Don’t do SECURITY. Do business SECURELY.

Japan’s FSA issues financial sector cyber security guidelines

Japan’s Financial Services Agency publishes guidelines setting cyber security expectations for financial institutions.

Japan’s Financial Services Agency today publishes its Guidelines on Cybersecurity in the Financial Sector, effective immediately.

Key points

  • Governance and risk-based cyber security controls.
  • Third-party and supply-chain risk.
  • Vulnerability management and testing, including threat-led penetration testing.
  • Incident response, recovery and information sharing.

UK technology providers serving Japanese financial institutions should expect these guidelines to shape security assessments. The guidelines reflect international practice, including G7 fundamental elements and the NIST Cybersecurity Framework, so suppliers with ISO/IEC 27001 certification and mature incident response will be well placed. Expect questions on supply-chain risk and threat-led testing.

Source: Guidelines on Cybersecurity for the Financial Sector (Japan FSA)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights