Executive Summary
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<p>Japan’s Active Cyber Defense (ACD) framework shifts the country from voluntary information sharing and post-incident investigation to mandatory reporting, preventive communications analysis, and limited disruption of attack infrastructure. Beginning October 1, 2026, designated critical infrastructure operators must notify the government about covered systems and report qualifying incidents; those with existing systems have six months to submit initial notifications. New authorities that allow the government to collect and act on communications information (通信情報) will not take effect until November 23, 2027.</p>
<p>The transition comes amid persistent Chinese strategic collection, North Korean revenue-driven cyber operations, and Russian cyber espionage. In cases directly linked to Japan, indicators related to these threat activities were frequently observed among victims, overseas affiliates, vendors, carriers, hosting providers, and government agencies. We assess with moderate confidence that connecting those indicators quickly enough to identify broader campaigns, warn potentially affected organizations, and coordinate defensive action will be ACD’s principal operational constraint. Its practical reach will extend beyond designated operators: overseas compromises may trigger Japanese reporting duties when they reach covered systems; vendors should expect remediation requests; carriers may be required to assist government measures; and hosting providers may encounter action against malicious systems operating on their infrastructure.</p>
<p>We further assess that improved visibility within covered organizations will likely make foreign subsidiaries, non-designated suppliers, employees, and external platforms comparatively attractive access paths for threat actors without reducing overall attack volume (because initial activity along these routes likely falls outside ACD’s mandatory-reporting perimeter or precedes recognition of a qualifying incident). Companies should therefore treat ACD not as a narrow compliance requirement, but as a change to incident escalation, contracting, evidence preservation, and public-private intelligence sharing across their operations and supply chains.</p>
<h2>Key Findings</h2>
<ul>
<li>Japan’s Active Cyber Defense is a two-statute framework — Acts 42 and 43 of 2025 — organized around four principal pillars: public-private collaboration, government use of communications information, access and neutralization of cyber threats, and institutional restructuring and independent oversight. Act 42 establishes the reporting, information-sharing, communications-analysis, and oversight framework, while Act 43 amends existing laws to authorize neutralization measures and reorganize Japan’s cybersecurity institutions.</li>
<li>Japan's mandatory cyber incident reporting begins October 1, 2026, but the government's communications-information collection capacity will not enter force until November 23, 2027 — a gap of roughly 13 months between the reporting duty and the detection capability intended to support it.</li>
<li>Japanese agencies recorded an eleven-fold increase in cyberattack-related packets from 63.2 billion in 2015 to 686.2 billion in 2024, while 99.4% of observed attack packets used overseas source IP addresses. This is equivalent to roughly one attempted attack per IP address every thirteen seconds.</li>
<li>Chinese, Russian, and North Korean cyber operations targeting Japan reflect distinct primary drivers: China pursues enduring strategic intelligence collection, North Korea prioritizes sanctions-driven revenue generation, and Russia combines standing espionage requirements with disruption that can track Japanese policy decisions.</li>
<li>Threat actors will likely emphasize five access paths likely to maintain limited visibility under ACD after reporting begins on October 1, 2026: foreign subsidiaries, non-designated suppliers, individual employees, consumer platforms, and short-lived infrastructure distributed across hosting providers. Organizations occupying these positions may consequently face greater targeting despite having no direct ACD reporting obligation.</li>
</ul>
<h2>Background</h2>
