Japan Drafts New Cybersecurity Guidelines for Critical Infrastructure After Ransomware Attacks

The Japanese government has drawn up draft guidelines outlining 150 measures designed to enhance cybersecurity for businesses managing critical infrastructure, according to a Jiji Press report published on August 23. Released in Tokyo, the draft explicitly warns that even closed networks disconnected from the internet “are not necessarily safe,” addressing vulnerabilities across 16 designated critical sectors including finance, railways, and electricity.

Critical Infrastructure Sectors and Network Security Warnings

The newly drafted guidelines target 16 sectors designated as critical infrastructure, pressing operators to abandon assumptions about isolated digital architecture. According to the draft reported by Jiji Press, companies must not rely on “overconfidence” or let their guard down simply because their systems use closed networks or dedicated operating systems or have unique technical specifications.

Describing cybersecurity as “a management issue that can be key to the survival of a company,” the government document emphasizes that “it is difficult to completely protect against cyberattacks.” Consequently, businesses in these designated sectors are urged to improve their capabilities to recover, fully preparing for the possibility of system failures.

Ransomware Mitigation and Insurance Strategies

Prompted by a recent series of ransomware attacks, the draft urges such businesses to take measures, including taking out cybersecurity insurance to ease the possible massive financial impact caused by ransomware attacks, while asking companies not to pay ransoms.

The strategic framework also looks ahead to emerging technological threats. To address cyberattacks utilizing advanced artificial intelligence models such as Claude Mythos, the draft mentions the need to strengthen defense measures promptly, including by using sophisticated AI models. Furthermore, accounting for progress in the development of quantum computers, the guidelines call for the adoption of postquantum cryptography, or PQC, which is hard to crack, by as early as 2035.

Public Consultation and Final Release Schedule

The Japanese government is currently accepting public comments on the guidelines until Wednesday. Following the conclusion of this consultation period, authorities plan to revise the draft based on the feedback received and release the final version by the end of September. The government hopes that industry groups and government agencies will refer to the guidelines when developing safety standards.

Japan Drafts New Cybersecurity Guidelines for Critical Infrastructure After Ransomware Attacks
Photo: adnkronos.com
Photo of author

Omar El Sayed - World Editor

Omar El Sayed is Archyde’s World Editor, focused on international affairs, diplomacy, conflict, and cross-border political developments. He brings a global newsroom perspective to complex events and helps readers understand how regional stories connect to wider geopolitical shifts.

Liam Gallagher Denies Oasis Glastonbury 2027 Rumours

Six EU Countries Push for Windfall Tax on Oil Companies Amid War Profits

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.