
Glory strives to avoid operational risks and mitigate losses in times of disasters, ensuring the safety of stakeholder positions.
Glory's Risk Management Committee, chaired by the company's president, works to strengthen the Group's risk management based on the risk management framework and process shown below.
In fiscal 2025, the Risk Management Committee established measures to address the most significant risks and implemented various risk management activities. In addition, Group companies were requested to assess risks using a common risk assessment methodology and to develop and implement risk mitigation measures. Through these efforts, we worked to identify and reduce risks across the Group.
The Risk Management Committee manages the Group's risk management framework and is chaired by the company's president.


The Group manages risk through a PDCA-based framework that supports the identification, assessment and response. Risks are assessed based on their potential impact and likelihood, and managed through one of four approaches: avoidance, mitigation, transfer, and acceptance. For material risks, responsible departments implement preventive actions and work to establish and enhance frameworks to ensure a swift and effective response in the event of a crisis. The Risk Management Committee reviews and approves Glory’s risk management framework, including its basic policies, governance structures, annual priorities, and implementation progress. Key matters are reported regularly to the Board of Directors.
In January 2026, the Risk Management Committee identified the most critical risks and approved mitigations strategies and related initiatives outlined below.

Glory enhances its BCP to maintain critical operations and rapid recovery in the event of a natural disaster or other emergencies. To support the stable delivery of products and services, we strengthen supply chain resilience through measures such as diversifying procurement sources and enhancing disaster response readiness through established procedures and manuals.
These efforts include BCP drills in the manufacturing division based on disaster scenarios, as well as regular reviews of response manuals and guidelines by the sales and maintenance divisions.
Glory handles a large volume of confidential information concerning matters such as cash processing and settlement processing. Accordingly, we focus on the integrated strengthening of our information security throughout the Group based on the Information Security Basic Policy and Privacy Policy, which stipulate our basic stance and attitude as a Group.
Under the supervision of the Chief Information Security Officer (Group CISO), we have established the Information Security Promotion Section as a company-wide cross-sectional organization to improve the level of information security for the entire Group. The section has been making continuous improvements through the PDCA cycle based on the Information Security Policy. Internal audits are also conducted regularly to check the suitability and effectiveness of the system. In addition, as a measure to strengthen security not only for the Group but also for the entire supply chain, we conduct security surveys of contractors who handle important information to ascertain their security levels and provide guidance on improvements as necessary.
For the purpose of safely and appropriately handling the information assets of our customers, departments concerned with offering systems solutions and services, such as the Service Connect Center (Information processing center), have acquired ISO 27001 certification, the international standard for information security.
| GLORY LTD. | Service Connect Center, System Development Division, Glory Monitoring Center, DX Innovation Development Department |
|---|---|
| Domestic group companies | GLORY Technical Solutions Ltd. SC Business Division (Former GLORY System Create Ltd.), GLORY NASCA Ltd. |
| Overseas group companies | Sitrade Italia S.p.A. |
We strengthen information security through ID management systems and intrusion prevention systems that prevent unauthorized entries via the internet or limit the use of external storage through device control. In addition, we implement two-factor authentication for data integration platforms to prevent unauthorized use by third parties.
For remote workers, we provide VPN (Virtual Private Network) connections to ensure network security and prevent the leakage of confidential information. Additionally, we enhance endpoint security through vulnerability management, anti-virus software, MDM (Mobile Device Management System), and EDR (Endpoint Detection and Response) solutions.
We have introduced an entrance and exit management system with ID cards or facial recognition along with a key management system to strictly control access and automatically save records.
We also ensure the continuous operation of the IT infrastructure by installing equipment such as private power generators and a UPS (uninterruptible power system).
We respond to constantly changing technologies and social circumstances and conduct level-based employee training to prevent information security breaches.
Our training includes programs for new employees to provide them with a basic knowledge of information security and relevant laws and regulations and training on supervisor responsibilities for information security so management can acquire the knowledge they need. We also conduct training programs for managementlevel personnel to deepen understanding of social trends (external environment) and our status (internal environment) related to information security.
We also conduct an annual, group-wide e-learning program in October during Corporate Ethics Month to strengthen the information security literacy of employees. Due to the increased the risk of information leaks from telework, we provide employees with training on risk prevention compliance.
In preparation for information security incidents such as data leaks, malware infection, and unauthorized access, we have established a system for minimizing damage, promptly recovering and preventing reoccurrence. G-CSIRT (Glory Computer Security Incident Response Team), which plays a central role in this effort, joined Nippon CSIRT Association, an industry group, in 2014 and has been enhancing response capabilities to incidents through such initiatives as gathering and sharing information and acquiring related skills. The system is being further strengthened to enhance the response to incidents in products, services and at offices.