Monex Group provides digitally enabled financial services globally, including online brokerage, crypto asset, and asset and wealth management services. As a financial group entrusted with customers’ sensitive information and assets, we recognize that strengthening cybersecurity is fundamental to enabling customers to transact with confidence and is a critical priority directly linked to business continuity, customer protection, and the preservation and enhancement of corporate value.
In recent years, cyberattacks worldwide have become increasingly sophisticated and complex, driven in part by advances in generative AI and other technologies. Because the Group operates a diverse range of businesses in Japan and overseas—including securities, crypto asset, and asset and wealth management businesses—comprehensive measures extending across business lines and regions are essential. The Group continuously strengthens its cybersecurity measures through a risk-based approach, with reference to the Financial Services Agency’s Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc., and the Special Publication 800 series issued by the U.S. National Institute of Standards and Technology (NIST).
We are creating a global system for responding to events and reducing damage arising due to cyberattacks throughout the entire Monex Group. Centered on the Monex Group CSIRT (Computer Security Incident Response Team) established within the Monex Group, CSIRTs have also been established in Monex Group companies. Through cooperation between the Monex Group CSIRT and the CSIRTs in group companies, we are strengthening governance and CSIRTs in each company perform the functions for protecting the operations, information assets and systems of as we promote cybersecurity measures along the four axes of organizational operation, system response, human response and external collaboration. The status of relevant cases handled by cybersecurities is reported on a monthly basis to the Board of Directors, and they are subject to the oversight by the Board.
We are continuously striving to strengthen day-to-day information security measures by utilizing intelligence from external specialist institutions and monitoring cybersecurity. In addition, we are performing analysis and taking steps to minimize damage and quickly recover from damage. CSIRTs play a central role in the acquisition of information on dangerous threats and the analysis of causes, the minimization of damage and responses for rapid recovery in the event of an “emergency” when a cyberattack is detected.
We implement measures in multiple stages (multi-layer defense) such as implementing multiple mechanisms for detecting and defending against unauthorized access and malicious programs such as computer viruses. In addition, these measures are reviewed as appropriate to address the occurrence of new threats.
We are endeavoring to improve information security literacy by constantly implementing training and drills for directors, employees, contract employees, and temporary staffs based on the Monex Group Information Security Basic Policy.
The Monex Group is building a system for collecting and sharing information on vulnerabilities and threats, etc. through communication with Financials ISAC and information institutions in Japan and abroad.
To strengthen security in ways tailored to the characteristics of each business, Monex, Inc. is enhancing identity authentication, including by requiring passkey-based login, to address unauthorized access and transactions arising from phishing and similar schemes. It also collects and analyzes threat intelligence from the Japan Cybercrime Control Center (JC3). To reduce the risk of unauthorized crypto asset transfers, Coincheck stores most crypto assets held in custody in cold wallets disconnected from the internet and continuously monitors and manages its hot wallets.
For details of the security initiatives undertaken by each Group company, please refer to the links below.
Monex Securities
Monex Group has internal policies and streamlined operation based on the policy to keep our customers’ information safe. Our Code of Conduct and Ethics and Compliance Code of Conduct policies include specific guidelines about how Officers and Employees should safeguard customers’ information. Data privacy is regularly reported at multiple Group-level governance forums, which include Board level representation to help ensure appropriate challenge and visibility among senior stakeholders. We are also investing in machine learning and intelligent strategies to improve detection and mitigation of fraud across our products and services. Monex Group will review and enhance the personal information protection management system on a continuing basis. In addition, we hold our suppliers and vendors to the same high standards for data security.
Monex Group is committed to protecting the privacy of data we hold and process, in accordance with the laws and regulations of the geographies we operate in. Our group companies are the first-hand entities to ensure that data privacy is handled and processed effectively to manage risks. For example, the entity in Japan, Monex Inc. and Coincheck, embed the requirements stated in the Act on the Protection of Personal Information legislated by the Japanese government. The Act is developed based on the OECD's Privacy Guidelines.
Our major group companies outside of Japan also have strict policies and processes to protect the privacy of data. TradeStation Group, Inc. operates an online securities and futures brokerage firm in the US that complies with the federal law and SEC and industry self-regulatory rules and regulations regarding privacy including the California Consumer Privacy Act of 2018 (CCPA) to cover the customer who reside in California. TradeStation Group also has an introducing broker based in London, England which processes personal data under the General Data Protection Regulation (“GDPR”). The subsidiary in Hong Kong, Monex Boom Securities Limited, operates its business in accordance with the Personal Data (Privacy) Ordinance of the Hong Kong Special Administrative Region.
Monex Group, Inc. (hereinafter referred as “the Company”) is fully aware that your name, address, e-mail address and other personal information are important to you. It also recognizes that your name, address, email address and other personal information are essential elements of your privacy. As a socially responsible company, we understand that proper handling of personal information of customers is an important management responsibility. All of our officers and employees are committed to protecting your personal information and respecting your privacy by complying with our internal rules and related laws and regulations regarding the handling of information.