- #Security measures
- #securitygovernance
- #InformationSecurity
- #DX
- #EMOROCO CRM Lite
- #CreativeCRM
- #Arcus Japan
- #CRM4.0
- #Corporate Psychology
- #Corporate Psychology
- #CRMDoctor
- #CRM・xRM
- #EMOROCO
- #Artificial Intelligence/Machine Learning (AI/ML)
- #Customer/Sales Strategy (SFA)
- #Customer Service Call Center (CS)
- #Marketing Automation (MA)
- #CustomerExperience
- #HAVE
- #Field Service (FS)
- #CRM
Japanese companies' customer information is being targeted from all over the world — Why you should protect it with CRM now
Hello, this is Matsubara, CRM Evangelist.
"A company like ours could never be a target of a cyberattack."
—There are quite a few business owners who think that way.
However, looking at the actual data, this assumption is quite dangerous.
This time, we will organize the reality of cyber threats surrounding Japanese companies with statistical data from public institutions and explain how EMOROCO CRM Lite's security features can address these threats.
table of contents
1. The reality of the threats surrounding Japanese companies
2. Why are small and medium-sized enterprises targeted?
3. What happens if customer information is leaked?
4. The danger of the assumption that "this doesn't concern us"
5. Why does implementing CRM contribute to security measures?
6. Security Features of EMOROCO CRM Lite
7. We do not use the phrase "absolutely safe."
8. Three preparations you can start today
9. Frequently Asked Questions (FAQ)
10. Summary
1. The reality of the threats surrounding Japanese companies
First, let's look at actual data published by public institutions, rather than relying on subjective opinions.
Ransomware attack
According to the National Police Agency, the number of ransomware attacks reported in 2025 (Reiwa 7) was 226, the second highest number on record, following the record high of 230 cases in 2022.
In the first half of 2025 alone, 116 cases of damage were reported, indicating that the situation remains at a high level.
Leakage of personal information
According to the Personal Information Protection Commission, the number of personal information leaks reported by companies and government agencies in fiscal year 2025 was 19,417, which was an 8% decrease from the previous year, but still the second highest number on record.
Furthermore, according to a survey by Tokyo Shoko Research, in 2025, there will be 180 reported cases of personal information leaks and losses by listed companies and their subsidiaries, affecting 30,636,910 individuals. This represents a threefold increase in large-scale incidents involving over one million people compared to the previous year.
Overall increase in security incidents
According to a survey by Cybersecurity Cloud, the number of security incidents reported by companies and organizations in 2025 is projected to be 165, an increase of approximately 1.4 times compared to 121 in 2024.
Sources: National Police Agency "Situation of Threats in Cyberspace in 2025", Personal Information Protection Commission "7 Annual Report", Tokyo Shoko Research survey, Cyber Security Cloud Co., Ltd. survey
2. Why are small and medium-sized enterprises targeted?
Some people might wonder, "Why are small and medium-sized enterprises being targeted, especially when it's not large corporations?"
However, a survey by the National Police Agency revealed that small and medium-sized enterprises account for approximately two-thirds of ransomware attacks (77 out of 116 cases in the first half of 2025).
The following are some of the reasons why small and medium-sized enterprises are being targeted:
• Investment in security measures tends to be less substantial compared to large corporations.
- In some cases, they are targeted as a "stepping stone" for attacks on large corporate business partners (supply chain attacks).
- For attackers, organizations with weaker defenses are easier to succeed with less effort.
The idea that "it won't be targeted because it's small" may actually mean the opposite: "it's easy to target."
3. What happens if customer information is leaked?
If a customer data breach actually occurs, the damage a company suffers is not limited to the leakage of the information itself.
• Time and cost involved in explaining and apologizing to customers
- Obligation to report to supervisory authorities and the risk of administrative guidance due to delays in response.
- Liability to compensate affected customers for damages
- Damage to existing relationships due to a decline in trust from business partners and customers.
- Damage to the company's image due to media coverage, etc.
The concept of "relational assetization," which I've explained on this blog so far, is about viewing relationships with customers as valuable assets.
Data breaches are one of the most undesirable situations, as they can cause significant damage to these assets in an instant.
4. The danger of the assumption that "this doesn't concern us"
The feeling that "this doesn't concern us" that many companies have stems from the following factors:
Customer information is scattered across Excel spreadsheets and personal computers, and the managers themselves do not know "what is where."
- Because they haven't experienced significant damage in the past, they may not fully grasp the risks.
- We feel that security measures are specialized and beyond our company's capabilities.
However, as actual damage data shows, small and medium-sized enterprises are also clearly targeted by attacks.
The very assumption that "this doesn't concern us" is the biggest factor causing people to postpone taking action.
5. Why does implementing CRM contribute to security measures?
Here's a perspective that might surprise you.
Implementing a CRM system is not just a means of improving sales efficiency; it also holds significant importance as a security measure.
