AIセキュリティ

Lessons from Japan's 2026 Breaches (Part 2): Endpoint Security and a Checklist for Small Firms

Published2026-09-30Ryuta Hamamoto

Part 2 of our look at the wave of unauthorized-access incidents disclosed in Japan in 2026. Using public guidance from Japanese and US agencies, it covers what companies can do now: patching VPN appliances, phishing-resistant MFA, PC and endpoint basics (EDR, disk encryption, admin rights, infostealers), backups, vendors and AI agents, what to do when a breach is found, and a prioritized checklist for small businesses.

Lessons from Japan's 2026 Breaches (Part 2): Endpoint Security and a Checklist for Small Firms
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. This autumn has brought a steady run of breach disclosures in Japan. Times Car, the car-sharing service, the ticketing platform e+, and Tokyo Metro's Metpo points program are all household names here. This second part is about what companies can do starting today, working through the most targeted entry points in order.

Here is the short version. Public agencies keep saying the same thing: even with AI making attacks faster, conventional security measures still work. The most common ways in are VPN appliances and remote desktop, and stolen IDs and passwords are another frequent route. So the order of work is patching the devices you expose to the internet, phishing-resistant multi-factor authentication, basic PC and endpoint settings, backups you can actually restore, control over vendors and AI, and a plan for when something goes wrong. At the end there is a ten-item checklist for small businesses.

Part 1 (Lessons from Japan's 2026 Breaches (Part 1)) made three points:

  1. Major companies disclosed incidents one after another in 2026, and most causes are still "under investigation." Even the published facts span several issues, from exploited vulnerabilities in devices and servers to investigations that include outside contractors
  2. As AI agents spread, attacks are becoming more automated and faster, and AI keys and permissions are now targets in their own right
  3. For identity documents such as driver's license images, the starting point is not to hold them at all, and if you must, to encrypt them with keys stored separately

I am not writing this to blame anyone. The companies that disclosed these incidents did so while still investigating and contacted affected people individually, which gives users time to protect themselves. I come back to that later in the piece.

The big picture: close the doors attackers actually use

Japan's Information-technology Promotion Agency (IPA), the government-affiliated body that publishes the country's main security guidance, says in its 2026 "10 Major Security Threats" report that most AI-related cases are "conventional cyberattacks that AI has semi-automated or sped up," and that "conventional cybersecurity measures are therefore effective"1. No magic new attack has appeared. Old techniques now run faster, cheaper and at larger scale. I agree with that reading.

The same report sorts attacks into six entry points and pairs each with a basic countermeasure: software updates for vulnerabilities, security software for malware, stronger authentication for password theft, reviewing settings for misconfiguration, backups for ransomware encryption, and awareness of techniques for social engineering. As long as the entry points stay the same, IPA says, these basics keep working1.

Which door first? I would start with the ones actually being used. Japan's National Police Agency (NPA) received 123 ransomware reports in the first half of 2026, the most for any half-year since it began tracking. Among the 36 victims who said how the attackers got in, 18 named VPN appliances, 9 named remote desktop and 9 named something else2. For all of 2025, VPN appliances accounted for 61 of 92 responses2.

The annual report of Japan's Personal Information Protection Commission (PPC), the national data protection authority, points the same way. Among breaches caused by unauthorized access, it frequently saw vulnerabilities left unpatched after fixes were available, IDs and passwords that were easy to guess, and database access controls left wide open by misconfiguration3. Vulnerabilities, credentials, settings. Whatever report you open, the list barely changes.

This article follows that order. Before buying anything flashy, count the holes in this sequence. With a limited budget and a small team, that is what pays off.

Stop leaving vulnerabilities open: VPN appliances and public servers

A VPN appliance exists to let staff reach the office network safely from outside. To an attacker, it is also a legitimate front door facing the internet. In a January 2026 leaflet, the NPA reported that among companies and organizations hit by cyberattacks, 52% of those using VPN appliances had not applied the latest patches4. More than half.

Late patching is rarely laziness. Systems that cannot go down, scheduling with the maintenance vendor, no test environment, a single person running IT. That is exactly why I recommend handling internet-facing devices separately from office PCs, with their own deadlines.

