{"url_path":"/sec/ix/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-22","source_url":"https://www.sec.gov/Archives/edgar/data/1070304/0001193125-26-276640-index.html","accession_number":"0001193125-26-276640","cik":"0001070304","ticker":"IX","issuer_name":"ORIX CORP","edgar_url":"https://www.sec.gov/Archives/edgar/data/1070304/0001193125-26-276640-index.html","primary_entity_key":"0001070304","primary_entity_name":"ORIX CORP"},"word_count":771,"has_tables":true,"body_markdown":"Item 16K. Cybersecurity\n\n(1) Risk management and strategy\n\nOur Information Security Control Department reports to and manages cyber and information security risks to the Information Technology Management Committee.\n\nOur Information Security Control Department has established a cyber and information security awareness training program for our consolidated group companies. All employees of our consolidated group companies, including investee companies, and employees of outsourcing companies with access to our network are required to take online training at least once a year. These educational programs also include phishing\ne-mails\nsimulations, which are conducted several times a year on an irregular basis. We also provide training through escalation and response simulations in the event of a cyber or information security incident.\n\nEach of our consolidated group companies is assigned an Information Security Owner, and cyber and information security knowledge and the Group’s security policies are shared with the companies at least semi-annually to raise readiness levels across the ORIX Group.\n\nIn order to control cyber and information security risks we face through our interactions with and reliance on third parties, such as through our outsourcing activities and use of cloud services, we conduct regular security assessments of business partners and outsourcing vendors. In addition, we have a framework in place for the Information Security Control Department to evaluate the security risks of information systems and cloud services provided by business partners and outsourcing vendors.\n\nThe Information Security Control Department is responsible for assessing and managing our cyber and information security risks and where necessary, engages third-party consultants for advice regarding specific areas where enhanced controls or\nin-depth\nanalysis is required.\n\nThe ORIX Group has also established a framework to respond to cyber and information security incidents and to mitigate the risk of security breaches, system failures and information leaks, including cyber attacks and damage to information security systems. A system has been established to assess the impact on operations and the likelihood of secondary damage in the event of a cyber and information security incident caused by cyber attacks. The Information Security Control Department analyzes and investigates the incident and also works with the legal department and compliance department to minimize the impact of the incident and prevent secondary damage. Any serious incidents are reported to the Executive Officer in charge of the Information Security Control Department and appropriate action is taken under his/her direction. The current Executive Officer in charge of information security at ORIX has extensive knowledge of information technology and security, cultivated through his experience with system development, project management and security management in over two decades at various international companies prior to joining ORIX\nCorporation\n, including over a decade of experience in the financial business sector.\n\nIn the current fiscal year, we did not identify any cyber or information security incidents that have materially affected or are reasonably likely to materially affect our business activities, results of operations or financial condition.\n\n \n\n1\n88\n\n[Table of Contents](#toc)\n\n(2) Governance\n\nThe ORIX Group has established internal rules governing the structure, basic policies, management standards for information security, education, and audits in accordance with global standards for information security controls such as ISO and NIST.\n\nThe Information Security Management Rules stipulate that strategies and policies regarding cyber and information security, as well as response policies for cyber and information security incidents, are to be discussed and determined by the Information Technology Committee. The Information Technology Committee is organized in accordance with the Information Technology Committee Rules and is composed of the Group CEO, the Group CFO and other executive officers designated by the Group CEO.\n\n In addition, the response status of any cyber or information security incident is reported to the Audit Committee by the Executive Officer in charge of the Information Security Control Department to ensure appropriate information sharing.\n\nWe have a system in place to determine the seriousness of cyber or information security incidents, report to the Disclosure Committee in a timely manner, as well as to disclose information on cyber security risks, strategies, and governance on a regular basis, in addition to the status of incident management. In addition to the management of incidents, we have also established a system that enables regular disclosure of cyber security risks, strategies, and governance.\n\nWe have also established company-wide security requirements with which all consolidated group companies must comply, such as keeping systems up to date through vulnerability management program and technical measures for network defense. We have also established internal rules for security log management that take into account physical and logical boundaries with external networks as well as information breaches caused by internal fraud.\n\n \n\n1\n89\n\n##### Table of Contents\n\nPART III"}