Business risks
June 2026
Of the matters relating to the business status, accounting status, etc. described in the securities report, the major risks that management recognizes as having the potential to have a significant impact on the financial position, operating results, and cash flow status of the consolidated company are as follows:
Please note that the matters relating to the future are based on judgments made by the Group as of the date of submission of the securities report.
Risks related to disruptions to information systems or inadequate information security and personal information protection
Our group provides system outsourcing services for the financial and retail industries, as well as our own services utilizing external public cloud services. Therefore, our group is committed to selecting public cloud services that meet the necessary and sufficient requirements for service provision, and to providing employee Education in information security and technical aspects. However, in the event of any disruption to these information systems, including communication networks and power systems, or any information security deficiencies, including the leakage of personal information due to computer viruses or cyberattacks, our group may suffer consequences such as loss of credibility, loss of customers, and compensation for damages.
As a countermeasure against this risk, our group has established a system compliant with ISMS (Information Security Management System) and is striving to strengthen our response by establishing internal rules that take into account the laws and regulations of each country/region, including GDPR (EU General Data Protection Regulation), in order to respond to global business. As a preventive measure, we have established a CSIRT (Computer Security Incident Response Team), provided personal information protection Education, developed security incident response procedures, conducted regular training, and raised awareness within the company through the latest case studies. In addition, we have introduced the CSPM (Cloud Security Posture Management) service to take measures such as detecting configuration deficiencies that could lead to unauthorized access or information leakage, and we have implemented incident detection and notification measures for critical services.
Climate change and disaster risks
Our group's sustainability policy is committed to co-creating the future from a global perspective and working towards the development of a sustainable society. Global climate change can change the foundations of life for our customers, business partners, and employees, and ultimately lead to changes in the business environment. From a medium- to long-term perspective, we consider this to be an important risk that we must consider in order for our services to continue to contribute to improving our customers' business challenges.
Furthermore, our group recognizes the risks related to fire, earthquakes, war, infectious diseases, and security in our system operations and support services. While we have taken measures such as earthquake and fire resistance in our data centers to ensure a certain level of safety, in the event of a major earthquake, fire, other natural disaster, equipment malfunction, or operational error, the provision of services may be significantly disrupted, potentially impacting our group's performance and financial condition due to compensation claims and loss of trust. In addition, if our employees or business partners providing support are unable to access necessary resources due to infectious diseases or other reasons, there is a risk that business continuity may become impossible.
Our group implements various measures to avoid failures and interruptions in system operation and support services, including security measures, information gathering from business partners, securing access routes to external resources, and enhancing internal Education. Furthermore, these measures are effective not only for system operation and support, but also for system development, package sales, and all internal back-office departments.
Risks related to securing and training engineers
The design and construction of information systems are knowledge-intensive and labor-intensive tasks, and we recognize that securing highly skilled engineers with a certain level of expertise is essential for business expansion. Currently, our group's personnel and Education systems ensure that we have the necessary engineers. However, if the labor market becomes tight and we are unable to secure the highly skilled engineers or labor that our group needs, if we fail to provide adequate support for new hires in a telework environment, or if a large number of our employees leave the group, our group's business development may be constrained.
As countermeasures against this risk, our group is working to minimize mismatches by increasing contact with our group employees throughout the application, interview, and onboarding process; to revitalize real communication by holding in-person company events in addition to online ones; and to create diverse career paths and supportive systems and environments for employees in specialized fields such as engineers, as well as those experiencing life events such as childcare or elder care.
Risks related to contract development
For contract development projects of a certain size or larger, the Group conducts "reviews of the appropriateness of estimates by persons not involved in the project," and is continually working to improve project quality and strengthen its management system, including promoting the standardization of project development methods and training project managers. However, even contract development projects that are deemed to be reasonably profitable at the time of acceptance may become unprofitable due to project management issues during the development stage, unexpected expansion of the development scope, an increase in work hours, etc. In such cases, the Group's business performance and financial position may be affected, including the recording of order losses, compensation for damages due to delivery delays, and the recording of impairment losses on related assets.
As a countermeasure against this risk, our group has implemented measures such as having the Project Council check proposals, project plans, and project execution (introducing a check sheet (Project Council Check Sheet) that can confirm project status using the same standards), establishing related rules, and spreading company-wide development standards and procedures. In addition, we regularly monitor whether projects are being implemented in accordance with rules and procedures.
Risks related to software development for new products and services
The Group is focusing on the development of its own services and software as an important investment to strengthen and maintain market competitiveness. However, the development of new services in particular involves a high degree of uncertainty. If the investment recovery plan is not expected to achieve the initial plan due to downward revisions to future revenue plans, delays in development plans, cost increases, etc., it may be necessary to record impairment losses on fixed assets.
As a countermeasure against this risk, our group monitors project progress through project councils and milestone reviews, establishes related rules, promotes modern development, etc. In addition, in order to understand customer needs, information is shared at management meetings regarding the status of new projects, etc.
Risks related to the actions of specific business partners
Our group's sales to Credit Saison Co., Ltd. account for 31.1% of our total sales (in the current consolidated fiscal year). A decrease in sales to this company could have an impact on our group's performance and financial condition. Furthermore, a decline in sales of "HULFT," our highest-selling software product, due to changes in the market environment or increased competition could have a significant impact on our group's performance and financial condition.
Our group will address this risk by promoting business development in new technologies and new fields as outlined in our management policy, and by developing more profitable businesses in new markets and customer bases.
Intellectual property risks
In sales of our core products, including "HULFT," "DataSpider Servista," and "HULFT Square Square," we are promoting global expansion and focusing on our customers' digital transformation. As we expand our business into these new technologies and new fields, we take great care to protect and preserve our proprietary technology and know-how and to avoid infringing on the intellectual property rights of third parties. However, issues regarding intellectual property rights may arise due to differences in legal systems in some regions. This could result in us being sued for damages for infringing on the intellectual property rights of others. Furthermore, we may be unable to obtain licenses from intellectual property rights holders, which could result in us being unable to provide certain technologies, products, or services. Either of these events could have an adverse effect on our business performance and financial condition.
To avoid such risks, the Group's compliance and risk management departments are primarily responsible for checking the intellectual property of other companies and for appropriately managing the intellectual property held by the Group.
Risks related to exchange rate fluctuations
If sudden exchange rate fluctuations occur in the Group's global business activities, such as the provision of products and services to overseas bases, development outsourcing, and other intra-group transactions, or the use of services from overseas vendors, this could affect the Group's business performance and financial position.