One published case is worth recalling. In September 2026, Japan's Digital Agency explained that the VPN vulnerability exploited in the breach of GSS, the shared work environment for government staff, had been made public before the attack was detected and was initially rated Medium on CVSS. The agency says it was moving faster than the usual response for that rating, but the flaw was exploited before the fix was applied5. I went through the details in What the Digital Agency's GSS Breach Teaches Companies About VPN Patching.

The lesson I take from it: if you rank fixes only by severity score, internet-facing devices can lose the race. I suggest three habits. First, put your VPN, firewall, routers, remote desktop gateways and public web servers on a single sheet, with model, firmware version, where the admin screen can be reached from, and who maintains each one. Second, when a vulnerability affecting anything on that sheet is reported as actively exploited, patch it first regardless of score, or immediately hide the admin screen from the internet and switch off features you do not use. Third, after patching, check whether anyone got in beforehand, and change passwords if needed.

If remote desktop is exposed directly to the internet, stop that first. In the NPA figures it is the second most common way in2. If you need it, allow it only from inside the VPN and always combine it with the multi-factor authentication described next.

Protect identities: phishing-resistant MFA and deleting unused accounts

Patching the devices does not help if someone logs in with a valid ID and password. In the same NPA leaflet, the most common way of authenticating remote work access was "ID and password only," at 39.8%4. In IPA's survey of small and medium-sized businesses, 36.8% of the 419 firms that suffered unauthorized access said their IDs and passwords had been phished6.

Multi-factor authentication (MFA) checks identity with something beyond the password, such as a phone or a hardware key. If you do not have it yet, add any form of it now. The US Cybersecurity and Infrastructure Security Agency (CISA) says any MFA is better than none, while calling phishing-resistant MFA "the gold standard"7.

Why does the type matter? In an August 2026 paper, IPA describes phishing sites that sit between the user and the real site, let the user complete MFA, and then steal the "session cookie" that marks the browser as logged in8. A one-time code typed into a fake site can still be relayed. Passkeys are different. Japan's Council of Anti-Phishing explains that they bind the secret to the site's domain name, so the real credential is never sent to a fake domain9.

NIST's SP 800-63B-4, finalized in July 2025, requires verifiers to offer at least one phishing-resistant option at the AAL2 assurance level, and says they must not require users to change passwords periodically unless there is evidence of compromise10. If your company still forces a password change every three months, I think swapping that rule for MFA would do far more good.

Keep the implementation tight, too. Once attackers get in, they sometimes turn MFA off or redirect one-time codes to their own address9. Require stronger verification whenever someone changes authentication settings.

Account cleanup matters just as much. CISA's ransomware guide recommends separating administrator accounts from user accounts and using admin accounts only for admin work11. The NPA leaflet lists deleting IDs no longer needed after staff move roles as a preventive step4. Former employees, people who changed jobs, test accounts nobody removed, IDs shared with contractors. If you have never done an account review, start there. I have written more about MFA bypass techniques in AI fraud that gets past 2FA.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

PCs and endpoints: settings you can change today

This is the core of Part 2. Endpoints are the devices at the edge of the network: staff PCs, smartphones, tablets and servers. Most attacks eventually run on some endpoint, so endpoint settings help every company.

Start with information-stealing malware, or infostealers. IPA warns that an infection can expose credentials saved in browsers and email clients, and that stolen credentials may be traded with ransomware groups and other attackers8. A May 2025 advisory from CISA and the FBI reported that one infostealer exfiltrated personal data, financial credentials, browser extensions and MFA details12. Login details stolen from one employee's laptop can be sold as a way into the whole company. That is why I would not treat endpoint security as an individual employee's problem.

Here is the practical list. Costs vary widely by product and contract, so I only give figures where I can.

Measure Why it helps First step Cost guide
Automatic OS and app updates Fewer attacks on known flaws Turn on for every PC and check monthly for stalled ones Built in
Antivirus and EDR EDR spots suspicious activity after entry and alerts you Antivirus on every device; EDR or monitoring where possible Otasuketai Type 1 endpoint monitoring: up to 2,000 yen per device per month, excl. tax
No everyday admin rights Malware finds it harder to change the whole system Standard rights for daily use, a separate admin account Configuration only
Disk encryption Harder to read a lost or stolen device Turn on BitLocker (Windows) or FileVault (Mac) Built into the OS (features vary by edition)
USB drives Fewer routes for data leaving and malware arriving Decide how data may be carried; limit USB where not needed Usually a setting
Browser extensions Some extensions can read the pages you visit Agree which extensions are needed and allow nothing else Configuration and policy
Credentials and sessions Defends against infostealers and session hijacking Move to passkeys; sign out all sessions when something looks wrong Built into many services
Remote wipe for lost devices Limits leaks from devices you cannot recover Set a contact and procedure; enable wipe through device management (MDM) Varies by product
Personal devices (BYOD) Keeps unmanaged devices away from business data Write down what personal devices may be used for and on what terms Policy work only

