TOP Sustainability Governance
Risk Management

Risk Management

The Tokyo Seimitsu Group has established “Risk Management Regulations” and a “Risk Management Committee,” which is headed by the president and COO, to identify and manage risks associated with business execution. Systems are in place to prevent potential risks from manifesting themselves and to prepare for crises. If a risk manifests itself, a “Risk Response Team” headed by the president and COO is immediately established to respond to that risk and take action to quickly settle the situation.

Risk Management Policy

1.

The Tokyo Seimitsu Group strives to prevent the occurrence of potential risks. If any risk has become apparent, President and COO and all employees work in unison to take prompt and prudent action.

2.

If any risk has become apparent, priority is given to protection and saving of human life.

Risk Management System

Risk Management Committee

Chairman

President and COO

Members

Committee Chairman, Audit and Supervisory Committee members, managing directors, managing executive officers, senior management, Group leaders, directors of subsidiaries, department heads, section chiefs and advisers

Risk Items and Content

The following risks are assumed to be the risks revolving around the business.

1.

Risks of occurrence of natural disasters and sudden events (earthquake, fire, storm and flood damage, terrorism, etc.)

2.

Risks caused by economic and financial market trends (business trends, fluctuation of currency rates, etc.)

3.

Risks caused by changes in customer investment trends (changes in semiconductor industry, automotive industry, etc.)

4.

Risks caused by competitor and industry trends (price competition, development competition, intellectual property rights, etc.)

5.

Risks concerning public regulations, policies and taxation (country risk, etc.)

6.

Risks concerning human resources (industrial accident, unexpected incident and accident, etc.)

7.

Risks concerning capital providers (changes in share ownership, etc.)

8.

Risks concerning IT system (IT system failure, etc.)

9.

Risks concerning the quality of products and services

10.

Risks concerning climate change

11.

Other risks associated with business execution

Business Continuity Plan

The Group has formulated a “business continuity policy” that places the highest priority on confirming and ensuring the safety of employees and their families, maintaining the supply of parts and materials necessary for customers to continue operations, and protecting human life and conducting rescue and recovery activities in the region. We review and adjust the Company’s business continuity plan (BCP) and plant BCPs on this basis. In fiscal 2023, as in the previous year, we continued to analyze assumptions of damage and vulnerabilities of current countermeasures in the event of a threat to each company and plant. We also analyzed and identified vulnerabilities with respect to BCP enhancement, starting with our response to climate change. Taking changes in the external environment into account, we continue to review and detail BCPs and manuals from a practical standpoint, as well as measures to ensure the continuity of product supply and service provision, in addition to seismic reinforcement measures at the level of each department, including general affairs, production management, manufacturing, and IT.

FY2023 BCP Performance

Reinforced buildings and equipment: Seismic reinforcement work in FY2023: Hachioji Plant No. 1 and No. 5

Enhanced internal and external inventories of maintenance parts and consumables for semiconductor manufacturing equipment

Established rules for the use of parts for display machines in emergencies in order to enhance the business continuity system for providing services in the precision measuring instrument business to customers impacted by disasters

Conducted annual DR (Disaster Recovery)* test of the Enterprise Resource Planning (ERP) system

Installed power backup equipment for the Enterprise Resource Planning (ERP) system at the head office of Tosei Engineering Corp.

Performed management of stockpiles and storage at each plant in accordance with “Rules for Managing Stockpiles in the Event of a Major Disaster”

Stockpiles and Storage at Each Plant

Hachioji Plant

Three days worth of stockpiles for 1,583 people

Hanno Plant

Three days worth of stockpiles for 400 people

Tsuchiura Plant

Two days worth of stockpiles for 30 people

*DR (Disaster Recovery)

Refers to the ability to mitigate damage, maintain functions, or recover and restore an information system that is seriously damaged by a natural disaster or other events. It also refers to the facilities, systems, and measures that are in place to prepare for such a situation

Safety Confirmation System

We have introduced a “Safety Confirmation System” for confirming people’s safety via mobile phones and smartphones following a disaster or accident. We explain the system to new employees and enforce early registration. We carry out operation drills twice a year (in June and December) to confirm the system’s effectiveness and to raise awareness of the system among all employees, and use the drill results to perform reviews and disseminate information. In fiscal 2023, in addition to conventional e-mail-based safety confirmations, we have made it possible to use safety applications and messenger applications together in order to improve the safety confirmation response rate and to anticipate delays in receipt or refusal of acceptance when actual safety confirmation e-mails are sent out. We continue to collect final response rate and elapsed time data, and implement measures for improvement.

Information Security

We believe that it is our responsibility to protect the information assets entrusted to us by our important customers and business partners as well as our own information assets. Accordingly, we have established the Information Security Policy as a guideline for information protection. The Information Security Committee is chaired by the CFO, and each company has a director in charge of security, a security manager, and a security subcommittee, and Group (affiliated) companies also participate in the committee. Although we have been implementing information security measures until now, unauthorized access to the servers of our Group companies was discovered in 2023. Taking this situation seriously, we have implemented the security enhancements since 2024.

Additionally, we are working to prevent leaks of confidential company information and personal information due to the expansion of the scope of conventional activities, including remote work (working from home), and provide education to improve individual employee literacy. Moving forward, we will strive to further strengthen our information security management system, including at Group companies, and work together to implement security measures.

Details of Security Enhancements (from 2024)

Contracted with an external SOC*¹ to establish a security monitoring system 24 hours a day, 365 days a year

Installed EDR*² software in all terminals in Japan and overseas to establish a system that can immediately detect and respond to suspicious behavior and cyber attacks

Introduced a globally-standardized document management platform

*¹ SOC (Security Operation Center)

A center comprised of a dedicated team that monitors and analyzes threats to information systems

*² EDR (Endpoint Detection and Response)

For the monitoring of endpoint devices such as PCs to detect and respond to suspicious behavior

Information Security Targets and Results

 

Target

Result

Number of regular information exchange
meetings on information security

18 times

38 times

Number of serious incidents

0 incidents

1 incident*

Proper management of personal information,
number of serious personal information leaks

0 incidents

0 incidents

Participation in security-related seminars

Twice per year

Twice per year

Provision of specialized security-related training

Twice per year

Four times a year

Information security training participation rate

98% or higher

99%

* Unauthorized access to the servers of our Taiwan subsidiary was discovered on September 12, 2023

Information Security System Chart

Information Security System Chart

A director in charge of security, a security manager, and a security subcommittee are assigned to each company, and Group (consolidated) companies also participate in the Information Security Committee.




Environment・Society・Governance

TOP Sustainability Governance
Risk Management