
In recent years, the cybersecurity risks facing companies have entered a new phase. In April 2026, US-based Anthropic announced an AI model — "Claude Mythos" — capable of autonomously identifying and exploiting software vulnerabilities at scale. The severity of the threat was deemed sufficient to warrant withholding the model from public release. In Japan, the Liberal Democratic Party's National Cybersecurity Strategy Headquarters and the Financial Services Agency have both initiated emergency response consultations, and vigilance is heightening across both the public and private sectors.
Against this backdrop, the importance of investors being able to properly assess the cybersecurity posture of the companies they invest in has never been greater. Cyber incidents carry consequences that extend well beyond direct financial damage — they can result in the loss of trust from customers and business partners, litigation risk, and ultimately the destruction of corporate value.
Cadira has long been attentive to the escalating cybersecurity risks posed by AI, and between January and March 2026 independently conducted a proprietary survey on "Cybersecurity Governance Frameworks" among its portfolio companies (35 respondents).
While the sample size is limited, the responses — gathered from companies with which we have conducted direct dialogue — provide a useful reference for understanding the state of governance at Japanese companies, and we report the findings below.
In response to the question "Over the past year or so, has cybersecurity been reported on or discussed at the board of directors level?", 80% of companies confirmed that cybersecurity reporting and discussion had taken place at board level, with a further 11% indicating that equivalent discussions had been held in forums such as risk management committees or internal control committees. The confirmation of management-level involvement at 91% of companies in aggregate suggests that a degree of baseline governance has taken root across the sample.
The Ministry of Economy, Trade and Industry revised its "Cybersecurity Management Guidelines Ver3.0" in March 2023(*1), and the Financial Services Agency published a standalone "Guidelines on Cybersecurity in the Financial Sector" — independent of its supervisory guidelines — in October 2024(*2). In light of these regulatory developments, the importance of cybersecurity discussion at board level is only set to increase going forward.
Q1. Over the past year or so, has cybersecurity been reported on or discussed at the board of directors level?
Discussed at board level: 80%
Discussed at equivalent committee: 11%
No reporting or discussion: 9%
Analysis of the substantive comments provided on board-level discussion topics reveals that the most common theme was the formulation and progress review of response policies and strategies (46%), suggesting that discussions involving management judgement and decision-making — such as reviewing future strategies and tracking the progress of initiatives in light of changes in the external environment — are widely taking place. The second most frequent theme was incident response and case sharing (37%), encompassing the sharing of the company's own incident experience, review of internal risks in light of peer examples, and other practically oriented risk management discussions. A notable proportion of respondents also cited governance framework and policy development (23%), and it is encouraging that a number of companies appear to have established the board as a forum for management judgement and decision-making, rather than merely a venue for reporting.
On the other hand, references to exercises and drills, and to vulnerability assessments and monitoring frameworks, each accounted for only 11% of responses. This may reflect a mindset that treats cyber incidents not as events that "might happen" but as events to be managed on the assumption that they "will happen" — a posture that can be seen as an important indicator of board-level commitment.
Q2. Please describe the content of cybersecurity-related reporting or discussions conducted at the board of directors or equivalent level (Multiple responses permitted)
Formulation and progress review of response policies and strategies: 46%
Incident response and case sharing: 37%
Governance framework and policy development: 23%
Exercises and training: 11%
Vulnerability assessment and monitoring frameworks: 11%
No comment provided: 37%
When asked who within the organisation bears ultimate accountability for cybersecurity, the most common response was a CIO, CDO, or equivalent IT executive (31%), followed by a director or executive officer serving in a concurrent capacity (29%). Together, these two categories account for approximately 60% of companies where ultimate cybersecurity accountability rests with either the IT function or a member of management in a concurrent role — suggesting that questions of expertise remain. A further 17% of companies indicated that the President and CEO bears direct responsibility, reflecting a meaningful number of cases where the top executive is at the forefront.
