| 会社名 | JNSA Architects, Inc. |
|---|---|
| 年商 | JPY 3.4 billion |
| 従業員数 | 170 |
| 主要事業 | PC online game development and operation |
| 主要システム | GanGan system (2M users, 100K paying, JPY 2B revenue last year, AWS Japan region) |
| 企業文化 | - No prior incident response experience. - Tends to view security incidents optimistically. - Cultural divide between founding members (Executive Takahashi) and those with a banking background (Executive Managing Director Sasaki). |
The final decision-maker for the entire company. Responsible for balancing business continuity, social responsibility, and shareholder value. In the event of an incident, responsible for determining the company-wide response policy, final approval of external communications, and reporting to the board and key stakeholders.
P&L owner of the core business. Revenue and KPI achievement are the top priority. During an incident, provides business-perspective input on minimizing revenue impact from service outage, preventing customer churn, and recovery prioritization.
Head of a relatively small business with influence over organizational culture. During an incident, provides risk-focused advice and an internal-control perspective on restoring morale and trust.
Head of the management division overseeing finance, legal, and HR. During an incident, responsible for financial impact assessment, provisioning decisions, legal risk management, regulatory compliance, and compensation policy.
Head of the overall IT infrastructure. Prioritizes availability and stable operations. During an incident, responsible for technical containment, recovery planning, system shutdown decisions, and technical briefings to management.
Operational lead for technical incident response. Responsible for initial response, forensics management, IOC analysis, and designing preventive measures. Provides accurate technical facts to management.
External risk management expert. Advises the CEO from a second-line position. Responsible for assessing the validity of management decisions, providing advice based on international standards, and checking the appropriateness of external communications.
Responsible for personal data protection and compliance with GDPR and similar regulations. Responsible for determining whether a breach has occurred, reporting to regulators, and confirming the legal validity of victim notifications.
Head of all system development. During an incident, responsible for assessing impact on the development environment, deciding on release halts, and re-adjusting modification schedules.
Operational lead for system operations. Leads server isolation, backup verification, and recovery operations.
Independent director responsible for governance oversight. Evaluates the appropriateness of management's response, accountability, and governance standards.
Director who oversees management decisions from an objective standpoint. Evaluates the rationality of risk response and the appropriateness of internal controls.
Responsible for overseeing accounting and internal controls. Audits financial impact, provisioning treatment, and the effectiveness of internal controls.
Contact for a major advertising client. Concerned about the impact of service outages and brand damage on advertising effectiveness; has influence over the decision to continue placing ads.
Contact for investors and analysts. Responsible for capital market disclosure and accountability, working with management and finance on investor relations.
Contact at the cyber insurer or broker. Supports confirmation of policy applicability, claims processing, and evidence gathering.
Primary contact for supervisory authorities and data protection agencies. Confirms reporting requirements and deadlines, and coordinates with authorities.