Skip to main content

Information Security

Policy

The Anritsu Group recognizes that it has a social responsibility to properly protect the information of all stakeholders in the course of its business activities and that such information is an important asset. Based on this idea, we have established a Basic Policy for Information Management, and we are striving to maintain and improve security.

Basic Rules of Information Management

The Anritsu Group ("Anritsu") recognizes its social responsibility for effectively protecting information related to all of its stakeholders, including customers, shareholders/investors, business partners and employees, throughout the course of its business operations, which offer "Original and High Level" products and services with sincerity, harmony and enthusiasm. Moreover, we view information as a vital asset for Anritsu and all its stakeholders. Therefore, Anritsu has established these Basic Rules of Information Management and declares it will responsibly handle information assets and take all possible actions to ensure their protection.

  1. Anritsu shall comply with the laws and social norms governing information assets and information management.
  2. Anritsu shall build information management systems and strive to effectively manage information assets.
  3. Anritsu shall develop and implement corporate regulations that define concrete procedures and rules of information management.
  4. Anritsu shall provide its officers, employees and others with the necessary education and training to deepen their knowledge of information management.
  5. Anritsu shall implement appropriate human, organizational, physical and technical measures to protect information assets.
  6. Anritsu shall quickly respond to risks associated with protecting information assets to minimize damage.
  7. Anritsu shall regularly and continually review and improve the information management activities noted above.

System

The Anritsu Group has established an information security management executive officer and the Information Management Committee as a system to ensure thorough information management within the Anritsu Group and to prevent information security incidents before they occur.

The information security management executive officer is appointed by the director in charge of the Information System Management Department, and the Information Management Committee consists of the directors in charge of each business division and group company.

In the domestic group, the Information Security Subcommittee, consisting of representatives from domestic groups, establishes policies, implements measures, provides employee training, and takes countermeasures and shares information when incidents occur. In overseas group companies, the Global IT Strategy Center, whose members are IT managers from regional headquarters, has been established to strengthen IT controls, including security. A comprehensive audit of the actual status of information management is conducted by the Information Management Committee, and the results are reported to the information security management executive officer.

Information Security System

ISO27001 Certification Status

  • Japan: DX Promotion Department
  • EMEA: Anritsu A/S Service Assurance Business Unit

Activities and Achievements

Promoting Information Security

 

■Introduction of a New Security System

Security risks in corporate supply chains are a critical issue. In recent years, as cybersecurity threats have increased, companies are being called upon to strengthen countermeasures throughout their entire supply chains. In response to customer requests for enhanced security, the Anritsu Group implemented a 24/7 monitoring system in FY2024 as part of its security reinforcement measures. This new system enables the early detection of security incidents and allows for swift response.

 

■Employee Training

To raise awareness of security, the Anritsu Group conducts security training through e-learning once a year for directors and all employees (regular, contract, part-time, and temporary employees) of Anritsu Group companies in Japan and overseas. We also conduct training with email that simulates an actual attack every two to three months.

 

■BCP Training

In FY2024, following on from FY2023, we conducted BCP drills to confirm that core operations could be performed solely using backup systems, and confirmed that this could be executed without issue. Additionally, in response to the transition to the latest standard "ISO/IEC 27001:2022" and the formalization of the risk of prolonged business disruption due to cyberattacks within its requirements (5.30 ICT preparedness for business continuity), we have revised our internal regulations. In addition to conventional disaster response drills, we added training that simulates a ransomware infection to confirm that internal and external communications and recovery operations based on the procedure manual could be properly executed.

 

■Initiatives Regarding the Use of Generative AI

Anritsu requires that employees of the domestic group, temporary staff, and employees of partner companies use only generative AI systems approved by the Information Systems Department when utilizing generative AI technology. When using the system, we adhere to guidelines (internal regulations) that clearly stipulate prohibitions on inputting certain information and the need to verify copyrights and trademarks, thereby preventing risks such as information leaks and intellectual property infringements before they occur.

 

Measures to Prevent Recurrence of Incidents

In response to security incidents occurring at overseas group companies in FY2023, we introduced multi-factor authentication as a measure to prevent recurrence. Subsequently, to prevent similar risks from occurring, we expanded multi-factor authentication across the entire group, both domestically and internationally. As a result, no similar incidents occurred either domestically or internationally in FY2024.

On the other hand, in FY2024, there were six incidents of mistaken email transmissions that led to the leakage of personal information. To prevent recurrence, we have strengthened employee training, thoroughly enforced rules for verifying recipients before sending e-mails, and established a rapid response system in the event of a misdirected e-mail.

United States