IT / AI / Cyber Security
IT and Digital Strategy
Amid the rapid changes in the environment surrounding companies, technological advancements continue to give rise to new businesses and services. As a result, IT and digital have become indispensable elements that are closely linked to management strategy. At our Group, we have developed and are advancing an IT and digital strategy that is aligned with the Group's management strategy, aiming to accurately respond to these changes and achieve both sustainable growth and business model transformation.
IT Governance
As IT and digital continue to have growing impact on management strategy, our Group places strong emphasis on IT governance under the leadership of senior management. By appropriately controlling the use of IT, we aim to maximize the value it brings to our business while minimizing associated risks – ultimately contributing to enhanced corporate value.
Specifically, to stably support the Group's global management and realize sustainable value provision to customers around the world, we have established the “Group IT Governance Basic Policy” and are promoting the development of an IT governance structure – encompassing rules, personnel, and organizational readiness – based on COBIT*, an internationally recognized standard. In addition, we also hold regular meetings with IT leaders from Group companies both in Japan and overseas to share our IT and digital strategies and accelerate collaboration across the Group. Through these efforts, we strive to build IT and digital capabilities that drive Group-wide synergies and contribute to enhancing overall corporate value.
At the same time, we are thoroughly managing the risk of “system risk” – which includes system outages, malfunctions, or unauthorized use that could damage customer trust, disrupt operations, or result in financial loss. In accordance with the “Group System Risk Management Policy”, each Group company is required to establish policies, operational frameworks, and processes for managing system risk, and to continually evaluate and improve their effectiveness.
To address risks associated with the utilization of AI, we identify and assess risks according to the specific use cases and environments in which AI is deployed. By implementing appropriate controls, we promote initiatives that enhance the safe and reliable use of AI. These efforts are designed to improve customer convenience and operational efficiency, thereby advancing the responsible and effective utilization of AI technologies.
- *COBIT: A global standard framework for IT governance that is advocated by the Information Systems Audit and Control Association and the IT Governance Institute of the United States.
AI Governance
To realize the Daiichi Life Group's purpose, “Partnering with you to build a brighter and more secure future,” and to ensure an appropriate balance between promoting innovation through the use of AI and effective risk management, the Group has established the AI Governance Policy for the Daiichi Life Group (hereinafter referred to as the “Policy”). The Policy is approved by the Board of Directors, reviewed annually, and revised as appropriate in response to environmental changes, including developments in laws and regulations and advances in technology. Based on this Policy, the Group promotes all AI-Related Activities, including AI Development, Provision and Use, in compliance with the Daiichi Life Group Code of Conduct.
In conducting AI-Related Activities, the Group places particular importance on the following guiding principles.
- Human-Centric: Respect human dignity and individual autonomy.
- Safety: Take into account impacts on life, body, property, mind, and the environment.
- Fairness: Eliminate unfair bias and discrimination and appropriately address unavoidable biases.
- Privacy Protection and Appropriate Information Handling: Ensure information is used in accordance with applicable laws, regulations, and other requirements.
- Security and Robustness: Ensure secure and sustainable operation of AI systems.
- Transparency and Accountability: Ensure verifiability of AI-supported decisions and clarify responsibilities.
- Improving AI Literacy and Innovation: Promote value creation through talent development, education, reskilling, and knowledge sharing.
Furthermore, based on these guiding principles, the Group emphasizes the following approaches in implementing AI-Related Activities.
- Customer First: Always place the impact on customers and other stakeholders as the highest priority.
- Role-based Approach: Clearly define responsibilities according to the roles of relevant parties, such as developers and users, and ensure appropriate actions are taken.
- Risk-based Approach: Respond according to the level of risk, considering both the magnitude of potential impact and the likelihood of occurrence.
- Overall Optimization: Make decisions from the perspective of Group-wide optimization, taking into account objectives, costs, and other relevant factors.
- Agile Governance: Maintain a continuous and rapid cycle of analysis, design, implementation, and evaluation to adapt to evolving technologies and social environments.
Under these guiding principles and approaches, the Group will maximize the benefits of AI while promoting safe and responsible AI governance across the Group, led by the IT and Digital Unit. Through these efforts, we aim to create sustainable value and contribute to society.
