Information Security
Epson's Principles of Corporate Behavior states, "We protect the security of people and company assets, and we exercise strict care in the management of all information." In line with this principle, Epson rigorously manages all information, respects the information assets of others, and works to strictly control personal data and confidential information to prevent information leaks. We recognize the importance of information security and have established practices that all employees can use to protect information.
Policies
The Epson Group Basic Information Security Policy sets forth the basic principles and rules regarding information security. We are strengthening our information security governance and fostering a security-conscious corporate culture by making sure that everyone in the Epson Group understands the importance of information security and safeguards sensitive information in their work.
Epson researches, develops, and uses AI in its operations and is promoting the responsible use of AI throughout the Group under the Epson Group AI Ethical Principles, which provides fundamental rules that should be upheld to ensure a human-centered society where people and AI coexist.
Organization
Under the Chief Information Security Officer (Group CISO), Epson’s business units establish and operate their own information security systems in accordance with Group-wide regulations. They also conduct internal assessments to continuously evaluate the effectiveness of their controls and the functionality of their risk management.
In response to the increasing severity of cyberattacks, the tightening of regulations and laws in various countries, the emergence of risks related to products and services, and the increasing sophistication of demands for security disclosures, Epson established the Information Security Management Center in FY2026 as the core organization of an expanded information security framework. The establishment of this center is accelerating the strengthening of a consistent global security system and efforts to communicate information to stakeholders.
With regard to AI, we have established an AI Ethics Committee in FY2023 to gather and analyze information on trends surrounding AI, make policy decisions, and respond to AI-related laws, regulations, and policies in various countries and regions. The committee is composed of members from technology development, quality control, legal, and administrative departments, and is working to build and properly implement a Group-wide AI governance system.
We have also appointed an AI Ethics Officer in each department to raise awareness of AI ethics, provide education, and assess the risks of AI utilization projects. We have also appointed AI Ethics Officers in our overseas affiliates and are building a global AI governance system by establishing AI standards in each company, reviewing and assessing the risks of AI system utilization projects, and providing employee training.
Initiatives
Cybersecurity
Cyberattacks are becoming more sophisticated by the day and are a major risks for companies. In addition to the Cybersecurity Management Guidelines of the Ministry of Economy, Trade and Industry, Epson refers to the Cybersecurity Framework (CSF) of the U.S. National Institute of Standards and Technology (NIST) to formulate strategic plans for strengthening countermeasures across the entire Epson Group.
Program
We implement programs in line with the Epson Group Basic Information Security Policy. The programs are designed to do the following:
- Ensure compliance by keeping track of international trends in laws, regulations, and guidelines and by updating our internal systems accordingly.
- Educate, train, and raise awareness among company officers and employees.
- Risk assessment
Security Monitoring and Response Organization
Epson has organized a global Computer Security Incident Response Team (CSIRT) to monitor security 24/7 and quickly respond to alerts about malware, including ransomware. The CSIRT also conducts incident response drills and reviews response procedures.
Factory Security
To reduce the risk of manufacturing disruptions due to security incidents, we have established factory security procedures and are implementing measures based on these procedures. We prioritize the measures through regular internal and external assessments and implement them according to a plan.
Supplier Security
We assess the information security of suppliers as part of our supplier management program. This is done both before initiating business with a new supplier and through annual evaluations. If a supplier's information security does not meet our criteria, we ask the supplier to address the issues and provide support as needed.
Product Security
As IT becomes increasingly pervasive, network connectivity has become a standard feature of products and services, with growing integration between smart devices and digital services. At the same time, cyber threats, including information breaches and data loss caused by the exploitation of software vulnerabilities, continue to intensify. In response, Epson incorporates security measures across the entire product lifecycle, from product planning and development through operation and maintenance.
Secure Development
Epson is incorporating the Secure by Design concept into the development of products and services that customers can use with confidence. We analyze risks at the planning and design stages, conduct design reviews, write secure code, assess vulnerabilities, and take other steps to improve the security quality of our products.
Vulnerability Management Organization
We are strengthening our organization to enable a unified global response to the early detection and mitigation of product and service vulnerabilities. Epson has established a Product Security Incident Response Team (PSIRT) to ensure user safety and reliability, reduce the risk of exploitation, and minimize social impact. We are working with external organizations, including the Ministry of Economy, Trade and Industry's Information Security Early Warning Partnership, to quickly identify vulnerabilities and exploits that are discovered and reported after products are released to market. In the event of an incident, we implement countermeasures such as workarounds and software updates, and we have established a system for promptly disseminating information to external parties.
Supply Chain Management
To mitigate risks in our supply chain, we use a Software Bills of Materials (SBOM) to gain visibility into the composition of software components. This enables us to identify and manage software dependencies and helps prevent the incorporation of malicious or vulnerable components. Additionally, when new vulnerabilities are discovered, we can quickly identify the affected software components, thereby minimizing potential damage.
Product Security Related Web Pages
Personal Data Protection
Countries and regions around the world are enacting and amending laws and regulations related to personal data protection and privacy protection, including the EU General Data Protection Regulation (GDPR). Epson is reviewing its internal rules to accurately collect and understand the requirements for personal data protection.
To fulfill our social responsibility and meet the trust of our customers, business partners, and employees, we are working company-wide to protect personal data. Specifically, Epson's internal regulations stipulate that control measures based on the 11 principles set forth in ISO/IEC 29100 shall be formulated. In compliance with the laws and regulations of each country and region, Epson Group companies establish and publish "Privacy Statements" and "Privacy Policies" on their respective national websites.
