Nomura Research Institute, Ltd.
4307・Prime Market・Information & Communication
Information Security Risk
With the advancement of DX and generative AI, threats of information leakage from cyberattacks and ransomware are increasing, and as an information services industry player handling substantial amounts of confidential customer information, particularly advanced management is required. The Group has obtained Privacy Mark certification, implemented an ISO27001-compliant security management system, and installed entry/exit management using X-ray inspection equipment at data centers, but if an information leak were to occur, business performance could be affected by customer claims for damages or loss of credibility. Strengthening group-wide governance in response to the increasing number of overseas subsidiaries is also being addressed as a key theme.
Project Management Risk
Information system development is generally conducted under contract-for-work agreements, and there is a risk that work hours may exceed initial estimates due to increasingly sophisticated and complex customer requirements or changes in specifications, resulting in delivery delays or deteriorating profitability. This risk is particularly high in long-term, multi-year projects where requirement changes are likely due to changes in environment and technology, and systems for the financial services industry also relate to the credibility of the financial markets as a whole. The Group has established an ISO9001-compliant quality management system and a dedicated review structure for projects above a certain scale, but risks of additional costs and claims for damages remain.
Risk of Intensifying Competition and Technological Innovation
The business model of the information services industry is changing, with consulting firms expanding into system development areas, system development firms expanding into consulting areas, and competitors expanding scale through M&A, creating a risk that the Group's competitive advantage may relatively decline. In particular, as competitors strengthen their AI capabilities amid the spread of AI utilization, differentiation may become difficult, potentially leading to intensified competition for orders and progressing price competition, which could reduce revenue opportunities. The Group recognizes that a delayed response to the rapid evolution of AI could directly impact business performance.
Human Resource Acquisition and Development Risk
In addition to labor shortages stemming from the declining working population, competition to acquire specialized talent, particularly in the AI and security fields, is intensifying further due to growing demand for AI utilization and increasingly complex cyberattacks. The Group is implementing measures to secure and retain personnel, including raising compensation, strengthening linkage with corporate performance and results, and accommodating diverse working styles, but if the Group is unable to secure and develop highly specialized personnel as planned, business performance could be affected. Developing next-generation leaders is also recognized as an essential issue for medium- to long-term growth.
System Operation Risk
The information systems developed and operated by the Group form critical infrastructure for customers' business operations, and systems for the financial services industry in particular relate to the credibility of the financial markets as a whole. The Group strives to maintain and improve operational quality through management systems compliant with ISO27001 and ISO20000, but if stable operation at the agreed level cannot be achieved due to human error, equipment failure, or infrastructure disruptions such as power outages, there is a possibility of deteriorating business performance or loss of credibility. Operational risks such as data entry errors or misdirected communications inherent in BPO Services also exist.
Supply Chain Risk
Outsourcing accounts for approximately half of production output, making it essential for business continuity to secure high-quality partner companies and maintain good business relationships with them. For overseas partner companies, there is a risk of unforeseen events arising from political, economic, or social factors, as well as risks related to disguised contracting issues in contracted work and abuse of a dominant bargaining position in price pass-through negotiations. The Group conducts periodic evaluations of partner companies and undertakes measures such as the "Declaration of Partnership Building," but if maintaining business relationships becomes difficult, this could hinder the smooth execution of business operations.
Regulatory and Economic Security Risk
Laws and regulations both in Japan and overseas may be newly established, amended, or reinterpreted in a short period due to circumstances beyond the Group's control, and in particular, there is a need to respond to the development and tightening of laws related to economic security, as well as strengthened export controls and sanctions measures in various countries, including U.S. export control regulations. If the Group's response to such regulations is delayed, this could result in administrative sanctions, trade restrictions, and loss of social credibility, and could also force changes to business strategy or business models. The Group strives to respond appropriately and in a timely manner by strengthening cooperation with relevant government agencies and enhancing internal systems.
Geopolitical Risk
For the Group, which operates globally, deteriorating international conditions such as terrorism or conflicts could threaten employee safety and disrupt business activities. Growing concerns over economic security and policy changes or regulatory tightening in various countries and regions act as constraining factors on business activities, posing a risk of impact on business performance and financial condition. The Group regularly monitors the political and economic situations in the countries and regions where it operates, but recognizes that it is difficult to fully avoid or predict geopolitical risks.
Business Investment and M&A Risk
The Group is pursuing M&A and alliances to expand its global business foundation, as well as investing in proprietary software, but if unrecognized issues emerge after execution or if expected results are not achieved, this could necessitate goodwill impairment, potentially affecting business performance. Software is difficult to repurpose due to its design for specific applications, and the recoverability of investment is not necessarily guaranteed. The Group has established a detailed pre-investment review process and a system for periodically checking the progress of business plans, but investment risk remains.
Climate Change and Natural Capital Risk
In response to growing social demand for decarbonization, the Group has positioned measures at its power-intensive data centers as a key priority, introducing renewable energy across all domestic data centers and adopting an ISO14001-compliant environmental management system. If the transition to renewable energy or efforts to reduce Scope 3 emissions are delayed, or if social demands regarding climate change advance rapidly, this could result in increased response costs and lost sales due to customer attrition, affecting the Group's social reputation. Responding to the Kunming-Montreal Global Biodiversity Framework and the TNFD recommendations is also recognized as a new challenge.
Importance and likelihood are shown based on the company's disclosures.
Last updated: July 19, 2026