<p>Japan’s Active Cyber Defense framework (能動的サイバー防御, “ACD”) is a package of legal and institutional reforms intended to prevent serious cyberattacks against government and critical infrastructure. The ACD establishes mechanisms for public-private collaboration (官民連携), government use of specified communications information (通信情報の利用), and narrowly defined authority to access and neutralize systems being used to conduct cyberattacks (アクセス・無害化措置) before they cause significant harm or damage. The framework also restructures the government’s central cybersecurity institutions and establishes independent oversight of the framework’s most sensitive authorities.</p>
<p>The framework is principally established through two statutes passed by the National Diet (国会) on May 16, 2025, and promulgated on May 23, 2025:</p>
<ul>
<li><strong>Cyber Response Capability Strengthening Act (サイバー対処能力強化法), Act No. 42 of 2025</strong><br />Full statutory title: <em>Act on the Prevention of Damage from Unauthorized Acts against Important Computers</em> (重要電子計算機に対する不正な行為による被害の防止に関する法律).<br />This statute establishes the critical-infrastructure reporting, communications information use, public-private information-sharing, and independent oversight framework.</li>
<li><strong>Cyber Response Capability Strengthening Act Arrangement Act (サイバー対処能力強化法整備法), Act No. 43 of 2025</strong><br />Full statutory title: <em>Act on the Arrangement of Related Laws Accompanying Enforcement of the Act on the Prevention of Damage from Unauthorized Acts against Important Computers</em> (重要電子計算機に対する不正な行為による被害の防止に関する法律の施行に伴う関係法律の整備等に関する法律).<br />This companion statute amends existing legislation, including the Police Duties Execution Act (警察官職務執行法), Self-Defense Forces Act (自衛隊法), and the 2014 Basic Act on Cybersecurity (サイバーセキュリティ基本法). These amendments authorize access-and-neutralization measures, restructure the government’s cybersecurity institutions, and strengthen interagency coordination.</li>
</ul>
<p>Implementation is phased; the reorganization of the government’s central cybersecurity institutions took effect on July 1, 2025, and the independent Japan Active Cyber Defense Oversight Commission (サイバー通信情報監理委員会) was established on April 1, 2026. The public-private reporting and access-and-neutralization provisions will take effect on October 1, 2026. Supplementary Article 1(4) of Act No. 42 <a href="https://www.cas.go.jp/jp/seisaku/cyber_anzen_hosyo_torikumi/pdf/houritsu.pdf" rel="noreferrer" target="_blank">requires</a> the communications-information use provisions to enter force within two years and six months of promulgation, by November 23, 2027.</p>
<h2>The Four Pillars</h2>
<p>For explanatory purposes, this overview organizes the ACD framework into four principal pillars:</p>
<ol>
<li>Public-Private Collaboration (官民連携)</li>
<li>Government Use of Communications Information (通信情報の利用)</li>
<li>Government Access and Neutralization Measures (アクセス・無害化措置)</li>
<li>Institutional Restructuring and Independent Oversight (組織・体制整備・独立監督)</li>
</ol>
<p>Together, the pillars summarize the framework’s principal government authorities, institutional changes, oversight mechanisms, and legal obligations for public- and private-sector organizations. They reflect a fundamental shift in Japan’s cybersecurity posture toward earlier detection, structured public-private cooperation, and preventive disruption, while placing the framework’s most sensitive authorities under specialized independent oversight. They do not encompass every provision within the two statutes.</p>
<h3>Pillar 1 — Public-Private Collaboration (官民連携)</h3>
<p>Pillar 1 creates mandatory reporting requirements and a consent-based information-sharing framework. For ACD reporting purposes, “designated operators” (特別社会基盤事業者) are critical-infrastructure operators designated under the Economic Security Promotion Act that use covered systems — Specified Important Computers (特定重要電子計算機). These include qualifying operators in sectors such as electricity, telecommunications, transport, and finance. Designated critical-infrastructure operators must notify the responsible government minister when they introduce covered systems — Specified Important Computers — and report qualifying cyber incidents (特定侵害事象等) to that minister and the prime minister. The prime minister will establish a statutory council (協議会)for information sharing and countermeasures to prevent damage to Important Computers (重要電子計算機) — the law’s broader category of protected computer systems, including Specified Important Computers — from specified unauthorized acts. This statutory council will replace and strengthen the existing 2019 Cybersecurity Council (サイバーセキュリティ協議会). Council members may be required to provide relevant materials and must comply with statutory confidentiality requirements.</p>
