Strike Co., Ltd.

Information Security

Basic policy on information security

At Strike Co., Ltd., our purpose, “Realizing people’s aspirations through M&A,” drives us to support companies and contribute broadly to society through our M&A advisory and brokerage services. We understand that ensuring information security is crucial for conducting business activities smoothly and efficiently. To protect our information assets, we have established the Information Security Policy, which we implement and promote as follows:

Information Security Policy

Basic policy on personal information protection

At Strike Co., Ltd., we understand the importance of personal information and recognize our social responsibility to protect it. We are committed to complying with all relevant laws, regulations, and internal policies to properly acquire, use, and manage the personal information we handle.

Privacy Policy

Information security system

A security team has been established within the Information Systems Department. The security team regularly audits the Company’s security status and formulates improvement measures as necessary to reduce information security risks.

For example, the team monitors employee access logs, and if any unusual activity is detected, they investigate it in detail. They also conduct external risk assessments to inform and enhance security measures.

In addition, the security team is responsible for incident response, working 365 days a year to address risks such as employees losing their devices.

Information security measures

In March 2024, we obtained ISO 27001 certification, the international standard for information security management systems, to provide our customers with ever greater peace of mind and trust.

In addition, information security training is conducted once a quarter for all employees by an outside instructor. A verification test is conducted at every training session to enhance security awareness.

Email security training for employees was conducted twice during the fiscal year ended September 30, 2023, to prevent virus infections from email attacks and information leaks. The results showed an open rate of 40% for the first session and less than 10% for the second, demonstrating the program’s effectiveness.