AI Governance
Epson is increasingly using AI in its products and operations. At the same time, we are putting in place a global AI governance system to address risks associated with the use of AI, such as information leaks, copyright infringement, human rights violations, and the generation of misinformation and expressions that promote bias and discrimination. We assess the risks before introducing and using AI, and strive to ensure transparency, fairness, and safety.
Establishment of Guidelines
To ensure the proper use of AI systems and ethical practices, we have established "Epson Group AI Management Regulation" as well as various guidelines, checklists, and risk level assessment tables for use throughout the Group. In light of the rapid spread of generative AI, we have formulated "Guidelines for the Use of Generative AI," which specify considerations for copyright and privacy, as well as precautions regarding input and output, to promote the proper use of generative AI.
Risk-based Approach
We manage the use of AI systems by evaluating the risk level of each project and implementing risk mitigation measures based on a risk-based approach. AI Ethics Officer determines the risk level for each AI utilization project and records the evaluation results. In addition to copyright infringement and information leakage, we check for risks related to consideration of social diversity, ensuring transparency and fairness, and potential human rights violations. If risks are identified, we take measures to mitigate or avoid them to promote the responsible use of AI.
Monitoring of AI Governance Activities
Since FY2025, all group companies have conducted self-assessments to evaluate compliance with regulations and guidelines, as well as the effectiveness of rule implementation and the status of employee training.
Education and Training
Epson considers cybersecurity, product security, personal data protection, and AI ethics to be important management issues and continuously provides education and training to all employees.
In the field of cybersecurity, in order to improve information security awareness and enhance the ability to respond to various external threats, we conduct Online Courses on information security for officers, employees, and temporary agency workers, as well as training on how to respond to targeted email attack and risk assessment education for managers.
In the field of product security, we are working on training that is relevant to employees in a wide range of departments, including not only the planning, design, and development departments, but also maintenance, service, and factory operations. We strive to improve security awareness throughout the entire product lifecycle and strengthen our practical response capabilities.
Regarding personal data protection, we provide training tailored to the importance and role of the information handled in our operations. In addition to Online Courses for employees who handle personal information, we also provide training on the European General Data Protection Regulation (GDPR) to improve our ability to comply with global legal regulations.
Furthermore, in order to promote the importance of AI ethics and ensure responsible AI utilization, we provide Online Courses on AI ethics for officers, employees, and temporary agency workers who use AI, as well as Online Courses on the internal use of AI and the provision of AI products and services.
Through these educational programs and training sessions, we are promoting the creation of an organization where each employee understands the importance of security and privacy protection, and can make appropriate judgments and take appropriate actions in their work.
List of Certifications
Epson recognizes the importance of information protection in communications both inside and outside the company, including with customers and suppliers, and obtains external certification as appropriate for the business model.
ISMS (Information Security Management System) Certification
* The names of the organizations in the table are based on information available at the time the certificates were issued.
| Name of organization | Seiko Epson Corporation |
|---|---|
| Certification standard | ISO/IEC 27001:2022 / JIS Q 27001:2023 |
| Scope of certification and registration | The following tasks within the DX Division: - Operation and management of cloud services related to accounting business - Operation and management of shared platforms - Operation and management of health guidance services The following tasks in the P System Solutions Operations Division: - Operation and management of cloud print and scan services - Operation and management of remote monitoring systems |
| Expiration date | September 10, 2027 |
| Certification body | BSI Group Japan Co., Ltd. |
| Certification registration No. | IS 507352 |
| Name of organization | Epson Avasys Corporation |
|---|---|
| Certification standard | ISO/IEC 27001:2022 / JIS Q 27001:2023 |
| Scope of certification and registration | - Embedded software and application development for information devices - Manual production, technical translation for the above - Quality evaluation of information devices and application software - Development, quality evaluation, operation and maintenance of business systems - Management of in-house network and servers, development and management of information systems - Development, operation, maintenance and provision of cloud services - Provision of system engineering services |
| Expiration date | August 5, 2028 |
| Certification body | BSI Group Japan Co., Ltd. |
| Certification registration No. | IS 85200 |
ISMS Cloud Security Certification
| Name of organization | Epson Avasys Corporation |
|---|---|
| Certification standard | JIP-ISMS517-1.0 (ISO/IEC 27017:2015) |
| Scope of certification and registration | ISO/IEC27001 (JIS Q 27001) Certificate Number: IS 85200 ISMS Cloud Security Management System for the development, operation, and maintenance as a cloud service provider of "commutas," and for the use as a cloud service customer of Amazon Web Services for "commutas." |
| Expiration date | August 5, 2028 |
| Certification body | BSI Group Japan Co., Ltd. |
| Certification registration No. | CLOUD 806539 |
Privacy Mark System
| Name of organization | Epson Sales Japan Corporation * |
|---|---|
| Certification standard | JIS Q15001 |
| Assessment body | Software Association of Japan (SAJ) |
| Registration No. | 10520010 |
* Epson Japan Corporation (effective October 1, 2026)
| Name of organization | Epson Direct Corporation |
|---|---|
| Certification standard | JIS Q15001 |
| Assessment body | Japan Institute for Promotion of Digital Economy and Community (JIPDEC) |
| Registration No. | 10580040 |