<p>In practice, two things change under Pillar 1. First, ACD-specific reporting becomes a statutory duty for designated critical-infrastructure operators that use covered systems — including operators in sectors such as electricity, telecommunications, transport, and finance — thereby reducing the government’s dependence on voluntary disclosure once a qualifying incident is detected. Second, government-to-industry sharing enters a protected statutory framework designed to support the distribution of sensitive threat and mitigation information. Pillar 1, therefore, aims to give the government broader visibility into threats while providing participating organizations with actionable warnings. Joining the council is voluntary, but participating members must comply with statutory information-handling and confidentiality obligations and may be required to provide relevant materials.</p>
<h3>Pillar 2 — Government Use of Communications Information (通信情報の利用)</h3>
<p>Pillar 2 authorizes the government to obtain and analyze specified communications information through two principal pathways:</p>
<ul>
<li>Voluntary agreements with participating organizations (当事者協定)</li>
<li>Defined government measures involving certain foreign-related communications (国外関係通信)</li>
</ul>
<p>The latter includes foreign-to-foreign communications transiting Japan, as well as limited foreign-to-domestic or domestic-to-foreign communications associated with specified cyber threats. Before a government employee may review acquired data, automated selection (自動選別) must retain only defined mechanical information (機械的情報), such as IP addresses, timestamps, and command information, and delete the remainder. Government measures not based on consent generally require prior approval from the Japan Active Cyber Defense Oversight Commission.</p>
<p>In practice, two things change under Pillar 2. First, the government gains a standing statutory framework for obtaining and analyzing communications information for preventive cyber defense: Japan’s pre-ACD Communications Interception Act <a href="https://laws.e-gov.go.jp/law/411AC0000000137" rel="noreferrer" target="_blank">authorized</a> interception only for criminal investigations of specified offenses and pursuant to a judge-issued warrant, and Japan lacked a comparable framework for systematic preventive collection and analysis. Second, the limit on what may be retained is enforced by the collection architecture rather than by rules governing analyst conduct. Officials set the selection criteria, but no person may examine the acquired data before the selection is complete, and unselected material must be deleted immediately.</p>
<h3>Pillar 3 — Government Access and Neutralization Measures (アクセス・無害化措置)</h3>
<p>Pillar 3 establishes access-and-neutralization authority through amendments to the <a href="https://www.shugiin.go.jp/internet/itdb_housei.nsf/html/housei/21720250523043.htm" rel="noreferrer" target="_blank"></a><a href="https://www.shugiin.go.jp/internet/itdb_housei.nsf/html/housei/21720250523043.htm" rel="noreferrer" target="_blank">Police Duties Execution Act and Self-Defense Forces Act</a>. Specially designated Cyber Harm Prevention Measure Enforcement Officers (サイバー危害防止措置執行官) may order an administrator to take necessary measures against a computer associated with communications or electronic records identified as being used in malicious cyber activity, or may take those measures directly. Depending on the circumstances, those measures could include:</p>
<ul>
<li>Stopping or removing attack software</li>
<li>Disrupting malicious command-and-control communications</li>
<li>Changing system settings to prevent an attacker from continuing to control compromised infrastructure</li>
</ul>
<p>The authority applies when an urgent need exists to prevent serious harm to life, physical safety, or property. Measures generally require prior approval from the Japan Active Cyber Defense Oversight Commission. When circumstances leave no time for advance approval, a measure may proceed, but the Commission must be notified promptly afterward and confirm whether the measure was appropriate.</p>
<p>In practice, Pillar 3 gives designated officers legal authority to intervene against attack infrastructure — including through actions that could otherwise constitute unauthorized access under the 1999 <a href="https://www.shugiin.go.jp/internet/itdb_housei.nsf/html/housei/h145128.htm" rel="noreferrer" target="_blank"></a><a href="https://www.shugiin.go.jp/internet/itdb_housei.nsf/html/housei/h145128.htm" rel="noreferrer" target="_blank">Act on Prohibition of Unauthorized Computer Access</a> — rather than relying on criminal investigation or voluntary remediation. The authority can reach infrastructure outside Japan, but overseas operations are subject to additional restrictions. Police measures against systems not reasonably believed to be in Japan may be conducted only by officers of the National Police Agency (NPA) following consultation with the minister for foreign affairs. In cases involving highly organized and planned threats by a person outside Japan, the prime minister may order the Japan Self-Defense Forces (JSDF) to conduct Communications Protection Measures (通信防護措置) jointly with police, but only when the JSDF’s specialized technology or information is indispensable, and the National Public Safety Commission has requested or consented to JSDF involvement.</p>
<h3>Pillar 4 — Institutional Restructuring and Independent Oversight (組織・体制整備・独立監督)</h3>
<p>Pillar 4 restructures the government's cybersecurity institutions and creates an independent body to oversee the authorities established in Pillars 2 and 3. The reforms include:</p>
<ul>
<li>The National Cybersecurity Office (国家サイバー統括室, NCO) replaces the former National Center of Incident Readiness and Strategy for Cybersecurity (内閣サイバーセキュリティセンター, NISC).</li>
<li>A new cabinet cyber officer (内閣サイバー官) leads the NCO and coordinates cybersecurity policy across the government.</li>
<li>The restructured Cybersecurity Strategy Headquarters (サイバーセキュリティ戦略本部) is headed by the prime minister (内閣総理大臣) rather than the chief cabinet secretary, with all other ministers of state as members.</li>
<li>The Japan Active Cyber Defense Oversight Commission (サイバー通信情報監理委員会) grants prior approvals, conducts ongoing inspections, reviews emergency measures taken without advance approval, and may issue recommendations.</li>
</ul>
<p>In practice, two things change under Pillar 4. First, central coordination is elevated: the Strategy Headquarters is now chaired by the prime minister rather than the chief cabinet secretary, while the cabinet cyber officer and NCO support government-wide coordination. Second, the sensitive authorities in Pillars 2 and 3 are reviewed by a commission separate from the agencies implementing them. Rather than requiring judicial warrants, the framework uses independent administrative review: the Japan Active Cyber Defense Oversight Commission approves nonconsensual communications acquisition and ordinarily approves neutralization measures, conducts continuing inspections, and receives notification of emergency measures. It may issue recommendations and must report annually to the National Diet through the prime minister and publish a summary. Pillar 4 does not establish a separate offensive cyber authority; cross-border neutralization remains governed by Pillar 3.</p>
<h3>Key Limits on ACD Authority</h3>
<p>The ACD framework expands Japan’s preventive cybersecurity authorities but does not provide an unrestricted mandate for surveillance or offensive cyber operations. Its principal statutory boundaries include:</p>
<ul>
<li>Communications analysis is not general content surveillance. Human review is limited to automatically selected mechanical information, including technical data such as IP addresses, timestamps, and computer commands, meeting statutory criteria. Purely domestic communications are not a category that the government may target without the parties’ consent. If included in data provided under a Party Agreement (当事者協定), they must be excluded through automated selection and deleted without human review. Separate laws continue to govern warrant-based interception for criminal investigations.</li>
<li>Access and neutralization authority is tied to specific mission objectives outlined in the ACD, rather than blanket provisions for government operators. Measures must address communications or electronic records used or reasonably suspected of being used in malicious activity and must be urgently necessary to prevent serious harm to life, physical safety, or property. Overseas measures carry additional procedural and international-law requirements.</li>
<li>The JSDF cannot independently initiate Communications Protection Measures. Its involvement is limited to highly organized and planned threats by a person outside Japan that present a high risk of serious, difficult-to-recover disruption, and requires a case-by-case finding that the JSDF’s technology or information is essential in preventing that disruption. Qualifying action requires a prime ministerial order, a request from or the consent of the National Public Safety Commission, and joint implementation with the police.</li>
