BIGLOBE Inc.
Japan · www.biglobe.co.jp · 15 vendors
BIGLOBE Inc. is a Japanese internet service provider and IT company that delivers networking services, content, and applications to residential and business users nationwide. The company offers a variety of internet connection services, including broadband connectivity and mobile services, along with digital content and platform services.
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- ActiveGate Co., Ltd. — Japan
- BIGLOBE Inc. — Telecommunications — Japan
- The Apache Software Foundation — Technology — United States
- and 13 more
Services catalogue
2 services in catalogue across 2 categories; runs on 15 sub-vendors.
- BIGLOBE CDN
- Internet Service Provider / Web Hosting
Insights
Last updated 2026-07-11 · revision 7
15 direct vendors, 236 subvendors
Direct vendors by controlling owner country (sample)
- United States: 9
- Denmark: 1
- Poland: 1
Subvendors by controlling owner country (sample)
- Canada: 7
- Germany: 5
- Ireland: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
BIGLOBE Inc. exhibits a high level of technical migration readiness, largely due to its existing highly cloud-native and multi-cloud architecture. The company's extensive use of AWS and Google Cloud, coupled with serverless computing (AWS Lambda, Amazon ECS, AWS Fargate), containers, Infrastructure as Code (IaC), GitOps, and CI/CD automation, signifies a mature cloud adoption strategy. This technical foundation means that BIGLOBE has already undergone significant modernization and possesses the expertise and flexible architecture required for further migrations or platform evolutions. The widespread adoption of containerization and serverless technologies ensures applications are likely decoupled and portable, facilitating efficient movement across different cloud services or environments. Automated infrastructure management via IaC and GitOps further reduces migration effort and risk. Financial stability, backed by KDDI, ensures resources are available for funding any necessary migration projects. Despite high technical readiness, significant challenges and constraints exist. Japan's Personal Information Protection Act (PIPA) and telecommunications regulations impose strict data residency and sovereignty requirements, mandating that personal data of Japanese residents and critical telecommunications infrastructure data generally remain within Japan. This severely limits options for migrating data or services to offshore cloud regions, even within existing cloud providers. Any migration strategy must meticulously adhere to these complex regulatory requirements, and potentially GDPR, adding considerable planning and audit overhead. The 'Vendor lock-in risk: Unknown' also presents an area of uncertainty, although the multi-cloud strategy inherently mitigates lock-in to a single major cloud provider.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
BIGLOBE Inc. is one of Japan's largest ISPs and provides cloud-adjacent services, web services, and enterprise IT solutions. As a provider of internet infrastructure and business services, SOC 2 compliance is highly relevant, particularly for enterprise and B2B customers who may require assurance over security, availability, and confidentiality controls. The risk is Medium because: (1) BIGLOBE's enterprise customers may contractually require SOC 2 reports; (2) absence of SOC 2 certification could be a competitive disadvantage in enterprise markets; (3) the recent unauthorized access incident to BIGLOBE email (June 2026) highlights the importance of formal security controls assurance. However, SOC 2 is a US-origin framework and Japanese companies often use equivalent Japanese standards (e.g., ISMS/ISO 27001) instead.
Evidence: https://www.biglobe.co.jp/service, https://www.biglobe.co.jp/outline
Cybersecurity Basic Act — Assessment Required
Japan's Cybersecurity Basic Act and associated guidelines from the National center of Incident readiness and Strategy for Cybersecurity (NISC) are directly applicable to BIGLOBE as a critical information infrastructure provider. The risk is High because: (1) ISPs are designated as critical information infrastructure operators in Japan; (2) BIGLOBE must implement cybersecurity measures aligned with NISC guidelines; (3) The June 2026 unauthorized access incident to BIGLOBE email demonstrates active cybersecurity threats; (4) Critical infrastructure operators face heightened scrutiny and reporting obligations; (5) BIGLOBE's role in Japan's internet infrastructure makes cybersecurity failures a matter of national security concern.
Evidence: https://www.biglobe.co.jp/sustainability, https://www.biglobe.co.jp/pressroom/release/2026/06/260623-a, https://style.biglobe.co.jp/entry/2024/08/06/100000
Telecommunications Business Act — Assessment Required
The Telecommunications Business Act is the primary sector-specific regulation governing BIGLOBE's core business as a registered telecommunications carrier in Japan. The risk is High because: (1) BIGLOBE operates as a Type II telecommunications carrier (ISP) and must maintain registration and comply with all operational requirements; (2) The Act mandates strict confidentiality of communications, prohibiting unauthorized interception or disclosure of user communications; (3) The June 2026 unauthorized access to BIGLOBE email services may constitute a violation of communication secrecy provisions under Article 4 of the Act; (4) The Ministry of Internal Affairs and Communications (MIC) actively enforces this Act and can revoke operating licenses for serious violations; (5) 2022 amendments introduced new obligations for large ISPs regarding transparent data handling and external transmission of user data.
Evidence: https://www.biglobe.co.jp/outline, https://www.biglobe.co.jp/pressroom/release/2026/06/260623-a, https://www.biglobe.co.jp/pressroom/release/2026/07/260706-a
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
BIGLOBE Inc. benefits from strong financial resilience primarily through its status as a 100% wholly-owned subsidiary of KDDI Corporation since January 2017. This parent backing provides access to group financing, shared network infrastructure, and cross-selling opportunities with au/UQ mobile bundles combined with BIGLOBE Hikari fiber broadband, which significantly reduces standalone liquidity risk. The company's recurring subscription-based revenue model through its ISP (BIGLOBE Hikari via NTT fiber wholesale) and MVNO (BIGLOBE Mobile on au network) services produces predictable ARPU-based cash flows. As of the last standalone-disclosed period (FY2015/2016), BIGLOBE generated revenue of approximately ¥68-70 billion with mid-single-digit-billion yen operating income, indicating a profitable operational base at the time of the KDDI acquisition. However, resilience is tempered by several structural risks. Japan's consumer fixed-line broadband market is mature and highly commoditized, with margin pressure from competing offerings including NTT Docomo's docomo Hikari, SoftBank Hikari, and even KDDI's own auひかり (creating potential intra-group cannibalization). Government-driven mobile price cuts in 2020-2021 and the introduction of MNO sub-brands (ahamo, povo, LINEMO, UQ Mobile) have compressed MVNO margins industry-wide. Additionally, BIGLOBE has significant wholesale cost dependency on NTT East/West for FTTH and on KDDI for mobile network access. The absence of standalone audited financials since 2017 limits external credit assessment transparency, though creditors typically rely on the KDDI parent relationship. Recent cybersecurity incidents involving unauthorized access to BIGLOBE mail services present reputational risks in a subscription-driven business model.
Key strengths: 100% ownership by KDDI Corporation (TSE Prime: 9433) providing parent backing, Recurring subscription revenue from ISP and MVNO services, Established brand with ~30 years in Japanese consumer internet market, Cross-selling opportunities with au/UQ mobile bundles, Diversified adjacencies including points/rewards (G-PLAN), portal & media, and corporate solutions, Approximately 3 million ISP subscribers at time of KDDI acquisition
Risk factors: Mature and commoditized Japanese consumer broadband market, MVNO margin squeeze from government-driven mobile price cuts and MNO sub-brands, Wholesale cost dependency on NTT East/West and KDDI, Potential intra-group cannibalization with KDDI's auひかり, Limited standalone financial transparency since 2017, Cybersecurity exposure - multiple 2026 unauthorized access incidents on BIGLOBE mail service, Reputational risk in subscription-based business
Revenue by geography
- Japan: 100%
Workforce by country
- Japan: 1100
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.