TOKYO ELECTRON LIMITED

Information Security

Approach to Information Security

An environment where data can be used safely and securely is crucial for the continuous and steady development of the operations of the Company. For this reason, we view the assurance of information security as an important managerial issue, and continuously reinforce the protection of information about our customers and suppliers as well as confidential information on leading-edge technology. In addition, we strive to strengthen information security to ensure the stable operation of the entire supply chain.

TEL Group Information Security Policy


July 1, 2020 Established
June 1, 2026 Revised

  1. Introduction
      As society becomes increasingly reliant on information, information security risks continue to grow. Organizations are therefore required to effectively manage, protect, and utilize information. The TEL Group recognizes that ensuring the confidentiality and integrity of information, as well as the availability of systems that support its business operations, is essential. We are committed to identifying and assessing risks and ensuring information security.
      This policy sets forth the fundamental principles of information security that guide the TEL Group’s business activities.



  2.   
  3. TEL Group Information Security Goals

      Maintain the confidentiality, integrity, and availability of all information assets necessary for business, including the environments in which they are processed (collectively, “information assets”), to enhance the corporate value of the TEL Group.

      Implement the following measures to achieve this:

      • Protect and properly manage confidential information to prevent data leakage and enhance customer satisfaction

      • Prevent unauthorized alteration of information assets and ensure that business is conducted based on accurate information

      • Strengthen resilience against incidents to ensure business continuity

      • Comply with applicable laws, social norms, and the ethical standards, and fulfill the social responsibilities

      • Achieve both digital transformation (DX) and security in a balanced manner



  4. Primary Objectives

    • Appoint a Chairperson of the Information Security Committee to oversee information security across the TEL Group, establish a globally unified information security strategy, and ensure the implementation of necessary measures throughout the TEL Group

    • Establish common information security rules in compliance with applicable laws and international standards, provide training to raise awareness and ensure adherence to these rules, and maintain appropriate information management across the TEL Group

    • Continuously monitor and detect security threats, and continuously improve information security through the PDCA (Plan-Do-Check-Act) cycle

    • Ensure information security across the entire supply chain

    • Establish a unified incident response process across the TEL Group, and enhance response capabilities through continuous training





  • *Confidentiality: Information assets can only be accessed by authorized persons.

    *Integrity: Information assets are maintained in an accurate state without unauthorized alteration or error.

    *Availability: Information assets are available to authorized personnel whenever needed.

Information Security Report 2026

The semiconductor industry is experiencing significant change, driven by digital transformation, the rapid adoption of generative AI, increasingly sophisticated cyber threats, elevated supply chain risks, and heightened geopolitical and economic security concerns. In this dynamic environment, information security has become an essential management foundation underpinning business continuity and supporting the preservation and enhancement of corporate value.
We have identified information security as one of our key items that should be worked on with priority as our material issues. Under our global governance framework, we are committed to protecting our leading-edge technologies as well as the information entrusted to us by our customers and suppliers, strengthening risk management throughout the supply chain, and enhancing the security of our manufacturing sites and products. We are also promoting the appropriate governance for emerging digital technologies, including generative AI, to achieve both robust security and sustained competitiveness.
This report provides an overview of these initiatives. For more detailed information, please refer to the relevant sections of this report.
We will continue to strengthen information security as a foundation for sustainable growth and corporate value creation. By reinforcing the trust of our stakeholders, we remain committed to contributing to the sustainable development of the semiconductor industry.

Main Activities

 

 
   
Information Security Systems Responding to Security Threats Information Security Management
We have established the TEL Group Information Security Committee, chaired by an executive officer at the Head Office, to formulate information security strategies for the entire Group. We also coordinate with the Information Security Committees of each company to build shared understanding, ensuring a unified level of information security across the Group and establishing a system under the supervision of the Head Office that enables the swift deployment of various security measures. In response to changes in threats and technology trends, we continuously implement technical measures such as strengthening security for PCs and servers, introducing multi-factor authentication, and enhancing network security. We also monitor threats, including cyberattacks and internal fraud, 24 hours a day, 365 days a year. In the event of an incident, we have a system in place to promptly share information with relevant divisions and respond swiftly. We formulate an Information Security Policy with reference to requirements set out in international standards such as NIST*¹, roll them out globally, and review them as needed. We also provide ongoing information security training for all employees to improve security awareness and literacy. In addition, we are working to obtain ISO/IEC 27001*² certification starting from the Head Office and are gradually expanding the scope across the Group.
     
 
 
Security at Manufacturing Sites and in Products Supply Chain Security
External Activities and Strengthening of Information Security Human Resources
 We are strengthening security at our manufacturing sites to ensure the safe and stable operation of our manufacturing systems. Furthermore, we are also implementing security measures, not only in our products, but also in our manufacturing processes and field support so that our customers can use our products and services with assurance. To protect the entire supply chain from information security threats, we regularly conduct information security assessments on our suppliers. We are working on the continuous enhancement of security measures by making improvements with our suppliers on identified issues. We participate in external security activities, including initiatives to standardize security at SMCC*³, and contribute to improving information security levels in the semiconductor industry and society as a whole. We are also members of external security organizations joined by a wide range of organizations from industry, government, and academia, where we share various types of security information. In addition, we are actively recruiting and developing human resources to support our information security.

NIST: National Institute of Standards and Technology, the U.S. national standards and technology institute.

ISO/IEC27001: International standard for Information Security Management Systems

SMCC: Semiconductor Manufacturing Cybersecurity Consortium. A consortium that deliberates on strengthening cybersecurity within SEMI, an international semiconductor industry association