NTTセキュリティホールディングス株式会社 (NTT Security Holdings)
Japan · owned by NTT株式会社 (NTT Inc.) (Japan) · www.security.ntt · 14 vendors
NTT Security Holdings is the core cybersecurity company of the NTT Group, providing proactive cyber defense services globally including threat intelligence analysis, consulting, managed security services, and incident response 24/7/365. The company leverages its Global Threat Intelligence Center and highly skilled security professionals to protect customers and society, aiming to be a 'Cyber Risk Mitigation Company'. It is headquartered in Akihabara UDX, Chiyoda-ku, Tokyo, with European operations based in Mölndal, Sweden.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Box, Inc. — Technology — United States
- Demandware — Technology — United States
- Zscaler, Inc. — Cybersecurity — United States
- and 11 more
Services catalogue
3 services in catalogue across 2 categories; runs on 14 sub-vendors.
- Biztrox
- HR Tech Consulting
- Talent Operations
Insights
Last updated 2026-04-13 · revision 2
14 direct vendors, 222 subvendors
Direct vendors by controlling owner country (sample)
- United Kingdom: 1
- United States: 10
- Canada: 2
Subvendors by controlling owner country (sample)
- Romania: 1
- Ireland: 2
- UK: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
NTT Security Holdings exhibits a high degree of migration readiness, primarily driven by its advanced and flexible technology architecture. The company's internal tech stack is predominantly cloud-native, utilizing a multi-cloud infrastructure across AWS, Azure, and GCP. This multi-cloud strategy inherently reduces vendor lock-in for core infrastructure and demonstrates a strong capability for agile deployment and migration between cloud environments. The use of AI-driven analytics engines and a high-volume SIEM pipeline further indicates a modern, scalable, and adaptable platform. The company's robust regulatory compliance (ISO 27001, SOC 2, GDPR, HIPAA) and demonstrated ability to manage diverse data residency requirements (including offering on-premise MDR deployments for strict local data needs) are significant advantages, as these factors often pose major challenges in large-scale migrations. Financial stability, as part of the NTT Group operating in a growing market, suggests the resources are available to fund strategic migration initiatives. Similar to resilience, the vendor data presents some inconsistencies. While "Total Vendors: 0" is listed, the tech stack includes platforms like Wix, GitHub, and Salesforce. While the multi-cloud approach mitigates cloud-specific lock-in, migration away from these specialized platforms could present some challenges, and the overall "Vendor Lock-in Risk" is explicitly stated as "Unknown." However, these are likely manageable dependencies compared to the flexibility offered by the core multi-cloud infrastructure. The overall modern architecture, compliance maturity, and experience with data residency position NTT Security very well for future migrations.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
As a cybersecurity services provider offering managed detection and response (MDR) and security monitoring services, SOC2 compliance is critical for demonstrating security controls to customers. The cybersecurity industry typically requires SOC2 Type II reports for vendor assurance. Lack of SOC2 compliance could significantly impact customer acquisition and retention in the enterprise market.
Evidence: https://www.security.ntt
Japan Cybersecurity Basic Act — Assessment Required
As a cybersecurity services provider in Japan, NTT Security Holdings may be subject to cybersecurity regulations under Japan's Cybersecurity Basic Act, particularly if they provide services to critical infrastructure operators. The risk is medium as compliance requirements depend on specific customer base and service types.
Evidence: https://jp.security.ntt
ISO 27001 (source) — Assessment Required
ISO 27001 certification is industry standard for cybersecurity companies to demonstrate information security management capabilities. As a provider of security services to 1,500+ enterprise customers, ISO 27001 certification would be expected by customers and is often a requirement for enterprise contracts. Lack of certification could impact competitive positioning and customer trust.
Evidence: https://www.security.ntt
Financials
Three-year financials
- 2024: equity ¥6,929M (Holdings) / ¥5,127M (NTT Security Japan)
- 2023:
- 2022:
Financial Resilience Score: 6/10
NTT Security Holdings benefits from the full financial backing of NTT, Inc., one of the world's largest telecoms and IT groups with revenues exceeding ¥13 trillion. This parent relationship provides access to group treasury facilities (confirmed via NTT Finance short-term borrowing of ¥2,090 million), a captive intra-group revenue base, and implicit credit support that substantially reduces the risk of financial distress. The operating subsidiary, NTT Security Japan, is demonstrably profitable with net income of ¥1,629 million in FY2024 and paid a ¥3,000 million dividend to Holdings, indicating strong underlying cash generation at the operational level. The group also benefits from structural tailwinds in the cybersecurity market, proprietary threat intelligence assets (GTIC, 800B+ logs/month), and a long operating history of over 20 years in managed security services. However, the Holdings entity itself recorded a net loss of ¥1,371 million in FY2024 with an accumulated retained earnings deficit of ¥924 million. A large deferred tax asset valuation allowance of ¥2,449 million was applied, signalling uncertainty about future taxable income at the Holdings level. The equity ratio of approximately 31.6% at both entities, combined with a Holdings-level debt-to-equity ratio of approximately 2.2x (though largely composed of intercompany payables rather than external debt), indicates a moderately leveraged structure that is manageable given group support but would be concerning on a standalone basis. Revenue concentration is a meaningful risk: the vast majority of revenue at both Holdings and NTT Security Japan flows through NTT Group wholesale contracts, creating dependency on internal procurement decisions and transfer pricing policies. An unresolved contract dispute with sibling entity NTT Security Corporation over applicable FX rates — only settled in April 2025 — illustrates governance complexity in intra-group pricing and currency risk from European subsidiaries. The short-term nature of all borrowings (no long-term debt) creates refinancing risk, though this is mitigated by the group treasury relationship. Financial transparency is severely limited: no consolidated P&L, EBIT, cash flow statement, or segment breakdown is publicly available. Income statements are not disclosed in Japanese statutory filings for private companies, making independent assessment of revenue trends, margins, and true geographic or product mix impossible from public sources alone. This opacity constrains the score despite the strong operational and strategic fundamentals.
Key strengths: 100% ownership by NTT, Inc. (¥13+ trillion revenue parent) providing implicit financial support and group treasury access, NTT Security Japan profitable with ¥1,629M net income and ¥3,000M dividend paid in FY2024, Confirmed NTT Finance short-term borrowing facility (¥2,090M outstanding), Captive intra-group revenue base providing revenue stability and predictability, Proprietary GTIC threat intelligence platform processing 800B+ logs/month — difficult-to-replicate asset, Strong sector tailwinds: ransomware incidents up 67% in 2023, structural growth in MDR/MSS demand, Equity ratio of ~31.6% at both Holdings and NTT Security Japan, Software investment of ¥1,997M at Holdings level reflecting ongoing Samurai MDR platform development
Risk factors: Holdings entity net loss of ¥1,371M in FY2024 with accumulated retained earnings deficit of ¥924M, Deferred tax asset valuation allowance of ¥2,449M signalling uncertainty about Holdings-level future taxable income, Holdings debt-to-equity ratio of approximately 2.2x (total liabilities ¥15,028M vs net assets ¥6,929M), Intra-NTT Group revenue concentration — majority of revenue dependent on NTT Group internal procurement decisions, No publicly available consolidated income statement, cash flow statement, or segment data, All borrowings are short-term (¥2,090M from NTT Finance) with no long-term debt — refinancing dependency on group treasury, Unresolved FX rate contract dispute with NTT Security Corporation (sibling) only settled April 2025 — illustrates intra-group governance and currency risk, European subsidiary currency translation risk (Sweden SEK, Netherlands EUR)
Revenue by geography
- Japan (NTT Security Japan intra-group wholesale): 60%
- NTT Parent wholesale: 31%
- Europe - Sweden (NTT Security Sweden AB): 6%
- NTT Security Corp. sibling: 2%
- Europe - Netherlands (NTT Security Netherlands B.V.): 1%
Revenue by product/service
- OT Security: 0%
- Security Consulting: 0%
- IoT Product Security: 0%
- Supply Chain Security: 0%
- Incident Response & Investigation: 0%
- Security Diagnostics & Assessment: 0%
- Managed Detection & Response (MDR) / Managed Security Services: 0%
Workforce by country
- Japan: 330
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.