Don’t do SECURITY. Do business SECURELY.

Japan enacts Active Cyber Defense Act

Japan enacts its Active Cyber Defense Act, requiring critical infrastructure operators to report incidents and share information.

Japan’s Diet today enacts the Active Cyber Defense Act, with obligations phased in by 2027.

Key points

  • Critical infrastructure operators must notify the government of important systems.
  • Cyber incidents must be reported.
  • Government and industry information sharing is established.
  • IT vendors must disclose and remediate vulnerabilities in critical systems.

UK suppliers to Japanese critical infrastructure should prepare for vulnerability disclosure and remediation requirements. The Act also gives Japanese authorities powers to analyse communications data and neutralise attack infrastructure, marking a significant shift in Japan’s cyber defence posture. Operators will expect suppliers to support incident reporting and vulnerability handling.

Source: Cyber Countermeasure Capability Enhancement Act (Cabinet Secretariat of Japan, in Japanese)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights