[Last One Mile Labor Union] "Even if it withstands audits, information can still leak" CEO Makoto Watanabe's sales-oriented security theory

For companies that handle customer information, information security is not just a decoration to show to auditing firms. It is a system designed to protect the information of customers, business partners, and employees from actual leaks and unauthorized use.

However, according to information provided to our union by a current employee of Last One Mile Co., Ltd., during the company's information systems training, Representative Director, Chairman, and CEO Makoto Watanabe defined the standard for security as "whether it can withstand an audit," explicitly stating the gist that data leaks may occur as long as the audit can be passed.

Table of Contents

Sometimes data leaks occur even when complying with audits.

What the company demands is a level of security that can withstand an audit. Conversely, I think there are times when data breaches can still happen even if it passes an audit.

A state of passing an audit and a state where customer information is secure are not the same thing. An audit merely verifies controls and evidence at a given point in time, and it is not a guarantee that completely prevents all fraud, all operations, or all leaks.

Understanding this difference, the company must use passing the audit as a minimum condition while implementing additional safety measures according to actual risks. However, in Makoto Watanabe's explanation, the bare minimum to pass the audit has become the upper limit the company aims for.

Always security that leans "closely to the edge" of sales

The systems department must always make security decisions that are cutting it close, can withstand audits, and are viewed from a sales-oriented perspective.

Balancing sales activities with security is naturally a given. However, if "cutting it close" becomes a constant goal, there will be no room to absorb uncertainties such as new threats, configuration errors, human error, and contractor incidents.

It is like operating in a way that continuously allows vehicles right at the maximum weight the bridge can withstand to cross it every day, day after day. On a clear day, no problems might occur, but the moment strong winds or aging are added, it collapses.

Recognizing even the possibility of customer data being stolen via USB

Mr. Makoto Watanabe was fully aware that leaving the USB port accessible could allow an operator to remove data.

The fact that the USB ports are active creates the risk of an operator plugging in a USB drive and extracting data.

Furthermore, the guide states that the Information Systems Department should not decide on its own that “USB drives should be disabled because they are dangerous,” but should instead limit its role to communicating the magnitude of the risk to management.

The system side should not just say no because there is risk. Your job is to accurately convey the degree of that risk. Management makes the decision.

It is not inherently unreasonable for management to make the final decision on risk acceptance. However, if you strip away even the specialized department's authority to determine that something is "legally, contractually, or technically unacceptable," the Information Systems Department ceases to be a security management division and merely becomes a receptionist that records the degree of risk for sales activities.

Turning "breaking into" the customer's system into a sales weapon

During the training, the expression "drill a hole" was repeatedly used regarding sales related to connecting the customer's system with the last-mile system.

System integration is impossible unless we definitely weaken security. We both have to poke holes in our defenses.

Penetrate where other companies aren't doing it. As a small and medium-sized enterprise, you can definitely make a breakthrough there.

"We can use this in our sales pitch by saying we can integrate while bypassing a listed company's security."

System integration equipped with proper authentication, encryption, access control, connection time limits, and log monitoring is standard business activity. However, can a representative's mindset—described to employees as "breaching a listed company's security" or "creating a loophole"—be reassuring to client companies?

Security for Audits and Security for Customers

It is necessary to pass the audit. However, an attitude of simply avoiding detection during the audit turns security into a formality for maintaining a listing rather than protecting customers.

Even if the materials to be submitted to the auditor are in order, data can still be extracted via USB from actual devices. Even if access restrictions exist in the regulations, exceptional connections increase for sales purposes. Still, if the operation is just about formally satisfying the audit items, customer information is protected only on paper.

Public questions for Last One Mile, Inc.

  1. During the training, were the USB ports on the terminals used by operators disabled?
  2. Have you ever had customer data removed using USBs or other external media?
  3. Regarding the connection with the customer system, was the "opening a hole" operation explained in the training actually implemented?
  4. Did the Information Systems Department have the authority to reject sales opportunities for security reasons?
  5. Do the Board of Directors and the Audit and Supervisory Committee evaluate the remark, "Even if it passes an audit, information leakage can still occur," as appropriate?
  6. After this training, did you review the information security policy, device management, access control, or external connection standards?

Stop the leak before it happens, rather than apologizing after it happens.

If a data leak occurs, the company can issue an apology, provide compensation, and announce recurrence prevention measures. However, it is impossible to completely recover leaked addresses, phone numbers, contract information, audio recordings, and identity verification information.

That is precisely why information security is different from normal business risk where "the company takes responsibility if a problem occurs."

Last Mile Inc. should set its standard not at the bare minimum that can withstand an audit, but at a level that can realistically protect customer information. If security is something that is weakened to the absolute limit for the sake of operating profit, the most dangerous entity for customers will not be external attackers, but the management that makes that decision.

President Makoto Watanabe's Corporate Training Series for Instilling Dangerous Ideologies Through Fear

Let's share this post!
Table of Contents