NS Solutions Corporation
2327・Prime Market・Information & Communication
Information Security and Unauthorized Access
With the expansion of SaaS-type IT services, the responsibility for managing customer information and personal data has increased. If an external cyberattack or internal information leak occurs, this could result in claims for damages or loss of credibility. An unauthorized access incident actually came to light at the end of FY2024. As a recurrence prevention measure, the Company established an Information Security Division directly under the president effective April 1, 2026, aiming to strengthen cross-company, group-wide governance and enhance its monitoring system.
Risk of Deteriorating Profitability in System Construction
Information system construction is generally conducted under contract-for-work arrangements, with strong project-specific characteristics and a completion obligation. If unforeseen impeding factors arise amid increasingly sophisticated, complex requirements and shortened delivery times, costs may exceed initial estimates. If contractual non-performance occurs, there is also a risk of claims for damages from clients or loss of credibility. The Company has established a Project Risk Management Organization that continuously identifies risks from the proposal stage and conducts organizational reviews.
Legal and Regulatory Risk, including Antimonopoly Act Violations
There are numerous opportunities for collaboration with other companies through outsourcing and subcontracting of operations, giving rise to risks of violating labor-related laws and the Subcontract Act (Act against Delay in Payment of Subcontract Proceeds, etc.) in relations with subcontractors, risks of violating the Antimonopoly Act and the Subcontract Act in pricing decisions, and risks of violating the Antimonopoly Act in public tender projects. If these risks materialize, they could result in administrative sanctions or loss of credibility. The Company works to avoid contractual risks through its Project Risk Management Organization.
IT Service Disruption Risk
In the provision of data center services, cloud services, and similar offerings, service disruptions caused by power or communication outages, equipment or facility failures, or human error could result in claims for damages from clients or loss of credibility. The Company identifies risks from the service proposal stage through its Project Risk Management Organization and, after order receipt, works to detect issues early and implement countermeasures through organizational reviews.
Risk of Fluctuations in Business Results and Cash Flow
Business results may fluctuate due to changes in economic conditions affecting IT investment trends, competitive conditions, the presence or absence of large-scale projects, and the progress and profitability of individual projects. In addition, quarterly and half-yearly results may fluctuate depending on the timing of recognition of projects such as equipment sales, where revenue is recognized at a single point in time. In the prior consolidated fiscal year, cash flow fluctuated significantly due to factors including a temporary increase in corporate income taxes associated with the sale of investment securities and expenditures for the acquisition of subsidiary shares.
Risk of Intellectual Property Rights Infringement
With the increasing sophistication and complexity of products and technologies, particularly the recent expansion in the use of generative AI, there is a possibility that the Company may face litigation or claims from third parties alleging infringement of intellectual property rights in connection with the services or products it provides. This could result in the burden of damages payments or force the Company to acquire or develop alternative technologies. The Company has assigned intellectual property officers to each division and, centered on its Legal and Intellectual Property Department, monitors third-party patent infringement and conducts internal training.
Labor Management and Harassment Risk
Long working hours, a risk characteristic of the IT industry, and the appropriate management of labor conditions across group companies remain challenges. Insufficient grasp of actual working conditions or legal violations could result in administrative sanctions or loss of credibility. The Company is working on continuous monitoring of actual working conditions using systems, reducing workload through standardization of business processes and use of generative AI, and strengthening global awareness-raising, training, and use of helplines to prevent harassment.
Business Continuity Risk from Natural Disasters and Infectious Diseases
Large-scale earthquakes, tsunamis, storms, floods, and other natural disasters, as well as the outbreak or spread of infectious diseases, could disrupt business activities if damage occurs to business sites, employees, or partners. The Company is working to formulate business continuity plans (BCP), build safety confirmation systems, conduct disaster drills, equip data centers with seismic isolation and earthquake-resistant structures and uninterruptible power supply units, and improve its distributed development framework and service continuity through the use of its cloud-based in-house development platform "TetraLink" and its IT service delivery platform "Nestorium."
Risk of Sales Dependence on Parent Company
The top shareholder, Nippon Steel Corporation (holding a 63.4% equity stake), is the Company Group's largest business partner. Sales to Nippon Steel in the current consolidated fiscal year reached ¥70,555 million (18.5% of sales). Should the parent company change its management policy or curtail IT investment, this could affect the Company Group's business results; however, the Company mitigates this risk by maintaining a broad customer base spanning manufacturing, distribution, finance, and public sector clients.
Technology Risk Associated with Generative AI Use
With the expanding use of generative AI, there is a possibility of increased risk of intellectual property rights infringement as well as the emergence of new risks related to the quality and security of the services and products provided. While promoting operational efficiency through the use of generative AI, the Company is working to manage technology risk through the use of "Nestorium," its company-wide standard SaaS-type IT service development and production platform, and by incorporating security requirements from the design stage.
Importance and likelihood are shown based on the company's disclosures.
Last updated: July 19, 2026

