Culture & governance
Digital trust depends on disciplined everyday practice.
Marketing teams handle client accounts, audience data, advertising platforms, creative assets and commercial information. Access must be purposeful, controlled and reviewable.
Explore careers →In plain language
Cyber security at Orix is the practical protection of systems, identities, devices, communications and data against unauthorized access, misuse, disruption or loss.
Access and authentication
Access and authentication
Shared credentials should be avoided. Strong authentication, current permissions and timely removal of unnecessary access reduce preventable exposure.
Phishing and payment fraud
Phishing and payment fraud
Unexpected login, payment, banking or confidential-data requests must be verified through a trusted second channel before action.
Incidents and suppliers
Incidents and suppliers
Lost devices, account compromise, malicious messages or unauthorized disclosure should be escalated promptly. Vendors handling sensitive information require appropriate review.
Policy FAQ
Questions people may ask.
These summaries explain the policy in accessible language. Applicable law, contract and formal internal procedures continue to govern specific situations.
What should I do after a suspicious message?
Do not use its links or attachments. Preserve the message and report it through the appropriate Orix contact for verification.
Does the policy apply to client platforms?
Yes. Client-provided accounts and data require the same or stronger care as Orix-controlled systems.