Business

Employee Interview #4
Cyber Security

To protect clients, the company, and employees from cyberattacks and maintain a secure digital environment, Nomura is strengthening its cybersecurity systems globally. Our Group Chief Information Security Officer (CISO) explains what initiatives are being implemented.

Summary

  • Cyberattacks are becoming more sophisticated such as via information theft and system damage
  • Nomura is strengthening is cybersecurity at a global level
  • Many attack vectors involve human error, so every employee must remain diligent

Q. Please tell us about recent cyberattacks.
A. Cyberattacks target digital environments such as the internet and computer networks. They involve theft of confidential information, destruction of systems, and theft of users' personal information, and cause harm to organizations and individuals.
These attacks are becoming more sophisticated with the use of advanced technologies like AI. Threats have increased due to geopolitical tensions, and we are seeing a rise in cyberattacks that cross national borders.

Q. How is Nomura responding to such threats?
A. Nomura provides fund transfer services and handles sensitive information that makes the firm susceptible to cyberattacks.
Our security teams deal with daily impersonation attempts targeting Nomura, which require us to conduct investigations in collaboration with various online platforms.

Q. What measures are being taken to enhance Nomura's cybersecurity defenses?
A. We have recently updated our name to Information Security to broaden and align our security services on a global scale. At Nomura, cybersecurity is a subset of Information Security. Cybersecurity relates to safeguarding data in cyber space whereas Information Security includes not only technologies but also policies, processes, people, and physical assets—it is a more holistic, business-centric approach to safeguarding our firm's assets.
My goal is for Nomura's Information Security team to deliver high-value expertise, enabling the business to embrace cutting-edge technologies and offer our clients top-notch services within a secure framework. This necessitates enhancing our ethical hacking skills, simulating cyberattacks to test our defenses, and detecting new cyber threats in real time.
As we develop our strategy, we will build a proactive cybersecurity defense strategy to defend against attacks on a global scale.
In Japan, we will be establishing a Security Center of Excellence to provide all security services to the business, our clients, and partners.

Q. What can employees do to guard against cyberattacks?
A. Simply strengthening our cybersecurity defenses and having experienced security teams is not sufficient to address all cyberattacks. Most attacks originate from human error or manipulation. It is crucial for each employee to recognize this and be vigilant in their daily tasks. This helps protect the firm, our clients, and employees.