ASJ INC.
2351・Standard Market・Information & Communication
Cybersecurity Risk
Responding to unknown and increasingly sophisticated cyberattacks—such as ransomware, supply chain attacks, and zero-day attacks exploiting generative AI—is positioned as a top-priority management issue. In the event of a system breach, the Group may face leakage of confidential information, recovery costs, liability for damages, lost business opportunities, and damage to its social credibility. The Group has implemented measures such as obtaining ISMS certification, establishing multi-layered defenses, and building AI governance frameworks; however, defense against new or unknown attack methods may prove difficult, potentially necessitating precautionary service suspensions.
Personal Information and Information Security
The Group holds a large volume of personal information through its internet services business. Should information be leaked due to system defects or intentional or negligent acts by internal personnel, the Group could incur substantial costs and be subject to claims for damages. The Group continues to undergo third-party audits as a Privacy Mark-certified operator and maintains ISMS certification and full PCI DSS compliance, but information leakage could still lead to a serious deterioration of corporate image. In particular, operations handling card information require ongoing compliance with industry standard requirements.
Generative AI and AI Agent Risk
Generative AI and AI agent technologies are evolving rapidly, and changes in industry standards or the emergence of innovative services from competitors could make it difficult for the Group to differentiate its services. Inherent risks also include inappropriate outputs due to hallucination or bias, copyright infringement, leakage of confidential information, and the need to respond to AI governance regulations. Although the Group has established internal usage guidelines and AI security measures, the materialization of these risks could lead to damage to social credibility, liability for damages, and increased costs of regulatory compliance.
Capital Expenditure and Impairment Risk
The Group holds substantial fixed assets due to active investment, including the Himeji Lab & Server Center and software research and development for new services. If a significant deterioration in the business environment reduces business profitability such that recovery of invested amounts becomes unlikely, an impairment loss on fixed assets may occur, affecting business results. In addition, the Group raises funds through borrowings from financial institutions, and rising market interest rates or changes in credit conditions could make it difficult to secure financing on the terms originally assumed.
Supply Chain Risk
The Group's business structure relies heavily on numerous external suppliers for hardware such as servers, network and storage equipment, software licenses, telecommunications lines, and power supply. Supply constraints have emerged due to semiconductor shortages, logistics disruptions from geopolitical risk, exchange rate fluctuations, rising energy prices, and cyberattacks on suppliers, potentially reducing service delivery capacity, increasing procurement costs, and delaying capital expenditure plans. While the Group addresses these risks by securing multiple suppliers and accelerating procurement planning, its ability to respond to supply constraints beyond what is anticipated may be limited.
Rising Energy Prices and Facility Costs
Because the Group's service model involves operating numerous servers in its own data centers, it consumes a large amount of electricity. If increases in electricity prices exceed expectations and cannot be passed on to service pricing, profitability will deteriorate. Additionally, the impact on business results may arise in cases where additional capital expenditure for facility expansion accompanying business growth is difficult to reflect in service pricing. The rise in energy prices due to geopolitical risk is also linked to supply chain risk, raising concerns about compounded effects.
Technological Innovation and Intensifying Competition
In the cloud market, there is a risk that competition for customer acquisition will intensify due to the entry of large corporate groups with strong capital resources, marketing capabilities, and broad customer bases, as well as new entrants. Internet-related technology is evolving rapidly, and if industry standards or user needs change abruptly due to the rapid spread of advanced technologies such as generative AI, the competitiveness of the Group's services could decline. The Group is addressing this through in-house development for price advantage and differentiation through value-added services, but the impact of a delayed response to unexpected technological innovation could be significant.
Legal Regulation and Compliance
The Group is subject to a wide range of laws and regulations, including the Telecommunications Business Act, the Personal Information Protection Act, the Payment Services Act, and the Act on Specified Commercial Transactions, and unforeseen enactment or amendment of laws could restrict business operations. If deficiencies in screening systems for compliance with anti-organized crime ordinances inadvertently result in transactions with antisocial forces, this could lead to termination of important contracts, compensation issues, and damage to social credibility. In addition, in payment processing services, if a third party commits an act violating laws such as intellectual property infringement or fraud, the Group, as a system provider, could be held responsible.
Human Resource Recruitment and Development Risk
Because the Group basically develops in-house the servers and applications needed to provide its services, securing and developing highly specialized personnel—including development and support staff as well as generative AI, cybersecurity, and infrastructure engineering talent—is key to business continuity. With 144 employees (as of March 31, 2026), the Group is a small organization, and there is no guarantee that it will be able to stably secure the personnel necessary as its business expands. If personnel development and appropriate staffing do not proceed as planned, this could affect the business and results of operations. If the management framework fails to keep pace with growth in headcount, operational disruptions could also occur.
Internal Control Systems and Governance
If the development of internal management systems fails to keep pace with rapid changes in the business environment as the business expands, this could result in misconduct or administrative disruptions, leading to legal liability and damage to corporate image. A similar risk exists if management and support for consolidated subsidiaries are not carried out appropriately, resulting in deteriorating subsidiary performance or misconduct. If a material weakness occurs in internal controls over financial reporting, the reliability of financial reporting could be undermined, resulting in remediation costs and a loss of credibility.
Importance and likelihood are shown based on the company's disclosures.
Last updated: July 19, 2026