<li>Reporting obligations are not universal. They apply to designated critical-infrastructure operators and covered systems, not to every Japanese organization or local government. Local governments instead fall under the separate <a href="https://laws.e-gov.go.jp/law/322AC0000000067" rel="noreferrer" target="_blank"></a><a href="https://laws.e-gov.go.jp/law/322AC0000000067" rel="noreferrer" target="_blank">Local Autonomy Act</a>, which has required them, since April 1, 2026, to establish cybersecurity policies and implement corresponding measures<em><strong>.</strong></em> Qualifying local-government systems may still receive protection under the ACD framework.</li>
</ul>
<h2>Tokyo’s Rationale For the ACD</h2>
<p>The ACD framework originates in Japan's 2022 National Security Strategy (NSS), which identified a rapidly deteriorating cyber threat environment and concluded that Japan’s legal authorities and institutional capabilities required expansion. The NSS <a href="https://www.cas.go.jp/jp/siryou/221216anzenhoshou/nss-e.pdf" rel="noreferrer" target="_blank">stated</a> that the “threat of cyberattacks, in which the risk of exposure is relatively low and attackers have an advantage, is growing rapidly.” In essence, cyberattacks were seen as low-risk (for the attackers), potentially high-impact means of disrupting operations, stealing information, or advancing strategic and financial objectives while complicating detection, attribution, and timely government response. The NSS <a href="https://www.cas.go.jp/jp/siryou/221216anzenhoshou/nss-e.pdf" rel="noreferrer" target="_blank">set</a> the objective that Japan’s cybersecurity response capabilities should be “strengthened equal to or surpassing the level of leading Western countries.” Tokyo’s rationale can be organized around three overlapping pressures: a sharp increase in malicious cyber activity observed by Japanese authorities; several high-profile cyberattacks that disrupted Japanese public- and private-sector operations; and gaps in the government’s legal authorities and institutional capabilities for sharing information, analyzing threats, and taking preventive action.</p>
<p>First, Japanese authorities have identified an increase in foreign-origin cyberattacks against Japanese public- and private-sector entities. A September 2025 Japanese NCO briefing <a href="https://www.cao.go.jp/cybersecurity/pdf/setsumei.pdf" rel="noreferrer" target="_blank">document</a> reported, citing the NPA, that 99.4% of observed attack packets in 2024 originated from overseas IP addresses (<strong>Figure 1</strong>). The same document, citing the National Institute of Information and Communications Technology (NICT), reported an approximately elevenfold increase in cyberattack-related communications between 2015 and 2024, from 63.2 billion observed packets in 2015 to 686.2 billion in 2024. The briefing described this volume as equivalent to approximately one attempted attack per IP address every thirteen seconds, although the underlying measurement represents packets received by sensors rather than confirmed, discrete attacks. Neither dataset identifies actors or intent, and the same briefing explains why the overseas share does not establish that the actors themselves are specifically based overseas: attacks are routed through chains of compromised intermediary machines, so tracing even a domestic-looking source usually leads to an overseas relay. Nevertheless, these figures indicate sustained growth in hostile traffic reaching the Japanese address space.</p>
<div>
<div>
<div>
<img alt="Bar chart titled "Reported cyberattack frequency against Japan" showing NICT-observed cyberattack-related communications rising from 632 billion packets in 2015 to 6,862 billion in 2024, with 99.4% from overseas IPs" height="876" src="https://www.recordedfuture.com/media_15c372cfa488dd4ef4e36e6137599aac3e8f5e3a5.png?width=750&format=png&optimize=medium" width="1303" />
</div>
</div>
<div>
<div><em><strong>Figure 1</strong>: Reported cyberattack frequency against Japan (machine-translated) (Source:</em> <em><a href="https://www.cao.go.jp/cybersecurity/pdf/setsumei.pdf" rel="noreferrer" target="_blank">Japanese National Cybersecurity Office</a>)</em></div>
</div>
</div>
Article Link: Japan Adopts Proactive Cyber Defense Strategy