When customer information is scattered across Excel spreadsheets, email attachments, personal computers, and multiple cloud services, the following problems can occur:
- The organization is unable to grasp where, what kind of, and how much customer information exists.
- Access permissions are managed inconsistently for each file and folder, making it difficult to control.
- There is a risk that customer information will remain on the computers and accounts of former employees.
Implementing a CRM and consolidating customer information into a single platform is the first step in creating a security governance system that allows you to control "what, who, and to what extent" can be handled.
6. Security Features of EMOROCO CRM Lite
EMOROCO CRM Lite includes the following features to support this information control:
- Permission management by security role and formDepending on the role, you can restrict the information displayed and the scope of actions that can be performed. For details, see below.Security Role and Form Permission Management Guide .
Validation settingsThis allows you to set rules for the values that can be entered, preventing incorrect entries and the registration of invalid data.
- Self-hosted deployment in an Azure environmentIf you do not want to store customer information in the cloud, you can operate it in your own managed environment. The operating platform (Azure) has obtained major security certifications such as SOC2.
API key authenticationWhen integrating with external systems, only authenticated access will be permitted.
Data portabilityIt supports the export of all data, avoiding the risk of "lock-in," where information is confined to a specific vendor.
These features consolidate scattered customer information into a single platform, providing a foundation for organizational control over "who has access to what and to what extent."
7. We do not use the phrase "absolutely safe."
There's something I'd like to tell you honestly.
No system can be guaranteed to be "absolutely secure" or "100% immune to attacks."
Cyberattack methods are constantly evolving, and the reality in the world of security is that perfect defense does not exist.
EMOROCO CRM Lite provides the foundation for a solution that allows for centralized information management, control of permissions, and the ability to switch to a self-managed environment as needed.
Building upon this foundation, organizational initiatives such as internal operational rules, employee training, and password management are necessary to create truly effective security measures.
Please understand that implementing a CRM is not the entirety of security measures, but rather an important part of them.
8. Three preparations you can start today
You don't need to implement all the major measures at once. I recommend starting with these three things.
1. Inventory where and how much customer information is currently scattered.
2. Develop a plan to consolidate scattered information into a centralized management platform such as a CRM.
3. Design access permissions according to roles, considering this simultaneously with CRM implementation.
These are preparations you can start working on today, even without a large budget or specialized knowledge.
9. Frequently Asked Questions (FAQ)
Q. Can implementing a CRM system completely prevent cyberattacks?
No.
While implementing CRM provides an important foundation for information control, it does not completely prevent cyberattacks.
This needs to be combined with organization-wide initiatives such as employee training and password management.
Q. Is it really possible that small and medium-sized enterprises could also be targeted?
Yes.
According to statistics from the National Police Agency, small and medium-sized enterprises account for approximately two-thirds of ransomware attacks.
Smaller companies tend to have weaker security measures in place, making them more vulnerable to attacks.
Q. I'm worried about storing customer information in the cloud. What should I do?
EMOROCO CRM Lite also supports self-hosting, allowing you to operate it in your own managed environment.
Q. I'm already using Excel for customer management, is that still risky?
If the encryption and access restrictions on the Excel file itself are weak, there is a risk of information leakage due to loss of the computer or unauthorized access.
We recommend considering migrating to a platform that allows for control over access permissions.
10. Summary
As statistical data shows, the cyber threats surrounding Japanese companies are not something that can be ignored.
Given that small and medium-sized enterprises account for the majority of the damage, the biggest risk is the misconception that "this doesn't concern us."
Having a platform that allows for centralized management of customer information and control of access permissions is a crucial foundation for security measures.
EMOROCO CRM Lite offers this foundation at an affordable price of 1,500 yen per month.
EMOROCO CRM Lite costs ¥1,500 per user per month (minimum 3 users) and has no initial setup fee, with a 30-day free trial.https://www.emoroco.com/You can start from there.
IT implementation subsidy eligible tool number: DL07-0022934.
We also offer a monthly newsletter, "ARCUS NEWS," which provides updates on EMOROCO CRM Lite and other useful information for CRM operations.
If you likeCLICK HEREPlease register here.
Additionally, we publish useful articles about CRM 4.0 on note ( https://note.com/arcuss_crm ), so please check them out as well.
Related article
Related articles and pages
Person who wrote this article
Articles in the same category
-
CRM Usage Guide for Advertising Agencies — Centralizing Clients and Projects […] -
A CRM Usage Guide for Travel Agencies — Using travel history and preferences to make the next proposal […] -
How to interpret the breakdown of CRM initial costs — How to avoid mistakes in quotes […] -
Differences between CRM 4.0 and personalization -
How to utilize customer data in the AI era — "Quality over quantity" is more important than ever before […] -
[EMOROCO CRM Lite Feature Introduction] Part 8: Relay System […]