A few notes. IPA's small-business guidelines define EDR as technology that detects viruses, ransomware and other attacks that have reached an endpoint and notifies an administrator13. It only helps if someone actually watches those alerts. If nobody in-house can, a monitored service such as Otasuketai, covered below, is probably more realistic.

Disk encryption protects in some situations and not others. NIST SP 800-111 explains that with full-disk encryption, once the user authenticates at boot, data is decrypted transparently as it is read and written14. It is strong against a laptop stolen while powered off, but if malware gets onto a running machine, the data is readable as usual. Treat encryption as protection against loss and theft, and leave intrusion to the other measures.

For companies doing business in Japan, loss planning also touches legal duties. The PPC's Q&A says a breach need not be reported if the data was strongly encrypted and at least one of these holds: the keys were stored separately and protected, the data or keys could be wiped remotely, or the design prevents third parties from using the keys15. Encryption plus remote wipe helps you make a calm decision when a laptop goes missing. Check any specific case against the Q&A's conditions.

IPA's guidelines give similar examples: encrypt and remotely wipe telework devices, and never connect USB drives or external disks to a PC reserved for online banking13. I could not find consolidated guidance on browser extensions from a Japanese public body, so that row reflects my own view, informed by the US advisory12.

Backups: keep one offline and prove you can restore

Whether ransomware stops your business depends heavily on whether you can restore from backup. In version 4.0 of its small-business guidelines, published in March 2026, IPA added "Take backups!" to its starter list of five security rules, which now has six13.

Having backups is not enough on its own. The NPA explains that attackers search internal systems for backups as well2. CISA's guide says most ransomware actors look for accessible backups to delete or encrypt them, and recommends keeping offline, encrypted backups of critical data and regularly testing that they work in a recovery scenario11. It also warns that automated cloud backups alone may not be enough, because encrypted local files can sync to the cloud and overwrite good copies11.

The minimum I suggest for small businesses: keep several generations, keep at least one copy somewhere not normally connected to the network, and actually restore from it once a year. IPA's guidelines likewise frame backup as three stages: taking it, storing it (generations and retention) and restoring it, including checking that the restore works13.

You do not want to discover on the day that you cannot restore. In the NPA's 2025 survey, only about 18% of organizations hit by ransomware had a business continuity plan (BCP) that assumed a cyberattack16. Just writing down where backups live, what to restore first and how to keep working until then on one page changes the first few days after an incident. CISA recommends keeping a paper copy and an offline version of the response plan11. If the file server is encrypted, the procedure stored on it goes with it.

Bring vendors and AI use into scope

Hardening your own PCs does not cover data held by others. In IPA's 2026 list of threats to organizations, "attacks targeting supply chains and contractors" ranked second, after ransomware17. The PPC's annual report shows that of 1,256 breach reports caused by unauthorized access in fiscal 2025, 328 originated at a contractor, roughly a quarter (total and share are my calculation)3. In IPA's survey, 19.8% of small firms hit by unauthorized access said attackers came in via business partners or group companies6.

For the attack on Metpo's email delivery service, Tokyo Metro lists "investigating the cause, including at contractors" among its emergency measures and is still investigating18. The cause has not been published.

For vendor reviews, I would start with a list showing which vendor holds which of your data and which systems they can reach with what permissions. Then give each vendor staff member their own account instead of shared IDs, enable maintenance access only during the work, and write into the contract how many hours they have to notify you after an incident. IPA's self-assessment also asks whether you understand how safe and reliable your external services are19.

AI now deserves the same treatment as a vendor. IPA placed "cyber risks around AI use" third in its 2026 list, the first time it has appeared17. The report highlights leaks through unapproved AI use at work, known as shadow AI, and lists countermeasures including banning unapproved AI services, limiting business use of personal accounts, opting out of training on input data, monitoring usage, and requiring more than one person to check approvals and sign-offs1.

