Toshiba Publishes English Edition of Cyber Security Report 2026
-Strengthening cyber resilience to address the growing sophistication and complexity of cyber threats in the generative AI era-
August 31, 2026
Kawasaki, Japan—Toshiba Corporation has released the English edition of the Toshiba Group Cyber Security Report 2026, outlining the Group’s cybersecurity policies, initiatives, and activities for fiscal year 2025.
As cyber threats continue to evolve, their scope has expanded into many areas, including control systems and industrial equipment. Ransomware attacks, targeted attacks, and supply chain-based threats are increasingly disrupting corporate activities and critical social infrastructure. At the same time, advances in generative AI are transforming the cybersecurity landscape. While AI accelerates cybersecurity defenses by enabling more advanced threat detection, analysis and automation, it is also being exploited by attackers to accelerate the discovery of vulnerabilities, phishing campaigns, impersonation attacks, and malware generation with greater sophistication, speed and scale. As a result, the cybersecurity environment is becoming increasingly complex. Toshiba Group is responding by advancing a strategy built around the concept of cyber resilience to protect its information and control systems, and the products, systems and services it provides.
The report highlights key initiatives to strengthen cyber resilience, including mitigating supply chain security risks and addressing AI security risks.
As security risks originating in supply chains increase, ensuring security across the entire supply chain is more important than ever. Alongside longstanding initiatives—including distributing security guidelines to suppliers and conducting security assessments before and during business engagements—Toshiba Group mitigates supply chain security risks by leveraging the visualized risk information from "attack surface assessment*," which objectively evaluates security levels.
The growing adoption of AI has also introduced new security challenges, including malicious attacks against AI systems, misuse of AI technologies, and information leakage. Toshiba Group addresses these risks by systematically promoting AI risk management that assesses risk from the earliest stages of AI system planning and development, and that incorporates results into design and operational measures. Through appropriate risk evaluation and the implementation of specialized countermeasures, the Group develops, provides, and operates AI systems that customers and society can trust.
Toshiba Group remains committed to transparency and stakeholder engagement. Through its cybersecurity website and future editions of the cybersecurity report, the Group will continue to share detailed information on its cybersecurity policies, strategies, and specific initiatives to strengthen security and resilience.
*Note: An attack surface assessment is an initiative that uses tools to detect the status of security measures and patch management practices for externally accessible networks, servers, and applications. The assessment helps to identify vulnerable points in information assets exposed to the Internet and to visualize security levels.
■ Toshiba Group Cyber Security Report 2026
https://www.global.toshiba/ww/cybersecurity/corporate/report.html
■ Toshiba Group Cyber Security Website
https://www.global.toshiba/ww/cybersecurity/corporate.html

