Komatsu recognizes that threats to information security are becoming increasingly sophisticated and complex each year. To enhance the overall information security level of the Group, we have clarified our policies regarding the establishment of management frameworks, protection of information assets, strengthening of system security, monitoring of networks and systems, and training and education for employees, and we are implementing corresponding activities.
In FY2025, there were no incidents that had a significant impact on our business.
Komatsu has established and operates a CSIRT (Computer Security Incident Response Team) covering its sites worldwide as an organizational structure for information security, including the capability to respond to cyberattacks. During normal operations, the CSIRT works to prevent information security incidents through activities such as information gathering, various system countermeasures, and employee education. In the event of an incident, the CSIRT aims to respond quickly, minimize damage, and restore systems as early as possible. Komatsu has also established SOCs (Security Operation Centers) in each global region to monitor systems and networks.
Because an initial response is extremely important in responding to cyberattacks, Komatsu has established employee reporting channels and a system for detecting signs of abnormal activity through SOC monitoring. Based on reports through these channels or signs of abnormal activity detected by SOCs, the CSIRT and SOCs promptly take initial response actions according to their respective roles, and consistently handle the process through root cause investigation and the formulation of measures to prevent recurrence. In the event of a major incident, Komatsu promptly reports it to the Risk Management Committee, which includes the President, directors, and the executive officer in charge of information security, and has established a structure to take appropriate actions based on management decisions.
In addition, to prepare for business continuity risks caused by cyberattacks, Komatsu is working to strengthen its emergency response capabilities by developing response manuals and conducting regular cyber-BCP drills.
At its production plants, Komatsu has established FSIRTs (Factory Security Incident Response Teams) and has built response structures to prepare for cyberattacks on plant networks and production equipment. In the event of an incident, FSIRTs and the CSIRT work together to minimize damage and enable an early resumption of production.
In addition, to continue providing customers with safe products and solutions, Komatsu works to ensure security from the planning and development stages, properly manages vulnerability information, and maintains response processes for cases where vulnerabilities are identified.
These initiatives are reported regularly to the Risk Management Committee, and important matters are also reported to the Board of Directors. Under the oversight of management, Komatsu appropriately manages information security across the Komatsu Group.
To appropriately protect the company's information assets, including personal and confidential information, Komatsu classifies and ranks information based on its importance, implements security measures such as access restrictions for storage locations and data encryption, and manages this information appropriately.
Komatsu recognizes that the proper protection of personal information—including that of customers, business partners, and employees—is essential for conducting business. We have established and comply with our "Global Privacy Policy" and ensure proper handling through e-learning programs and internal audits. We also work to protect personal information overseas in line with legal and societal requirements in each country and region, such as compliance with the General Data Protection Regulation (GDPR) in Europe.
To prevent information leaks caused by cyber threats such as external unauthorized access and computer virus infections, Komatsu implements system countermeasures based on a Zero Trust approach, in addition to multilayered defense, or Defense in Depth. Under Zero Trust, Komatsu does not unconditionally trust any access, whether from inside or outside the company. Instead, it verifies users, devices, access destinations, and usage status each time access is made, thereby reducing security risks.
In particular, for access from outside the company, including telework, as well as the use of business systems and cloud services as they increasingly move to cloud environments, Komatsu has introduced access management that combines multi-factor authentication (MFA) and device authentication. This ensures not only user authentication but also allows connections only from devices authorized for business use, thereby reducing the risk of information leaks caused by unauthorized access or spoofing. In cloud environments, Komatsu also promotes secure cloud use by appropriately managing access privileges, thoroughly applying the principle of least privilege, and monitoring usage logs.
Komatsu also implements continuous security measures to enable the early detection of cyber risks and strengthen response capabilities.
For vulnerability assessments, Komatsu conducts continuous monitoring and assessments as necessary for internet-facing servers, critical internal systems, and systems running in cloud environments. In addition, by monitoring and analyzing security logs and communication status, Komatsu has established a structure capable of detecting signs of cyberattacks, such as unauthorized access, malware infections, and abnormal communications, in real time.
Detected vulnerabilities and suspicious behavior are visualized and centrally managed using a control ledger, and the responsible system-owning departments respond promptly according to the level of risk and priority.
Penetration testing is outsourced to external specialized vendors and conducted once or twice a year. The testing specifications and scope are also reviewed as necessary, taking into account the progress of cloud adoption and trends in new cyber threats, to support continuous improvement.
Through these initiatives, Komatsu is strengthening its structure to detect signs of cyberattacks in real time across both on-premises and cloud environments, and to analyze and respond to them appropriately.
At Komatsu, appropriate handling of information is clearly defined as a standard of conduct to be followed by all employees, who are expected to actively engage in the proper protection and management of information. Recognizing that information security requires not only organizational and system-level measures but also individual responsibility, Komatsu promotes adherence to fundamental practices and continuous improvement of employee knowledge. In the event of a security incident, employees are required to promptly report to the CSIRT. To ensure that these principles and behaviors are well understood and practiced, Komatsu provides regular e-learning programs for all employees. In addition, targeted email attack simulations are conducted several times a year to strengthen awareness and preparedness.
These e-learning programs and training exercises are conducted not only in Japan but also at overseas subsidiaries, as part of Komatsu’s efforts to strengthen information security across its global operations.
By conducting audits related to information security, Komatsu is working to enhance the overall information security level across the Komatsu Group. These audits are conducted by Komatsu employees with specialized expertise, who also provide advice to increase their effectiveness. By conducting audits from an independent and impartial standpoint as parties with no direct interest, Komatsu ensures independence and fairness.
Komatsu requests that not only Komatsu and Group companies, but also dealers and partner companies that share Komatsu’s confidential business information, manage information security in line with Komatsu’s information security policies. Komatsu also provides ongoing and effective support. For dealers and partner companies, Komatsu recommends periodic checks and interviews using checklists regarding system measures for information devices and other equipment, as well as proper information management methods. Komatsu also recommends the use of its designated information security training materials. Through these activities, Komatsu shares with all relevant parties the need for appropriate information system management in handling confidential business information and ensuring stable business continuity, thereby reducing risks.