Information Security Basic Policy

As a partner company contributing to the development of industry and social infrastructure that shape the future by leveraging cutting-edge technologies cultivated through long experience with water treatment, the Organo Group (the “Group”) aims to provide products and services that create value and solve issues for industry and society.

Through these activities, we recognize that protecting the Group’s information assets from external cyberattacks and internal security incidents is our social responsibility, and we will establish mechanisms for ensuring information security, including cybersecurity, and continuously improve them.

The Group will implement the following measures to establish, implement, inspect, and improve information security.

(1)

Building and operating a management system

We will build an information security management system led by the management team, and under managers designated by the management team, we will establish and enforce regulations for appropriately implementing information security measures.

(2)

Compliance with laws, regulations, and contractual obligations

Regarding information security and personal information protection, we will monitor and manage changes in domestic and international laws and regulations applicable to the Group, ensure compliance, and fulfill contractual obligations to stakeholders.

(3)

Implementation of security measures in line with the level of importance

We will implement security measures in line with the level of importance of information held by the Group as well as its manufacturing and field management systems, striving to prevent and reduce incidents and accidents.

(4)

Quick response to information security incidents

In the event of an information security incident or similar occurrence, we will respond promptly and appropriately under our emergency response framework and strive to prevent recurrence.

(5)

Education and training

We will provide regular education and training for all employees of the Group, including executives, on information security-related regulations and the importance of information management and will work to raise awareness so that each individual can respond autonomously.

(6)

Disclosure of policies and initiatives

We will appropriately disclose our Information Security Basic Policy and the status of initiatives on our website and will strive to enhance the trust and confidence in the Group among all stakeholders, including customers, business partners, shareholders, and employees.

(7)

Continuous improvement

To continuously improve information security and adapt to changes in the business environment, we will strive to periodically review and improve our information security regulations, including this Information Security Basic Policy, as well as the operational status of our information security measures.

April 1, 2026
Masayuki Yamada
Representative Director and President
ORGANO CORPORATION