JAC Group has identified Organisational Resilience as a materiality issue that underpins our value creation. We are committed to establishing and operating a framework that promotes risk management in an organised and continuous manner across the Group.
JAC Group has positioned risk management as a vital initiative for enhancing corporate value and has put in place a risk management system centred on the JAC Group Risk Management Committee. The Committee monitors and reviews risks that could seriously impact management in accordance with the below framework.
The status of risk management is reported to the Board of Directors twice a year. With respect to FY2025, the Risk Management Committee reported on the various risk measures undertaken and the results at the Board of Directors meeting held on 12 February 2026.
As the use of digital technologies expands and cyberattacks become increasingly sophisticated, the appropriate protection of information held by companies has become an important management issue that is essential for business continuity and the maintenance and enhancement of corporate value. Through its recruitment business, JAC Group handles important information, including personal information and confidential information entrusted to the Group by corporate clients and candidates. The Group is committed to ensuring the confidentiality, integrity, and availability of information, while working to ensure its proper management and protection. The Group also strives to build trust with corporate clients and candidates by providing accurate and appropriate information and providing services with integrity that respect the rights and interests of both parties. In handling information, the Group places importance on maintaining its accuracy and reliability and manages information appropriately to prevent misunderstandings or disadvantages from arising.Under its Information Security Policy, the Group promotes the development of organisational structures, the operation of internal rules and procedures, employee education and training, the management of outsourced service providers, incident response, and continuous improvement. Through these efforts, the Group is committed to safe and secure business operations that earn and maintain the trust of stakeholders.
|
Issues |
Countermeasures |
Main measures |
|
Unauthorised external access, delays in countermeasures, and risks to business continuity |
Employee training |
Ongoing implementation of information security e-Learning for all employees |
|
Risk assessment |
Ongoing implementation of “targeted attack email training” |
|
|
Strengthening emergency response and BCP measures |
Annual vulnerability assessments |
1. Compliance with laws and regulations related to information security
2. Organisational structure to ensure information security
3. Establishment of rules and regulations concerning information security management
4. Implementation of education and training for ”related parties” concerned in handling important information assets
5. Information security measures for outsourcing contractors
6. Response to information security incidents
7. Periodic evaluation and continuous improvement
JAC Group recognises large-scale natural disasters, including a major earthquake directly beneath the Tokyo metropolitan area and a Nankai Trough earthquake, as significant business risks that could have a material impact on its operations. Ensuring the health and safety of employees, their families, corporate clients, and candidates is the Group’s top priority. To this end, the Group has established systems and procedures to ensure a swift and appropriate response in the event of a disaster while ensuring business continuity. The Group has developed disaster response manuals and disaster response procedures and has implemented an employee safety confirmation system. The Group also works to geographically diversify the management of its business assets and maintains the information systems necessary to support a transition to remote working when required.
In addition, the Group continuously conducts disaster preparedness e-learning programmes, company-wide disaster drills, and safety confirmation exercises to enhance employees’ awareness of disaster preparedness and strengthen emergency response capabilities. Furthermore, to minimise the impact of major disasters, including earthquakes, on business continuity, the Group continues to develop and review its Business Continuity Plan (BCP). By implementing continuous improvements based on training outcomes and risk assessments, the Group is working to strengthen organisational resilience.