Information Security Management

The Cosmo Energy Group regards information assets as one of its important management resources and recognizes that managing risks such as cyberattacks, information leaks, and system failures is critical to ensuring business continuity and maintaining the trust of stakeholders. Based on the Basic Policy on Information Security approved by the Board of Directors, we strive to maintain and enhance corporate value by ensuring the confidentiality, integrity, and availability of information assets, while complying with laws and regulations as well as internal rules. In addition, as the adoption of new AI technologies advances, we have established AI principles to appropriately manage the associated risks and promote the responsible use of AI. In accordance with these policies and principles, we continuously review and improve our education, operations, technical measures, and management systems in order to maintain and enhance the information security standards of the Group as a whole.

Governance Structure

Information Security Management Structure

Within the Group, the Chief Digital Officer (CDO) is responsible for information security management, and the IT Initiative Department implements security measures. The status of information security initiatives and significant risk matters are reported to the Board of Directors and other relevant bodies in a timely manner, and a system ensuring continuous oversight at the management level has been established. In addition, we collaborate with Group companies and relevant departments to establish a framework for promoting security measures across the Group.

Cyber Incident Response Structure

The Group has established a Cyber Incident Response Team (CSIRT) within the IT Initiative Department. CSIRT works with law enforcement authorities and external specialized organizations during normal operations to gather threat intelligence and enhance its response capabilities. In addition, through participation in cyber exercises organized by external organizations and BCP exercises conducted on the assumption of business continuity, the CSIRT verifies and improves practical response procedures and the allocation of roles and responsibilities. When a cyber incident occurs, the CSIRT carries out a coordinated response ranging from early detection and initial response to preventing the spread of damage, analyzing the cause, and preventing recurrence. In the event of a serious incident, a Crisis Response Headquarters is established under the leadership of senior management, with relevant departments working together to respond on a company-wide basis, thereby minimizing the impact on business and facilitating an early recovery.

Information Security Initiatives

Security Education

The Group continuously conducts education and awareness-raising activities for all employees with the aim of enhancing information security awareness and response capabilities. We also regularly conduct e-learning programs, targeted attack email drills, new employee training, and other initiatives to ensure that each employee is able to make appropriate judgments and take appropriate actions in their day-to-day work.

Security Technical Measures

To reduce the risks of information leaks and system outages caused by cyberattacks, the Group implements multilayered defense measures for networks, endpoints, servers, and other systems. We also work to strengthen vulnerability management and access controls and to appropriately manage system configurations, while continuously advancing security measures in response to changes in the IT environment.

System Monitoring and Detection

The Group collects and analyzes logs from PCs, systems, and networks and conducts continuous monitoring to facilitate the early detection of anomalies. In addition, our Security Operations Center (SOC), which operates on a 24-hour, 365-day basis, monitors unauthorized access and communications to rapidly identify signs of incidents, prevent damage before it occurs, and minimize the impact of incidents.

Security Risk Management and Continuous Improvement

While referring to frameworks such as the NIST Cybersecurity Framework (CSF) 2.0, we engage third-party organizations specialized in security assessment to inspect and evaluate the effectiveness of our governance, risk management processes, and technical security measures, and we implement continuous improvements.