Published on 05 Oct 2026

What can we learn from cyber risk incidents to strengthen corporate resilience?

by Simon Ong Jia Jun, Sua Jia Ren Addison and Shinichi Kamiya

On 29 September 2025, Asahi Group Holdings (‘Asahi’) was hit by a major cyberattack that broke into its computer systems in Japan and East Asia. The attack took down core systems, badly disrupting production and deliveries and even delaying the company’s financial reporting. Cleaning up and returning to normal took months—a sign of the serious and wide-reaching nature of the attack. Table 1 presents these key numbers at a glance.

Table 1: Summary of key numbers

Key Numbers at a Glance
Market capitalisation dropped by ~7% (~¥164 billion).
Revenue in Japan and East Asia dropped by 3.7% from Financial Year (FY) 2024 to FY2025.
Core operating profit in Japan and East Asia dropped by 16.1% from FY2024 to FY2025.
November 2025 monthly sales of Asahi’s flagship product, Super Dry Beer, fell by 25% year-on-year (YoY) compared with November 2024.
More than 1.5 million pieces of personal information and records were exposed.
Release of financial results for FY2025 was delayed for more than six months. FY2025 results were eventually published on 8 July 2026.

To measure the financial hit, we tracked how Asahi’s share price moved around the attack after stripping out normal market swings—what analysts call the ‘abnormal return’. In the one-, two- and five-day windows around the announcement, Asahi’s shares lagged on the market by 2.28%, 2.54% and 2.76%, respectively. These gaps are small, and statistically they cannot be separated from Asahi’s normal day-to-day price movements; the wider windows look worse mainly because they add up to more trading days. In other words, the stock market did not react in a clearly measurable way.

The hit on day-to-day operations was far bigger. The attack forced Asahi to stop shipments, delay production and switch to manual processes just to keep running. The timing made it worse: the disruption ran straight into the November–December holiday season, the busiest time of year for beer in Japan. In Japan and East Asia, revenue fell by 3.7% and core operating profit fell by 16.1% from FY2024 to FY2025. November 2025 monthly sales of Asahi’s flagship product, Asahi Super Dry, dropped sharply by 25% compared with November 2024—a major reason for the lower revenue and profit.

In short, the financial and operational pictures point in different directions. The share price barely moved, but the operational damage was deep and costly for Asahi. Over the following months, though, Asahi’s performance did weaken—its returns and risk-adjusted returns were worse after the attack than before, even as its main rivals’ shares rose—showing that a market reaction too small to be ‘statistically significant’ can still accompany a real loss of value: about ¥164 billion, roughly 7% of Asahi’s market value.

The incident also shows why strong risk management and board oversight matter. Asahi’s own risk management and governance did not prevent the attack: despite a framework on paper—group-wide security standards, subsidiary checks and incident-reporting procedures—attackers still broke in and halted operations, exposing gaps in access control, monitoring and detection, and internal-control design.

Asahi’s response—establishing an Emergency Response Headquarters (ERH), leaning on its business-continuity plans and tightening security (for example, adopting a ‘zero-trust’ model that trusts no user or device by default)—shows how a company’s governance shapes how well it handles a crisis. Boards and executive teams also need members who genuinely understand cybersecurity, so they can oversee this risk properly and make better-informed decisions.

The Asahi case offers other companies five practical lessons. First, a calm stock price can hide serious operational damage, so firms should judge an attack on more than their share price reaction. Second, cyber risk is a company-wide business risk, not just an information technology (IT) problem. Third, risk frameworks only help if the controls and recovery plans behind them actually work when tested. Fourth, cyber insurance bears limitations, and firms cannot fully depend on it to recover all costs. Last, it is important that firms ensure that their leaders are equipped with cyber technical knowledge to remain resilient in managing cyber risk. Companies that build cyber risk into their everyday risk management are far better placed to limit the damage when an attack hits.

--

Read the complete executive results on our published papers here.