents, as well.

*1 Security Operations Center is an organization dedicated to detecting, analyzing, and taking countermeasures to cybersecurity threats.
*2 Security rating services quantify a company’s security measures to provide ratings that are useful in external and internal risk assessment and the formulation of countermeasures.
*3 Attack surface management is a series of processes executed to discover IT assets that are accessible from outside the organization (via the Internet) and to continuously identify and assess the vulnerabilities and other risks they present.
*4 Operational technology (OT) consists of plant and other facility control systems. Whereas IT deals specifically with information, OT is considered unique in that it interacts with the physical environment.

Training and Countermeasures Against Cyberattack

NSK conducts annual drills simulating incidents triggered by cyberattack. In FY2025, as in the previous year, we participated in the NISC/NCA collaborative drill* held by the Nippon CSIRT Association to verify whether our response structure would function effectively in the event of an actual incident. We also collaborate with regional system management departments to provide training on targeted attack emails to all officers and employees who use a PC. Incident response drills at plants simulate attacks that have taken down internal plant systems and OT systems. We evaluate our incident response procedures to ensure production continuity in the event of an emergency and improve them based on identified issues.

* NISC/NCA collaborative drills are cyber drills executed jointly by the National center of Incident readiness and Strategy for Cybersecurity (NISC) and Nippon CSIRT Association (NCA). NISC conducts an annual all-sectoral critical infrastructure provider drill (cybersecurity tabletop exercise) every December for NCA members.

Image from Targeted Attack Email Training

Educational content is displayed to employees who do not handle a suspicious email properly, in order to help officers and employees thoroughly understand the appropriate actions to be taken.

Image from targeted attack email training
◆Enhancing Information Security Awareness
Prevention of Information Leaks and Information Security Education

The NSK Group has established rules for classifying and appropriately handling information according to the confidentiality level of information assets, paying close attention to the handling of confidential information and striving to prevent information leaks. As part of our education and awareness efforts, we conduct regular e-learning programs for officers and employees around the world. Furthermore, we provide training by role categories, such as officers and system management department members and training at the time of hiring or before being posted overseas, and we regularly provide related information. In this way we work to maintain and enhance the information security awareness of all officers and employees.

Information Security Desk

The NSK Group has an internal system for disseminating security information and receiving security incident reports. We also have an escalation process to ensure that appropriate procedures are carried out when such reports are made.

Information Security Desk
◆Strengthening Risk Management Related to Business Use of AI
Establishing AI Governance

The NSK Group has established the AI Utilization Management Procedural Standards to ensure that AI can be used safely and securely. The standards clearly specify responsibilities and roles related to the planning, development, introduction, use, evaluation, and overall management of AI and mandate the implementation of appropriate management of the risks associated with AI use. In addition, the standards require all parties involved in the use of AI to comply with the Corporate Code of Ethics and internal regulations related to personal information and information security. 

In particular, in the development of AI, the standards require that the source of data used in development is recorded and that risks involving data accuracy, fairness, and bias are identified. The standards also require that, wherever possible, the rationale behind AI-generated outputs should be explainable.

Moreover, in the use of AI, the standards require users to make their own judgements about the content of the output based on an awareness that AI-generated output may contain errors and inaccuracies.

Compliance | NSK Global

Privacy Policy | NSK Global