Only 9% of companies have a dedicated Chief Information Security Officer (CISO) in a full-time role. Among Fortune 500 companies, virtually all had appointed a dedicated CISO by 2022, with some 40% having since created a Deputy CISO position to deepen organisational capability. By comparison, the prevalence of concurrent roles held by IT executives or the CEO at Japanese companies highlights the challenge of securing dedicated management-level expertise in cybersecurity.
A small but notable proportion of companies identified a divisional general manager as the ultimate accountable party (11%), and 2% indicated that accountability was "undecided" — suggesting that responsibility structures remain in flux at some organisations.
Q3. Please indicate the title of the individual who bears ultimate accountability for cybersecurity.
CIO / CDO or equivalent IT executive: 31%
Director / Executive Officer (concurrent): 29%
President and CEO: 17%
Divisional General Manager: 11%
Dedicated CISO: 9%
Undecided / Unknown: 3%
Regarding the scope of cybersecurity monitoring, 66% of companies — the largest proportion — indicated that their monitoring covers the entire group, suggesting a reasonable baseline from a group governance perspective. However, a substantial 51% of respondents indicated coverage limited to the listed parent company only, confirming that a meaningful number of companies have limited capacity to address breach risks originating through subsidiaries or affiliates.
Only 17% of companies have extended their monitoring scope to include business partners and suppliers. Recent cyber attacks have increasingly targeted the weak points of supply chains rather than internal systems. Under the NIST Cybersecurity Framework and ISO certification standards (ISO 27001), third-party risk management is recognised as a critical requirement — and the strengthening of monitoring frameworks across the entire supply chain, including business partners, remains an important challenge going forward.
Q4. What is the current scope of your cybersecurity monitoring? (Multiple responses permitted)
Group companies (all): 66%
Listed parent company: 51%
Group companies (selected): 26%
Business partners (selected): 17%
Business partners (all): 0%
No response: 6%
The above presents the findings of our survey on cybersecurity governance frameworks, conducted among listed companies between January and March 2026.
The survey confirmed management-level involvement in cybersecurity at 91% of companies, indicating that the foundations of governance have been established to a meaningful degree. At the same time, with dedicated CISOs in place at only 9% of companies and only 14% having extended monitoring to cover the supply chain, there remains significant room for improvement in the transition from "formal involvement" to "effective risk management."
As the advancement of AI makes the sophistication and automation of cyber attacks an increasingly tangible reality, gaps in these frameworks represent a risk that can directly affect corporate value. Cadira will continue to engage with its portfolio companies through dialogue, working to improve the effectiveness of cybersecurity governance.
*1 Cybersecurity Management Guidelines and Support Tools: https://www.meti.go.jp/policy/netsecurity/mng_guide.html
*2 Cybersecurity Measures in the Financial Sector: https://www.fsa.go.jp/policy/cybersecurity/index.html
Learn More
The Shift Toward Growth-Oriented Corporate Governance
More than a decade has passed since Japan's corporate governance reforms began in 2015, and this yea...
Reflections on Succession Planning Following the Revision of the Corporate Governance Code
Key Points of the Corporate Governance Code RevisionIn July 2026, the Corporate Governance Code was ...
The Impact of AI's Evolution on Asset Management
AI Adoption: Rapid Spread, Gap in ResultsThe evolution of AI is bringing about a structural shift in...
The Need to Reassess Risks considering Extreme Weather
Growing Cost of Extreme Weather Risk MitigationIn May 2026, CDP (Carbon Disclosure Project, an NGO p...
Survey on Cybersecurity Governance Systems (2026Q1)
In recent years, the cybersecurity risks facing companies have entered a new phase. In April 2026, U...
The Impact of Large-Scale Military Operations Against Iran
Japan’s Crude Oil and LNG ProcurementFollowing the large-scale military operation conducted by the U...
A Review of the Lower House Election Results and Key Themes Ahead
Lower House Election ResultsIn the February 2026 general election for the House of Representatives, ...
Japan’s Evolving Discount Rate — Re-examining Corporate Valuation in a Rising Interest Rate Environment
Interest Rate Trends and BackgroundLong-term interest rates in Japan have been rising. Comparing Jan...
Further Revision of Governance and Shift in Management Resource Allocation: Expanding the Scope of Growth Investment in the Japanese Stock Market
Review of 2025The Japanese equity market in 2025 experienced a broadly strong upward trend. The TOPI...
AI-Powered Threats: How Cybersecurity Became a C-Suite Priority
Cybersecurity DamageIn recent years, cybersecurity incidents have continued to rise sharply. Accordi...
AI-Related Corporate Survey: Internal Training and Policy Status at 34 Listed Companies
At Cadira Capital Management, we conduct surveys after IR meetings with listed companies, focusing o...
Japan's First Female Prime Minister: The Takaichi Administration and New Investment Opportunities
Japan’s First Female Prime MinisterIn October 2025, Sanae Takaichi was elected Prime Minister of Jap...
Defining the Boundaries of Sustainable Investing in an Era of Expanding Defense Spending — Cadira’s Investment Policy
In recent years, rising geopolitical tensions have heightened the importance of the defense industry...
Japan’s Stewardship Code, Third Revision: Accelerating Collaborative Engagement Between Investors and Companies
In June 2025, Japan’s Stewardship Code underwent its third revision. The key points of this revision...
Evolving IR Practices in Japan: Insights from Cadira’s Q2 2025 Survey
At Cadira Capital Management, we conduct ongoing surveys with listed companies following our IR meet...
Staying Grounded Amid Political and Trade Uncertainty in Japan
At Cadira Capital Management, we believe that while macro-level developments such as politics and tr...
Gender Reform as a Catalyst: What Sustainable Investors Should Watch in Japan
On June 11, the World Economic Forum released its Global Gender Gap Report 2025 (*1), in which Japan...
What GPIF’s Stewardship Reports Reveal About the Future of Investor Engagement
In recent years, M&A activity and activist investor engagement have been gaining momentum in the...
From Disclosure to Dialogue: What We Learned from Publishing Our Progress Report 2024
Since the publication of our inaugural Progress Report 2024 in March, we have held discussions ...
Aligning Incentives for Sustainable Growth — Results from Our Survey on Equity-Based Compensation
At Cadira Capital Management, our investment management team conducts post-IR meeting surveys with t...
Agility Matters More Than Ever—The Impact of U.S. Tariff Policy and Implications for Japanese Equities
When the environment is highly uncertain, investors cannot rely solely on a company’s current busine...
Governance Reforms and the Future of Japan’s Listed Subsidiaries: Unlocking Value through Transparency
Efforts to enhance corporate governance in Japan continue to advance steadily. The Tokyo Stock Excha...
On the Possibility of GPIF to engage in Impact Investing
Within Japan's impact investment community, there is growing discussion about the possibility of the...
Acceleration of AI Investment and Its Impact
Massive AI Investments by HyperscalersMajor global IT companies, known as hyperscalers, are aggressi...
On the Publication of the Draft 7th Strategic Energy Plan
On December 17, the Ministry of Economy, Trade, and Industry (METI) of Japan released the draft of t...
Strengthening Human Capital: Insights from Cadira’s Investor–Company Dialogue
Cadira’s investment team conducts post-meeting surveys following IR meetings.These surveys include q...
On Economic Rationale for Sustainability
This has been a year of many elections around the world. Looking back, it seems that support for pop...
Trends in the US Housing Market
Housing was one of the key issues of the 2024 U.S. presidential election. Skyrocketing home prices a...
On Japan’s House of Representatives Election on October 27
Elections to the House of Representatives were held on October 27. The Liberal Democratic Party (LDP...
On the 2024 LDP Presidential Election
On October 1, Shigeru Ishiba was sworn in as Prime Minister of Japan. Prior to this, on September 27...
August Stock Market Volatility and Subsequent Outlook
The Japanese stock market plunged in the first half of August, with the TOPIX posting historic decli...
On the Growth Potential of the Japanese Local Economy
Capital investment in Japan continues to expand. Looking back at capital investment in corporate sta...
Our View on the TOPIX Revision Proposal
On June 10, 2024, the Japan Exchange Group announced a proposal to revise the TOPIX, Japan's benchma...
Impact IPOs: Current Status and Challenges
Cadira Capital Management met with two companies that went public last year as "impact IPOs". Below ...
On the Japanese Government's Support for Impact Investing
The Japanese government has been taking initiatives to promote impact investing. Following the relea...
On the Recent Weakening of the Japanese Yen
The yen-dollar exchange rate reached 160 yen on April 29, 2024. This is the yen's weakest level in 3...
On the Bank of Japan's Rate Hike
On March 19, 2024, the Bank of Japan decided to raise its policy rate from -0.1% to 0-0.1%. This is ...
On the Growing Interest in the Japanese Stock Market
On February 22, 2024, the Nikkei Stock Average reached a new market high for the first time in 34 ye...
Impact Integrated Value (IIV)
How can we effectively integrate both positive and negative impact when making investment decisions?...
Positive Impact Assessment
Integration of positive impact in corporate valuation poses significant challenges. For standardized...
Our Investor Contribution
Engagement is a core activity essential to achieving our mission. It is conducted with the aim of ma...
Sustainable Companies
The Japanese stock market is in a situation where structural changes are creating new investment opp...
Structural Investment Opportunity
At Cadira Capital Management, we believe that investor engagement will bring about a structural chan...
Listed Equity Impact Investing: Challenges and Opportunities
An approach known as "impact investing" is becoming increasingly popular in the investment world. In...
Our Investment Philosophy
At Cadira Capital Management, we believe that "investing for sustainability" will deliver superior r...
Our Views on Geopolitical Risks
The conflict between Israel and Palestine erupted on October 7th, raising concerns about geopolitica...
Perspectives on Equity Investing in a Declining Population
"Is there any reason to invest in countries with declining populations?"This is an unavoidable quest...
Our Comments to the “Draft Basic Guidelines on Impact Investment” by the Financial Services Agency of Japan
On June 30, 2023, the Financial Services Agency of Japan released the "Draft Basic Guidelines on Imp...
Our Views on Exchange Rate Risks
The Bank for International Settlements (BIS) announced that the real effective exchange rate (*1) fo...
Our Bottom-up Approach to Listed Equity Impact Investing
At Cadira Capital Management, we take a unique bottom-up approach to impact investing in public equi...
Important Notice
The content of this website has been prepared by Cadira Capital Management Co., Ltd. (“CCM”) for informational purposes only to professional investors who are expected to make their own investment decisions without undue reliance on such content. The views and strategies described may not be suitable for all investors. Under no circumstances is it to be used or considered as legal or investment advice, a recommendation to buy, an offer to sell, or a solicitation of an offer to buy or sell securities and investors should be advised to consult their own stockbroker, accountant, solicitor, independent financial adviser, or other professional adviser for advice. We accept no liability whatsoever for any direct or consequential loss arising from any use of this content. The information is intended solely to report on investment strategies and opportunities identified by CCM. Opinions and estimates offered constitute our judgment and are subject to change without notice, as are statements of financial market trends, which are based on current market conditions. CCM and its affiliates do not warrant the accuracy or completeness of any of the information or data contained herein. References to specific securities and their issuers are for illustrative purpose only and are not intended to be, and should not be interpreted as investment advice or, a recommendation, offer or solicitation for the purpose or sale of any financial investment. This content does not constitute tax advice and as such investors should be advised to consult their own tax advisers regarding the tax consequences of their investment activities. Investment return and principal will fluctuate, so that a client's initial investment may increase or decrease. Investing in securities markets involve risks like those arising from stock and bond markets, currency exchanges rate and interest rate volatility. No part of this content may, without CCM prior written consent, be copied, reproduced, or published by any recipient for any purpose. Past performance is not indicative of future performance.