For companies that handle customer information, information security is not just a decoration to show to auditing firms. It is a system designed to protect the information of customers, business partners, and employees from actual leaks and unauthorized use.
However, according to information provided to our union by a current employee of Last One Mile Co., Ltd., during the company's information systems training, Representative Director, Chairman, and CEO Makoto Watanabe defined the standard for security as "whether it can withstand an audit," explicitly stating the gist that data leaks may occur as long as the audit can be passed.
Sometimes data leaks occur even when complying with audits.
What the company demands is a level of security that can withstand an audit. Conversely, I think there are times when data breaches can still happen even if it passes an audit.
A state of passing an audit and a state where customer information is secure are not the same thing. An audit merely verifies controls and evidence at a given point in time, and it is not a guarantee that completely prevents all fraud, all operations, or all leaks.
Understanding this difference, the company must use passing the audit as a minimum condition while implementing additional safety measures according to actual risks. However, in Makoto Watanabe's explanation, the bare minimum to pass the audit has become the upper limit the company aims for.
Always security that leans "closely to the edge" of sales
The systems department must always make security decisions that are cutting it close, can withstand audits, and are viewed from a sales-oriented perspective.
Balancing sales activities with security is naturally a given. However, if "cutting it close" becomes a constant goal, there will be no room to absorb uncertainties such as new threats, configuration errors, human error, and contractor incidents.
It is like operating in a way that continuously allows vehicles right at the maximum weight the bridge can withstand to cross it every day, day after day. On a clear day, no problems might occur, but the moment strong winds or aging are added, it collapses.
Recognizing even the possibility of customer data being stolen via USB
Mr. Makoto Watanabe was fully aware that leaving the USB port accessible could allow an operator to remove data.
The fact that the USB ports are active creates the risk of an operator plugging in a USB drive and extracting data.
Furthermore, the guide states that the Information Systems Department should not decide on its own that “USB drives should be disabled because they are dangerous,” but should instead limit its role to communicating the magnitude of the risk to management.
The system side should not just say no because there is risk. Your job is to accurately convey the degree of that risk. Management makes the decision.
It is not inherently unreasonable for management to make the final decision on risk acceptance. However, if you strip away even the specialized department's authority to determine that something is "legally, contractually, or technically unacceptable," the Information Systems Department ceases to be a security management division and merely becomes a receptionist that records the degree of risk for sales activities.
Turning "breaking into" the customer's system into a sales weapon
During the training, the expression "drill a hole" was repeatedly used regarding sales related to connecting the customer's system with the last-mile system.
System integration is impossible unless we definitely weaken security. We both have to poke holes in our defenses.
Penetrate where other companies aren't doing it. As a small and medium-sized enterprise, you can definitely make a breakthrough there.
"We can use this in our sales pitch by saying we can integrate while bypassing a listed company's security."
System integration equipped with proper authentication, encryption, access control, connection time limits, and log monitoring is standard business activity. However, can a representative's mindset—described to employees as "breaching a listed company's security" or "creating a loophole"—be reassuring to client companies?
Security for Audits and Security for Customers
It is necessary to pass the audit. However, an attitude of simply avoiding detection during the audit turns security into a formality for maintaining a listing rather than protecting customers.
Even if the materials to be submitted to the auditor are in order, data can still be extracted via USB from actual devices. Even if access restrictions exist in the regulations, exceptional connections increase for sales purposes. Still, if the operation is just about formally satisfying the audit items, customer information is protected only on paper.
Public questions for Last One Mile, Inc.
- During the training, were the USB ports on the terminals used by operators disabled?
- Have you ever had customer data removed using USBs or other external media?
- Regarding the connection with the customer system, was the "opening a hole" operation explained in the training actually implemented?
- Did the Information Systems Department have the authority to reject sales opportunities for security reasons?
- Do the Board of Directors and the Audit and Supervisory Committee evaluate the remark, "Even if it passes an audit, information leakage can still occur," as appropriate?
- After this training, did you review the information security policy, device management, access control, or external connection standards?
Stop the leak before it happens, rather than apologizing after it happens.
If a data leak occurs, the company can issue an apology, provide compensation, and announce recurrence prevention measures. However, it is impossible to completely recover leaked addresses, phone numbers, contract information, audio recordings, and identity verification information.
That is precisely why information security is different from normal business risk where "the company takes responsibility if a problem occurs."
Last Mile Inc. should set its standard not at the bare minimum that can withstand an audit, but at a level that can realistically protect customer information. If security is something that is weakened to the absolute limit for the sake of operating profit, the most dangerous entity for customers will not be external attackers, but the management that makes that decision.
President Makoto Watanabe's Corporate Training Series for Instilling Dangerous Ideologies Through Fear
- [1] "If the probability of being caught is 1%, then sell the customer list." CEO Makoto Watanabe taught the legal department about the probability of discovery and compliance.
- [2] “Delay Social Insurance Payments by One Month and Come Up with a Reason”: An Analysis of CEO Makoto Watanabe’s Labor Management Training
- [3] "Information leaks can still happen even if audits pass" CEO Makoto Watanabe's sales-oriented security theory
- [4] "Even if someone uses a company card at a bar, it's fine." CEO Makoto Watanabe's post-punishment internal control
- "It's okay if accounting is off by 10 million yen." CEO Makoto Watanabe's surprising number management taught to the accounting department.
- [6] "Now that we're listed, it's okay to make mistakes occasionally" CEO Makoto Watanabe's inverted internal control theory
- [7] “Take a Photo of Your Resume and Resignation Documents, Then Shred Them”: CEO Makoto Watanabe’s Approach to Personal Information Management
- [8] “Commission Will Be Consolidated Into Bonuses Once Every Three Months”: CEO Makoto Watanabe’s Plan to Reduce Labor Costs
- [9] "There is no one who is emotionally unstable," CEO Makoto Watanabe's view of employees shown to the HR department.
- "Getting Customers to Turn Right: CEO Makoto Watanabe's Emotion Marketing Training"
- [11] “Doctors Who Have Worked for Over 10 Years Are Specialists”—Is CEO Makoto Watanabe’s Advertising Training Okay?
- [12] 35 Controversial Statements by CEO Makoto Watanabe: “Probability of Detection Compliance” Revealed Through 7 Training Sessions
- [Overall Review] Isn't the biggest management risk Watanabe Makoto himself? Dangerous management philosophy of a listed company CEO seen from 7 training videos
