{"url_path":"/sec/mfg/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-26","source_url":"https://www.sec.gov/Archives/edgar/data/1335730/0001193125-26-283791-index.html","accession_number":"0001193125-26-283791","cik":"0001335730","ticker":"MFG","issuer_name":"MIZUHO FINANCIAL GROUP INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1335730/0001193125-26-283791-index.html","primary_entity_key":"0001335730","primary_entity_name":"MIZUHO FINANCIAL GROUP INC"},"word_count":1382,"has_tables":true,"body_markdown":"ITEM 16K.  Cybersecurity\n\nCybersecurity Strategy\n\nMany of our systems are connected to our domestic and overseas locations, and the systems of our customers and various payment institutions, through global telecommunications networks. As cyber attacks become more sophisticated, we recognize cybersecurity as an important management issue and continuously promote cybersecurity measures under management leadership.\n\nWe define cybersecurity risk as the risk that the group may incur tangible or intangible losses due to cybersecurity-related problems that occur at the group and/or at its clients, along with organizations, etc., that have a business relationship with the group, such as outside vendors and goods/services suppliers and view it as one of our top risks. Accordingly, we have established a system to centrally manage cybersecurity risk through the Risk Appetite Framework and the Comprehensive Risk Management Framework.\n\nGovernance System\n\nAt Mizuho Financial Group, the President & Group CEO deliberates and resolves fundamental issues related to cybersecurity risk management. The Board of Directors receives reports from the Group Chief Information Security Officer (“CISO”) on cybersecurity risks that may have an impact on management policies and strategies, annual business plans, medium- to long-term business plans, etc., other cybersecurity risks that the Board of Directors should be aware of from a medium- to long-term perspective, and important matters such as the status of risk control.\n\nThe Risk Committee and the IT/Digital Transformation Committee *1, both of which are advisory bodies to the Board of Directors, each receive reports from the Group CRO on the status of comprehensive risk management and from the Group CISO on basic matters related to cybersecurity risk management, evaluate conformity with our basic management policies and the appropriateness of our cyber initiatives, and present recommendations or opinions to the Board of Directors. In addition, the independent third line in the three lines of defense *2 conducts audits on the initiatives of the first and second lines, and reports the results to the Operational Audit Committee, etc.\n\nUnder such supervision by the Board of Directors, our President and Group CEO oversees the cybersecurity risk management of Mizuho Financial Group, and the Group CISO, in accordance with the instructions of the Group CIO and the Group CRO, establishes measures for risk management through autonomous control activities by the first line, and monitoring, measurement, and evaluation by the second line of such autonomous control activities by the first line and gives instructions to prevent cybersecurity risks that may arise from fraud or outsourcing, and to respond appropriately to cyber incidents.\n\nThe Group CISO has been engaged in the IT and systems industry for more than 30 years and, with extensive knowledge and experience, is responsible for the planning and operation of cybersecurity risk management.\n\nBased on the instructions of the Group CISO, the Cybersecurity Management Department identifies possible cybersecurity risks to our business and systems, evaluates our preparedness, assesses risks\n\nidentified by\n\n \n\n190\n\nanalyzing the location and magnitude of cybersecurity risks, and then reviews and formulates additional measures to strengthen risk control, such as preventive measures and reactive responses, and strengthens risk control and governance through reflection in business plans.\n\nThe Cybersecurity Management Department reports to the Group CISO on the status of cybersecurity risk management, and the Group CISO regularly reports, and if applicable, submits proposals for deliberation, to the Management Committee via the IT Strategy Promotion Committee and to the Board of Directors, each on the status of our cybersecurity measures, etc., with the aim of developing and strengthening a system for ensuring cybersecurity.\n\nWe have appointed a person in charge of cybersecurity and have established a communication system at group companies, to monitor the status of our cybersecurity measures and to quickly gather information when an incident occurs.\n\nInitiatives for Strengthening Cybersecurity\n\nTo identify and prevent the manifestation of cybersecurity risks, we collaborate with external organizations such as the Financial Services Information Sharing and Analysis Center\n(FS-ISAC)\nand other financial institutions. We collect threat intelligence and implement prioritized measures based on the potential impact on us.