Cyber Security Measures
Our Group has established the position of Chief Information Security Officer (CISO) to oversee information security initiatives across the Group. In order to protect information assets throughout the Group from increasingly sophisticated cyber threats and to continuously deliver security, safety, and reliability to customers and other stakeholders, we strive for ongoing enhancement across the areas of people, processes, and technology. Under this policy, we have established “Cybersecurity Policy for Daiichi Life Group”, which sets out specific requirements necessary for the development and maintenance of cybersecurity frameworks and is shared throughout the Group.
From a systems perspective, we continuously strengthen our capabilities to address emerging cyber threats through initiatives such as implementing defense-in-depth measures that combine multiple layers of detection and protection against unauthorized access, malware, and other cyber risks. In addition, through collaboration with external organizations, we collect, analyze, and utilize cybersecurity intelligence and work to optimize cybersecurity measures across the entire Group, including overseas life insurance subsidiaries. Furthermore, we conduct vulnerability assessments to identify system vulnerabilities and evaluate the possibility of exploitation. Based on the results, Group companies conduct penetration testing, and the implementation status is monitored on an ongoing basis.
To strengthen incident response capabilities, we have established the Group Cyber Incident Response Rules, which define our response framework in the event of a cybersecurity incident. Through system monitoring and the utilization of threat intelligence, we strive to detect suspicious activities and potential indicators of information leakage at an early stage. Based on these detection results and information received from external parties, our Computer Security Incident Response Team (CSIRT), consisting primarily of dedicated personnel with advanced technical expertise, conducts impact assessments and incident classification. The CSIRT then coordinates with relevant departments and Group companies to oversee containment measures, investigation and analysis, and recovery activities aimed at minimizing the impact of incidents. Following an incident, root cause analyses are conducted, and lessons learned are incorporated into measures to prevent recurrence, thereby enhancing cyber resilience across the Group. We also maintain incident response procedures and regularly conduct drills and exercises to improve the effectiveness of our response framework.
We continuously provide cybersecurity education and training programs for all employees, including e-learning courses and phishing simulation exercises, to enhance understanding of their roles and responsibilities regarding information security. In addition, we conduct cybersecurity exercises and simulations for directors, officers, and employees to improve the effectiveness of our response processes.
Employees are required to promptly report incidents, suspicious activities, suspicious emails, or other cybersecurity-related concerns to the cybersecurity function in accordance with established procedures. Reporting and escalation processes have been formally defined and implemented across the organization.
The Group considers the appropriate management of information security risks throughout the supply chain to be a key priority. Information security requirements have been established for suppliers and other third parties, with compliance assessed through vendor due diligence and contract management processes when entering into new contracts or making significant changes to existing arrangements.
These requirements include the proper management of personal information and confidential information in accordance with applicable laws and regulations, as well as the implementation of cybersecurity measures. Through these initiatives, we seek to reduce information security risks across the supply chain.
In addition, the Group continuously evaluates and enhances the effectiveness of its cybersecurity posture with reference to external frameworks such as the NIST Cybersecurity Framework, as well as guidelines issued by the Financial Services Agency of Japan (FSA). In response to changes in the technological landscape, including the emergence of Frontier AI, the Group strengthens cybersecurity and resilience through ongoing monitoring of Group companies' preparedness and the provision of support and guidance. Furthermore, independent third-party assessments of cybersecurity governance, management frameworks, and technical controls are conducted annually for major Group companies. Based on the findings identified through these assessments, improvement plans are developed and their progress is continuously monitored to further strengthen the Group's cybersecurity posture.
The Internal Audit Unit conducts risk-based internal audits based on annual risk assessments and evaluates both the effectiveness of cybersecurity governance frameworks and the status of cybersecurity improvement initiatives across the Group and its subsidiaries. Audit results are reported to senior management, and where areas requiring improvement are identified, corrective actions are requested from the audited organizations and the implementation status is subsequently monitored. In recognition of the growing importance of cybersecurity risk, the Group has conducted internal audits focused on cybersecurity every year since fiscal year 2020.