Companies building AI agents into their work should go a step further. OWASP, the nonprofit security community, lists "Excessive Agency" among the main risks of AI applications and traces it to too much functionality, too many permissions and too much autonomy20. Give an agent only the permissions its job needs. Treat AI service API keys, the keys programs use to call an AI, like production passwords, and keep them out of source code and chat. Put a human approval step in front of anything irreversible such as payments, deletions or sending data outside, and make sure the approver actually reads what they approve. Japan's Ministry of Economy, Trade and Industry (METI) held the first meeting of a working group on safe use of AI agents by businesses on 18 September 2026 and has begun work toward a set of countermeasures21.

Part 1 covers agent-specific risks in more depth. For writing internal rules, see our guide to shadow AI policy design, and to check how well your staff understand AI, try the AI literacy check.

When a breach is found: first moves and disclosure

No amount of preparation brings the risk to zero. In the NPA leaflet, 41.2% of organizations that suffered an attack had no incident response manual4. The first few hours are worth deciding in advance.

The NPA is clear about the first move. Isolate infected machines from the network to stop the spread. Switching them off in a hurry can destroy logs and other traces and make the investigation harder. Contain the damage and preserve data first, then organize and move on to investigation and recovery16. "If something looks wrong, unplug the network cable, turn off Wi-Fi, leave the power on and call IT." If every employee remembers one line, make it that one.

For companies subject to Japan's Act on the Protection of Personal Information, a breach triggers legal steps. If the incident involves sensitive personal information, risk of financial loss, possible malicious intent, or more than 1,000 people, you must report to the PPC and notify the individuals affected. Reporting has two stages: a preliminary report within roughly three to five days of learning about it, and a final report within 30 days, or 60 days for incidents that may have been malicious, such as unauthorized access22.

An amendment passed on 10 July 2026 and promulgated on 17 July23. According to the PPC's summary, the duty to notify individuals will be eased where there is little risk to their rights and interests, with the change taking effect within two years of promulgation24. This is easy to misread: what is being eased is notice to individuals, not reporting to the PPC. The summary says nothing about relaxing the reporting duty.

Talk to the police early as well. The NPA says police can advise on the initial response and provide decryption tools, among other support16. In Japan, each prefectural police force has a cybercrime consultation desk25. On ransom payments, the police point out that the money may fund criminal groups and that decryption is not guaranteed16.

Finally, disclosure. I think there is a lot to learn from how the companies that went public handled it. Times Mobility, which runs Times Car, detected unauthorized access at 9:07 a.m. on 25 September 2026 and issued a first notice the same day. The next day it added that the access route had been cut off. Its second notice on the 28th put the number of accounts at about 6.6 million, and its third on the 29th said about 1.6 million accounts had identity document images leaked, releasing figures as they were confirmed. It says it will publish its prevention measures, with timelines, in a later update26. e+ broke down the leaked records and data items by refund method, stated clearly what was not affected, and listed a full review of its systems and more frequent security assessments as prevention steps27. Tokyo Metro named the exact sender address of its notification emails and said it would not ask customers to complete any other procedure or visit an outside website18. All of this helps users spot fake messages and protect themselves.

Disclosing mid-investigation means numbers may change later. Even so, publishing facts as they are confirmed and contacting affected people individually buys users time to protect themselves. Prepare a disclosure template, an inquiry desk and the sender address you will use for official notices before you need them.

Where small businesses should start: a prioritized checklist

The hard part for small businesses is the gap between how often they are targeted and how few people they have. The NPA found that small and medium-sized businesses accounted for about 60% of the 226 ransomware cases reported in 202516, and about 60% again in the first half of 20262. In IPA's survey of 4,191 small and medium-sized firms in Japan, the average loss among firms that had an incident was 730,000 yen (9.4% lost 1 million yen or more, up to 100 million yen), and about 70% said the incident affected their business partners. Meanwhile, 62.6% had made no information security investment in the previous three fiscal years6.

That 730,000 yen is an average across all kinds of incidents. For ransomware alone, 60% of organizations hit in the first half of 2026 spent 10 million yen or more on investigation and recovery2. And because partners are affected too, it is never just your own problem.

Here is the order I would work in with limited time. Go from the top.

