2026.5.14

Survey on Cybersecurity Governance Systems (2026Q1)

In recent years, the cybersecurity risks facing companies have entered a new phase. In April 2026, US-based Anthropic announced an AI model — "Claude Mythos" — capable of autonomously identifying and exploiting software vulnerabilities at scale. The severity of the threat was deemed sufficient to warrant withholding the model from public release. In Japan, the Liberal Democratic Party's National Cybersecurity Strategy Headquarters and the Financial Services Agency have both initiated emergency response consultations, and vigilance is heightening across both the public and private sectors.

Against this backdrop, the importance of investors being able to properly assess the cybersecurity posture of the companies they invest in has never been greater. Cyber incidents carry consequences that extend well beyond direct financial damage — they can result in the loss of trust from customers and business partners, litigation risk, and ultimately the destruction of corporate value.

Cadira has long been attentive to the escalating cybersecurity risks posed by AI, and between January and March 2026 independently conducted a proprietary survey on "Cybersecurity Governance Frameworks" among its portfolio companies (35 respondents).

While the sample size is limited, the responses — gathered from companies with which we have conducted direct dialogue — provide a useful reference for understanding the state of governance at Japanese companies, and we report the findings below.

Board-Level Reporting and Discussion of Cybersecurity

In response to the question "Over the past year or so, has cybersecurity been reported on or discussed at the board of directors level?", 80% of companies confirmed that cybersecurity reporting and discussion had taken place at board level, with a further 11% indicating that equivalent discussions had been held in forums such as risk management committees or internal control committees. The confirmation of management-level involvement at 91% of companies in aggregate suggests that a degree of baseline governance has taken root across the sample.

The Ministry of Economy, Trade and Industry revised its "Cybersecurity Management Guidelines Ver3.0" in March 2023(*1), and the Financial Services Agency published a standalone "Guidelines on Cybersecurity in the Financial Sector" — independent of its supervisory guidelines — in October 2024(*2). In light of these regulatory developments, the importance of cybersecurity discussion at board level is only set to increase going forward.

Q1. Over the past year or so, has cybersecurity been reported on or discussed at the board of directors level?

Discussed at board level: 80%

Discussed at equivalent committee: 11%

No reporting or discussion: 9%

Topics Discussed at Board Level

Analysis of the substantive comments provided on board-level discussion topics reveals that the most common theme was the formulation and progress review of response policies and strategies (46%), suggesting that discussions involving management judgement and decision-making — such as reviewing future strategies and tracking the progress of initiatives in light of changes in the external environment — are widely taking place. The second most frequent theme was incident response and case sharing (37%), encompassing the sharing of the company's own incident experience, review of internal risks in light of peer examples, and other practically oriented risk management discussions. A notable proportion of respondents also cited governance framework and policy development (23%), and it is encouraging that a number of companies appear to have established the board as a forum for management judgement and decision-making, rather than merely a venue for reporting.

On the other hand, references to exercises and drills, and to vulnerability assessments and monitoring frameworks, each accounted for only 11% of responses. This may reflect a mindset that treats cyber incidents not as events that "might happen" but as events to be managed on the assumption that they "will happen" — a posture that can be seen as an important indicator of board-level commitment.

Q2. Please describe the content of cybersecurity-related reporting or discussions conducted at the board of directors or equivalent level (Multiple responses permitted)

Formulation and progress review of response policies and strategies: 46%

Incident response and case sharing: 37%

Governance framework and policy development: 23%

Exercises and training: 11%

Vulnerability assessment and monitoring frameworks: 11%

No comment provided: 37%

Ultimate Accountability for Cybersecurity

When asked who within the organisation bears ultimate accountability for cybersecurity, the most common response was a CIO, CDO, or equivalent IT executive (31%), followed by a director or executive officer serving in a concurrent capacity (29%). Together, these two categories account for approximately 60% of companies where ultimate cybersecurity accountability rests with either the IT function or a member of management in a concurrent role — suggesting that questions of expertise remain. A further 17% of companies indicated that the President and CEO bears direct responsibility, reflecting a meaningful number of cases where the top executive is at the forefront.