\n\nSpecifically, we take measures to ensure consistent security throughout the entire system development lifecycle, from the planning phase to the development and operation phases.\n\nAfter the release of systems, we promptly identify and address the impact of disclosed vulnerability information on our group’s system by introducing configuration management database, and vulnerability scanning systems.\n\nTo evaluate the effectiveness of these technical measures against cyber attacks on our systems, we also regularly conduct vulnerability assessments and\nThreat-Led\nPenetration Testing *3.\n\nAs part of our preparedness measures, the\nMizuho-Cyber\nIncident Response Team *4 and other highly qualified professionals are deployed, and a 24 hours a day, 365 days a year monitoring system is in place using an integrated Security Operation Center *5, etc.\n\nWe are also focusing on human resources development, such as conducting study groups for directors including outside directors, cybersecurity training for each executive and employee layer, and phishing email training for all executives and employees at least once every six months.\n\nAdditionally, we confirm before, and on a regular basis after entering into a contract with a third party, the security management preparedness, including responses in the event of a cyber incident, of third parties such as cloud service providers that provide outsourcing and cloud services. When we receive reports of cyber incidents from third parties, in addition to identifying and analyzing the impact on the group, we also strive to respond appropriately to risks when there is concern about the impact on the group.\n\nWe verify the effectiveness of our cybersecurity posture by referring to external frameworks related to cybersecurity, such as the Cybersecurity Framework developed by the National Institute of Standards and Technology and guidelines on cybersecurity published by the Financial Services Agency. Additionally, we undergo evaluations by third parties.\n\nImpact and Response When a Cyber Incident Occurs\n\nAs a result of our enhanced cybersecurity measures, we are not aware of any past cyber attacks that could have had a significant impact on investor decisions or could have materially affected our business operations,\n\n191\n\nresults of operations and financial condition, in the fiscal year ended March 31, 2026. However, regarding a cyber attack due to a failure to strengthen cybersecurity measures, leaks or falsification of electronic data, suspension of business operations, information leaks, and unauthorized remittances there can be no assuranc that such incidents will not occur and cause inconvenience and disadvantage to our customers.\n\nIn addition, our business operations, results of operations and financial condition may be materially affected by compensation for damages, administrative actions and damage to reputation.\n\nIn the unlikely event that a cyber-incident is detected, or if it is determined on firm grounds that the likelihood of a cyber incident occurring is very high, the Cybersecurity Management Department will report the cyber incident to the Group CISO. The Group CISO reports to the Management Committee and the Board of Directors when particularly important incidents occur or are likely to occur.\n\nBased on the instructions from the Group CISO, the Cybersecurity Management Department monitors the cause of the incident (including incidents for which the likelihood of occurrence is determined on firm grounds to be very high), the nature and extent of the damage or expected damage, supports the formulation of effective containment, eradication and recovery measures, analyzes attack methods or expected attack methods based on cyber incident information, and conducts incident response.\n\nEven after incident recovery, the Cybersecurity Management Department monitors changes that could lead to cyber incidents in the group and promptly reports to the Group CISO when a breach of the threshold is identified. In addition, the Cybersecurity Management Department analyzes and evaluates the status of causes and risks, and implements necessary measures after consulting with the Group CISO on the response policy.\n\n \n\n*1\n\nIT/Digital Transformation Committee (as described in “Item6.C. Board Practices”)\n\n*2\n\nThree lines of defense (concept for defining and classifying organizational functions and responsibilities in risk management and compliance)\n\n*3\n\nThreat-Led\nPenetration Testing (evaluation of systems and response processes by analyzing targeted threats and conducting attacks that mimic actual attacks)\n\n*4\n\nCyber Incident Response Team (incident response teams within the Cybersecurity Management Department that specialize in information security issues within the organization)\n\n*5\n\nSecurity Operation Center (a specialized team within the Cybersecurity Management Department that monitors and analyzes threats to information systems in organizations such as enterprises)\n\n \n\n192\n\nPART III"}