  1. List and patch everything visible from the internet. Write down the model, version and maintainer of VPN appliances, routers and public servers
  2. Do not expose remote desktop directly to the internet. Allow it only from inside the VPN
  3. Put MFA on remote logins and email. Where you can choose, pick a phishing-resistant method such as passkeys
  4. Delete accounts nobody uses. Review former employees, role changes, test accounts and IDs shared with vendors
  5. Turn on automatic updates and antivirus on every PC. Consider EDR or endpoint monitoring if someone can watch the alerts
  6. Remove admin rights from everyday accounts. Use a separate account for admin work
  7. Encrypt laptops and decide what happens when one is lost. Write down the contact and the remote wipe procedure on paper
  8. Keep at least one backup offline and test a restore. Keep several generations and restore for real once a year
  9. Run a structured self-assessment. In Japan, IPA's 25-item check and a SECURITY ACTION declaration are the obvious starting points
  10. Put your incident playbook on one page. Isolate, leave the power on, and list who to call (internal staff, police, vendors, insurer, data protection authority). Add one line on generative AI use while you are at it

If your company does business in Japan, use item 9. SECURITY ACTION is IPA's scheme for small businesses to declare that they are working on security, and its logo is free to use13. One star means committing to the six basic rules; two stars means completing the self-assessment and publishing an information security policy28. A declaration at either level is required to apply for the national Digitalization and AI Adoption Subsidy (formerly the IT Introduction Subsidy). Declarations made in March 2026 or earlier cannot be used for subsidy applications and must be resubmitted with a GBizID, so it is worth checking even if you declared before29. The self-assessment has 25 questions in three parts: basic measures, measures for employees and measures for the organization19.

If nobody in-house can watch for trouble, Japan has the Cybersecurity Otasuketai ("help squad") Service. These are private-sector packages combining a help desk, monitoring, on-site emergency support and simple cyber insurance, and IPA marks the ones that meet its criteria30. The Type 1 criteria also cap prices: network monitoring at 10,000 yen a month and endpoint monitoring at 2,000 yen per device per month, excluding tax31. Subsidy support for adopting these services is available as well30.

One warning. METI and the Cabinet Secretariat's National Cybersecurity Office are preparing the Supply Chain Security (SCS) rating scheme, and there have been reports of sales pitches using it to push products with claims like "without a rating you will be barred from trading" or "get rated now or you will be excluded from bids." On 27 April 2026, both bodies warned against this, explaining that the scheme is voluntary, meant for business partners to agree on security levels, and does not require any specific security product32. The scheme is expected to launch around the end of fiscal 2026. Before a pushy pitch talks you into an expensive product, work through the checklist above and the public schemes.

What we do in-house

A brief word about us. TIMEWELL holds ISO/IEC 27001 certification, the international standard for information security management (scope: planning, development and provision of SaaS products using AI technology). I explain the standard in our beginner's guide to ISMS and ISO/IEC 27001.

That said, certification shows the system is in place, while day-to-day safety depends on what each person does. That is why we run security training for our staff every week. The basics in this article do not stick after hearing them once.

If running staff training on your own is hard, our WARP SECURITY program may be worth a look. It spends less time on attack techniques and more on everyday preparation: internal rules, approval design and how to decide when something goes wrong.

Summary

  • Even with AI speeding up attacks, conventional measures such as patching, authentication and backups still work
  • List what you expose to the internet, add phishing-resistant MFA and delete unused accounts
  • On PCs, the basics are automatic updates, EDR, separate admin accounts, disk encryption and remote wipe
  • Give vendors and AI agents only the access they need, and keep human approvals real
  • When a breach is found, isolate without switching off, then report to the authorities and call the police quickly

The companies that disclosed incidents this autumn published facts mid-investigation and contacted the people affected. Whether your company could do the same when its turn comes depends, I believe, on the few hours of preparation done before anything happens. This week, start by listing the devices you expose to the internet. If you would like to talk through staff training or internal rules, get in touch.

References

The facts in this article are based on the public sources below. As of 30 September 2026, the causes of most of the incidents mentioned were still under investigation.