Only 9% of companies have a dedicated Chief Information Security Officer (CISO) in a full-time role. Among Fortune 500 companies, virtually all had appointed a dedicated CISO by 2022, with some 40% having since created a Deputy CISO position to deepen organisational capability. By comparison, the prevalence of concurrent roles held by IT executives or the CEO at Japanese companies highlights the challenge of securing dedicated management-level expertise in cybersecurity.

A small but notable proportion of companies identified a divisional general manager as the ultimate accountable party (11%), and 2% indicated that accountability was "undecided" — suggesting that responsibility structures remain in flux at some organisations.

Q3. Please indicate the title of the individual who bears ultimate accountability for cybersecurity.

CIO / CDO or equivalent IT executive: 31%

Director / Executive Officer (concurrent): 29%

President and CEO: 17%

Divisional General Manager: 11%

Dedicated CISO: 9%

Undecided / Unknown: 3%

Scope of Monitoring

Regarding the scope of cybersecurity monitoring, 66% of companies — the largest proportion — indicated that their monitoring covers the entire group, suggesting a reasonable baseline from a group governance perspective. However, a substantial 51% of respondents indicated coverage limited to the listed parent company only, confirming that a meaningful number of companies have limited capacity to address breach risks originating through subsidiaries or affiliates.

Only 17% of companies have extended their monitoring scope to include business partners and suppliers. Recent cyber attacks have increasingly targeted the weak points of supply chains rather than internal systems. Under the NIST Cybersecurity Framework and ISO certification standards (ISO 27001), third-party risk management is recognised as a critical requirement — and the strengthening of monitoring frameworks across the entire supply chain, including business partners, remains an important challenge going forward.

Q4. What is the current scope of your cybersecurity monitoring? (Multiple responses permitted)

Group companies (all): 66%

Listed parent company: 51%

Group companies (selected): 26%

Business partners (selected): 17%

Business partners (all): 0%

No response: 6%

Summary

The above presents the findings of our survey on cybersecurity governance frameworks, conducted among listed companies between January and March 2026.

The survey confirmed management-level involvement in cybersecurity at 91% of companies, indicating that the foundations of governance have been established to a meaningful degree. At the same time, with dedicated CISOs in place at only 9% of companies and only 14% having extended monitoring to cover the supply chain, there remains significant room for improvement in the transition from "formal involvement" to "effective risk management."

As the advancement of AI makes the sophistication and automation of cyber attacks an increasingly tangible reality, gaps in these frameworks represent a risk that can directly affect corporate value. Cadira will continue to engage with its portfolio companies through dialogue, working to improve the effectiveness of cybersecurity governance.

*1 Cybersecurity Management Guidelines and Support Tools: https://www.meti.go.jp/policy/netsecurity/mng_guide.html

*2 Cybersecurity Measures in the Financial Sector: https://www.fsa.go.jp/policy/cybersecurity/index.html

Learn More

2026/7/16

Turning Social Challenges into Growth — Optex Group's Competitiveness and Value Creation Through Engagement

We introduce Optex Group (6914), including a company overview and Cadira's ongoing engagement activi...

2026/6/23

Turning Environmental Value into Growth- Daiseki’s Circular Business Model and the Source of Its Competitive Advantage

We spotlight Daiseki Co., Ltd. — providing an overview of the company and an account of Cadira's eng...

2026/5/21

 The Essence of Quality-Oriented Management – ​​Insights into Long-Term Value from a Dialogue with Sysmex

This month, we spotlight Sysmex Corporation (6869) — providing an overview of the company and the on...

2026/5/14

Survey on Cybersecurity Governance Systems (2026Q1)

In recent years, the cybersecurity risks facing companies have entered a new phase. In April 2026, U...

2026/4/24

A Growth Model Built in the Infectious Disease FieldーShionogi & Co.'s Strategic Transformation and Value Creation

This month, we will dive into Shionogi & Co., Ltd. (4507), focusing on its corporate profile and...

2026/3/19

A Growth Model Born from Social Issues – Park24's Value Creation and Investment Perspective

This month, we will dive into Park24 Co., Ltd. (4666), focusing on its corporate profile and Cadira'...

2026/2/20

Deepening Sustainability Dialogue — Survey Findings Highlight Qualitative Shifts in IR

Survey OverviewCadira Capital Management conducts a sustainability-related survey following IR meeti...

2026/2/20

Diversity Driving Japan’s Vision as an Asset Management Nation — Cadira’s Role in Partnership with IMC

The Independent Managers Club (IMC) is a research and advocacy organization launched in October 2023...

2026/1/26

The Educational Foundation for Human Capital - A Dialogue Between Insource and Cadira

This month, we will dive into Insource Co., Ltd. (6200), focusing on its corporate profile and Cadir...

2025/12/12

Supporting Social Stability Through Technological Advancement — Our Dialogue with Macnica Holdings

This month, we introduce Macnica Holdings, Inc. (3132), covering its corporate profile and our engag...

2025/11/28

AI-Related Corporate Survey: Internal Training and Policy Status at 34 Listed Companies

At Cadira Capital Management, we conduct surveys after IR meetings with listed companies, focusing o...

2025/10/24

TDK’s Timeless Evolution: Corporate Culture and Value Creation Revealed Through Our Dialogue 

(Center: CIO Yu Shimizu, at TDK Internal Event)For nearly 90 years since its founding, TDK has conti...

2025/9/26

Collaborative Dialogue Supporting Sustainability Strategy — The Case of Kokuyo

Cadira supports the sustainable, long-term growth of its portfolio companies through collaborative d...

2025/8/29

Evolving IR Practices in Japan: Insights from Cadira’s Q2 2025 Survey

At Cadira Capital Management, we conduct ongoing surveys with listed companies following our IR meet...

2025/8/22

Report on Our Annual Conference (July 3, 2025)

On July 3, 2025, Cadira Capital Management hosted its annual conference to reflect on activities dur...

2025/7/18

Mitigation and Adaptation in Action: Why Weathernews Inc. Stands Out

At Cadira Capital Management, we believe companies that integrate environmental impact with business...

2025/6/20

From Disclosure to Dialogue: What We Learned from Publishing Our Progress Report 2024

Since the publication of our inaugural Progress Report 2024 in March, we have held discussions ...

2025/5/22

Building on Three Pillars — How Sekisui House Integrates Innovation, Sustainability, and Global Expansion

At Cadira, we place importance not only on regular IR meetings but also on engaging directly with co...

2025/5/22

Aligning Incentives for Sustainable Growth — Results from Our Survey on Equity-Based Compensation

At Cadira Capital Management, our investment management team conducts post-IR meeting surveys with t...

2025/5/15

Engagement as a Catalyst for Corporate Renewal — Insights from KDDI

Cadira has maintained an ongoing dialogue with KDDI Corporation (hereinafter “KDDI”). Our CIO, Mr. S...

2025/4/25

Bridging the Gap in Sustainability Dialogue for Smaller Companies — The Case of Econavista

Cadira Capital Management engages in constructive and neutral dialogue on the identification of corp...

2025/4/23

EMP Roundtable: The Current Status and Potential of EMP in Cultivating the Next Generation of Asset Managers (Part 2)

Participants:Mr. Hiroyuki Nomura, Operating Officer, Senior General Manager, Investment Planning Dep...

2025/4/23

EMP Roundtable: The Current Status and Potential of EMP in Cultivating the Next Generation of Japanese Asset Managers (Part 1)

Participants:Mr. Hiroyuki Nomura, Operating Officer, Senior General Manager, Investment Planning Dep...

2025/4/11

Redefining Work: Timee’s Social Impact in Japan’s Labor Market

Cadira engages in deep dialogue with Timee, Inc. (hereinafter "Timee"), placing a strong emphasis on...

2025/3/14

Lecture on Impact Integration Methods in Listed Equity Investments

At Cadira Capital Management, we actively share our investment approach to foster greater impact ori...

2025/2/21

From Umami to Impact: How Ajinomoto Aligns Growth with Global Sustainability Goals

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2025/2/14

Strengthening Human Capital: Insights from Cadira’s Investor–Company Dialogue

Cadira’s investment team conducts post-meeting surveys following IR meetings.These surveys include q...

2025/1/23

Sysmex: Advancing Global Healthcare Through Innovation and Engagement

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/12/13

Leadership Renewal and the Path to Sustainable Value at Optex Group

Optex Group is a manufacturer of sensors for indoor and outdoor security, automatic doors, and indus...

2024/11/29

Connecting the Investment Chain: Market Dialogue with Marui Group and Katitas

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/10/25

IR Survey Results 2024Q3: Rising Wages and the Business Case for Social Impact

We conduct a survey for respondents following IR meetings. The survey covers impressions of the meet...

2024/10/25

Our Activities in September 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/9/24

Our Activities in August 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/8/23

Our Activities in July 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/7/26

IR Survey Results 2024Q2: SSBJ Sector Classifications and the Evolving Role of Sustainability in Corporate Strategy

We conduct a survey for respondents following IR meetings. The survey covers impressions of the meet...

2024/7/19

Our Activities in June 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/6/21

Our Activities in May 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/5/24

Our Activities in April 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/4/26

IR Survey Results 2024Q1: How Japanese Companies Are Measuring Their Impact

Cadira's investment management team conducts a survey of respondents following IR meetings. In addit...

2024/4/19

Our Activities in March 2024

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/3/29

Our Comments to the "Capital Markets Disclosure and Dialogue Guidance for Impact Companies

The Japan National Advisory Board of the Global Steering Group for Impact Investment (GSG-NAB Japan)...

2024/3/15

"Make Home the Happiest Place in the World" — Sekisui House’s Landmark Acquisition and Cadira’s Perspective

On January 18, Sekisui House announced the acquisition of M.D.C. Holdings ("MDC"), a leading U.S. ho...

2024/3/15

Engagement Supporting Brand Renewal and Business Transformation — The Case of Kanadevia (formally Hitachi Zosen)

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/2/23

Survey Result from Our Investor Relations Meetings (2023Q4)

At Cadira Capital Management, we ask our contacts to fill out a survey after each Investor Relations...

2024/2/16

From Revitalizing Vacant Homes to Creating Social Impact — Engagement with KATITAS

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2024/1/12

Our Activities in December 2023

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2023/12/15

Our Activities in November 2023

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2023/11/10

Our  Activities in October 2023

At Cadira Capital Management, our mission is "Connecting the Investment Chain and Beyond". Collabora...

2023/10/27

Survey Result from Our Investor Relations Meetings (2023Q3)

At Cadira Capital Management, we ask our contacts to fill out a survey after each Investor Relations...

2023/10/23

Our Comments to the “Draft Basic Guidelines on Impact Investment” by the Financial Services Agency of Japan

On June 30, 2023, the Financial Services Agency of Japan released the "Draft Basic Guidelines on Imp...

List

Important Notice

The content of this website has been prepared by Cadira Capital Management Co., Ltd. (“CCM”) for informational purposes only to professional investors who are expected to make their own investment decisions without undue reliance on such content. The views and strategies described may not be suitable for all investors. Under no circumstances is it to be used or considered as legal or investment advice, a recommendation to buy, an offer to sell, or a solicitation of an offer to buy or sell securities and investors should be advised to consult their own stockbroker, accountant, solicitor, independent financial adviser, or other professional adviser for advice. We accept no liability whatsoever for any direct or consequential loss arising from any use of this content. The information is intended solely to report on investment strategies and opportunities identified by CCM. Opinions and estimates offered constitute our judgment and are subject to change without notice, as are statements of financial market trends, which are based on current market conditions. CCM and its affiliates do not warrant the accuracy or completeness of any of the information or data contained herein. References to specific securities and their issuers are for illustrative purpose only and are not intended to be, and should not be interpreted as investment advice or, a recommendation, offer or solicitation for the purpose or sale of any financial investment. This content does not constitute tax advice and as such investors should be advised to consult their own tax advisers regarding the tax consequences of their investment activities. Investment return and principal will fluctuate, so that a client's initial investment may increase or decrease. Investing in securities markets involve risks like those arising from stock and bond markets, currency exchanges rate and interest rate volatility. No part of this content may, without CCM prior written consent, be copied, reproduced, or published by any recipient for any purpose. Past performance is not indicative of future performance.