Footnotes

  1. 10 Major Information Security Threats 2026, Explanatory Report (Organizations) — Information-technology Promotion Agency, Japan (IPA) — March 2026 (Japanese) ↩ ↩2 ↩3

  2. Threats in Cyberspace, First Half of 2026 — National Police Agency — September 2026 (Japanese) ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  3. FY2025 Annual Report — Personal Information Protection Commission — July 2026 (Japanese) ↩ ↩2

  4. Survey of Organizations Affected by Cyberattacks and Countermeasures (leaflet) — National Police Agency — January 2026 (Japanese) ↩ ↩2 ↩3 ↩4

  5. Q&A on Unauthorized Access to the Government Solution Service — Digital Agency — 11 September 2026 (Japanese) ↩

  6. FY2024 Survey on Information Security Measures at Small and Medium-sized Enterprises — IPA — 14 February 2025 (Japanese) ↩ ↩2 ↩3

  7. Implementing Phishing-Resistant MFA — CISA — October 2022 ↩

  8. Attack Emails Targeting Organizations and How to Counter Them — IPA — 3 August 2026 (Japanese) ↩ ↩2

  9. Anti-Phishing Guidelines, FY2026 Edition — Council of Anti-Phishing Japan — May 2026 (Japanese) ↩ ↩2

  10. SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management — NIST — July 2025 ↩

  11. #StopRansomware Guide — CISA et al. — October 2023 ↩ ↩2 ↩3 ↩4

  12. Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations (AA25-141B) — CISA and FBI — 21 May 2025 ↩ ↩2

  13. Information Security Guidelines for SMEs, Version 4.0 — IPA — 27 March 2026 (Japanese) (overview of the revision on IPA's page) ↩ ↩2 ↩3 ↩4 ↩5

  14. SP 800-111 Guide to Storage Encryption Technologies for End User Devices — NIST — November 2007 ↩

  15. Q&A 6-19: When personal data is protected by advanced encryption — Personal Information Protection Commission (Japanese) ↩

  16. Threats in Cyberspace in 2025 — National Police Agency — March 2026 (Japanese) ↩ ↩2 ↩3 ↩4 ↩5

  17. 10 Major Information Security Threats 2026 — IPA — 29 January 2026 (Japanese) ↩ ↩2

  18. Notice of Unauthorized Access to Metpo Member Services — Metro Point Club Office (Tokyo Metro) — 27 September 2026 (Japanese) (Tokyo Metro notice PDF) ↩ ↩2

  19. Five-Minute Information Security Self-Assessment (Appendix 3 to the SME Guidelines) — IPA — March 2026 (Japanese) ↩ ↩2

  20. LLM06:2025 Excessive Agency — OWASP GenAI Security Project ↩

  21. First Meeting of the Sub-Working Group on Safe Use of AI Agents by Businesses, Industrial Cybersecurity Study Group — Ministry of Economy, Trade and Industry — 18 September 2026 (Japanese) ↩

  22. Guidelines on the Act on the Protection of Personal Information (General Rules), as amended April 2026 — Personal Information Protection Commission (Japanese) (overview: Mandatory breach reporting and notification) ↩

  23. Bill to Partially Amend the Act on the Protection of Personal Information (bill status) — House of Councillors (Japanese) ↩

  24. Summary of the Bill to Partially Amend the Act on the Protection of Personal Information — PPC Secretariat — April 2026 (Japanese) ↩

  25. Cybercrime Consultation Desks — National Police Agency (Japanese) ↩

  26. Unauthorized Access to the Times Car Website: First Notice — Times Mobility — 25 September 2026 (Japanese), Second Notice — 28 September 2026, Third Notice — 29 September 2026 ↩

  27. Notice and Apology Regarding Unauthorized Access and a Personal Data Leak — e+ (eplus) — 29 September 2026 (Japanese) ↩

  28. SECURITY ACTION Two Stars — IPA (Japanese) (scheme overview: SECURITY ACTION) ↩

  29. Digitalization and AI Adoption Subsidy (formerly IT Introduction Subsidy) — SECURITY ACTION, IPA (Japanese) ↩

  30. Cybersecurity Otasuketai Service — IPA (Japanese) ↩ ↩2

  31. Cybersecurity Otasuketai Service Criteria, Version 2.0 (briefing material) — IPA (Japanese) ↩

  32. Beware of Inappropriate Sales Pitches Citing the SCS Rating Scheme — Ministry of Economy, Trade and Industry — 27 April 2026 (Japanese) ↩

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles