TRAFEED

What "Economic Security Management" Means in Practice — 11 Cases from METI's Collection of What Companies Actually Did

Published2026-08-18Ryuta Hamamoto

Japan's Ministry of Economy, Trade and Industry has published a collection of concrete corporate case studies on economic security. Where the guidelines said what companies should do, this one shows what other companies actually did, across 11 cases. From a plant that stopped for a day to a firm that built up inventory and won investor confidence for it. Here is the behavior-change framework it uses, and what financial institutions say they are really looking at.

What "Economic Security Management" Means in Practice — 11 Cases from METI's Collection of What Companies Actually Did
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

In May 2026 Japan's Ministry of Economy, Trade and Industry published a collection of concrete case studies on corporate management and economic security, and METI Journal ONLINE covered it again on 18 August12. Thirty-four pages, eleven cases. Reading it, I think this document does a genuinely different job from the Economic Security Management Guidelines that came before it.

The guidelines set out what companies should do. The case collection sets out what other companies actually did. That gap matters more than it sounds. The question I hear most often from corporate planning and legal teams is "I understand why it matters — but concretely, where do I start?" This document is aimed squarely at that void.

The short version

This is a long piece, so here is the whole argument up front. Reading only this should be enough to raise it in a meeting.

  • "Economic security management" is not a rebranding of compliance. METI splits it into securing supply chain autonomy, securing the indispensability of your own technology, and the governance that keeps both running. Doing export control properly does not cover it
  • The collection sorts companies into five stages — unaware, aware, preparing, acting, sustaining. The obstacle differs by stage, so copying another company's success story rarely moves anything. Deciding where you are comes first
  • Companies with no sensitive technology are the more exposed ones. The cautionary case in the opening section is a maker of equipment for food factories. Having concluded that economic security was somebody else's problem, it lost an expansion plan when a raw material stopped arriving
  • The first step almost always begins with a management decision. In all three cases in the basics section, movement started not when the front line felt the danger, but when management decided to create the team
  • Investors are already looking. "More inventory is not automatically bad. If there is a logic to it, we view it positively." "Business continuity is a precondition, not a bonus." The collection carries direct quotes across five themes, up to the line that failure to address it gets the valuation discounted
  • The cost of not disclosing now exceeds the risk of disclosing. Technology-leakage measures are sensitive and hard to publish. But investors say the real problem is that they cannot tell whether you are doing nothing or simply cannot say

The rest of this piece walks through the collection.

What the phrase actually covers

METI issued its Economic Security Management Guidelines (First Edition) in January 2026, positioned as a reference for companies designing strategies that contain losses from economic security risks over the medium to long term and support corporate value2.

The point to hold onto is that this is wider than compliance. Doing classification properly, following the Foreign Exchange and Foreign Trade Act — necessary, but that covers well under half of what the collection deals with.

The eleven cases are sorted into three categories.

Category What it means Where it shows up
Securing autonomy Able to keep supplying under any conditions, without depending on one country or counterparty Inventory buffers, sourcing diversification, tracing the supply chain upstream
Securing indispensability Your technology or product is hard to replace, so others need you Inventorying critical technologies, preventing leakage, developing new materials
Strengthening governance The organization and decisions that keep the other two running Creating a dedicated economic security function, making security levels visible

Autonomy is "make it survivable if we get cut off." Indispensability is "make it so we don't get cut off." Opposite directions. And neither is achievable by one diligent person, which is what the third category is for.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Which stage you are in changes what you should read

The figure at the front of the collection is the part that impressed me most.

METI's chart of corporate behavior-change stages and bottlenecks: five stages from unaware through sustaining, with the specific obstacle companies hit at each stage

Source: METI, Trade and Economic Security Bureau, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.2

Five stages:

  • I. Unaware Do not know, or know but are not interested
  • II. Aware Interested, but see no necessity
  • III. Preparing See the necessity, but cannot act
  • IV. Acting Acting, but it is not working
  • V. Sustaining Acting effectively, and confident it will hold

And the reason for being stuck differs at each. Unaware and aware companies think "economic security is for the government to handle," "compliance with export control is enough," "we face no risk that touches our business." Preparing companies say "we don't know what to do or how," "we lack the resources — compliance already takes everything." At the acting stage it becomes "we cannot get cooperation internally, so nothing has real force," "our suppliers and contractors don't come along, so it never becomes a supply-chain or industry-wide effort," "it is hard to judge how far to go, and which countries to deal with and how far."

I found this genuinely practical. A common failure is a preparing-stage company reading an impressive acting-stage example and closing the document with "we could never do that." Different blockage, same prescription, no effect.

The collection is built to match: the opening and Chapter 1 for those short of the preparing stage, Chapter 2 for acting, Chapter 3 for sustaining. Decide your stage, then read. That is the intended use.

The opening section: "this doesn't apply to us" is the expensive answer

The collection puts failures before successes. It calls them "horror cases," and they land.

Case A: a supplier is attacked, and every domestic plant stops

Company A's main supplier, Company X. It was X's subsidiary that was hit by a cyberattack. The virus had also entered the ordering system used for parts production. X cut its external network connections immediately, and on receiving the report, A halted every one of its domestic plants because it had no visibility on parts supply.

Fast coordination held A's shutdown to a single day. Restoring X's ordering system took about a month, during which X managed orders by hand. The point of entry was a vulnerability in a communications device at X's subsidiary.

Not your own company, not even your direct supplier, but a communications device at your supplier's subsidiary — and every domestic plant stops. The collection notes that the impact spread across the supply chain and escalated to the government urging the whole industry to strengthen its measures.

Case B: a food-equipment maker loses its expansion plan when a raw material stops

This one may be closer to home for most readers.

Company B makes equipment that removes metal contaminants from raw materials on food factory production lines. That equipment requires a part made with raw material A, produced in country X. The equipment was about 10% of B's revenue, but the president saw real traction and was about to concentrate resources on sales when country X announced tighter export screening for raw material A into Japan.

Learning about it from a newspaper, the president asked the trading company that supplied the part, and was told imports had stopped completely. A warehouse check showed roughly six months of stock.

Here is how the collection describes B's position:

The president of Company B knew the term "economic security," but had not grasped its impact on his own business.

And:

Because its equipment served the food industry, the company concluded that it was unrelated to "economic security," and did not treat it as its own concern.

I think those two lines are the most important thing in the document. B's president was not ignorant. He knew the term. It simply had not connected to his bill of materials. That is not a failing worth condemning; it describes almost every company I talk to.

Redesigning the equipment to avoid raw material A would take years to reach commercialization. The government is building out third-country sourcing support and technology development, but those take time. The collection records B's frustration directly: long-term support measures will not arrive in time for stock that runs out imminently.

The stated takeaway:

Recognize that even if your product is neither a sensitive technology nor a designated critical material, another country's measures can cut off your parts and materials, cost you the chance to grow, and put business continuity at risk.

Not designated does not mean not affected. Worth emphasizing.

Case C: financial institutions already screen counterparties on economic security

The third opening case is a financial institution, Company C. Its markets division had long gathered and analyzed negative news on compliance, money laundering and terrorist financing to support investment decisions. In the last five to ten years, economic security, human rights and cybersecurity were added to that.

C noticed that compliance work and economic security work share the same underlying purpose — managing and gathering information on counterparties — and built a combined due diligence process covering both. Background checks on new counterparties, obviously, but also continuous evaluation of existing ones using reporting from domestic and international news vendors and disclosures from overseas authorities. When risk information surfaces, C weighs the business impact and, for difficult cases, interviews the counterparty directly to establish the facts.

What I find interesting is what happens next. Where dialogue shows that governance is being rebuilt, C resumes business early. Not a detect-and-cut mechanism, but detect, verify, and restore where warranted. That is what balancing risk management against commercial momentum looks like in practice.

Read from the other side: when you are the one being screened, the question is whether you can answer what you are asked.

The basics section: the first step is a management decision

Chapter 1 is subtitled "taking the first step requires strong leadership and action from management." Read the three cases and the subtitle stops being decoration.

Case D: leakage comes from people, not only accidents

Until the incident, Company D held a strong assumption that information leaks were accidents, and had low sensitivity to deliberate leakage by employees or former employees. In the collection's words, the company had drifted into a state where anyone who wanted to take something out could take it out.

An employee, X, moved to a competitor, and D became aware of a suspected leak. Its internal investigation concluded the probability was high, and it consulted the police. The investigation stalled, and the full picture has not been established.

Worth pausing here: the collection describes this as a leak that "was suspected" and a probability "judged to be high." The full facts were never established, so this should not be treated as confirmed wrongdoing. This article treats it the same way.

D took three actions afterwards.

  1. Set up a responsible unit in corporate planning and screened every employee's email in full for signs of external leakage
  2. Introduced an AI tool to analyze and monitor access logs, auditing behavior that deviated from normal patterns, with individual interviews where something looked off
  3. For departing employees, intensified email auditing over the final months, and tightened confidentiality contracting — non-disclosure agreements at exit plus per-project undertakings

The stated effect was deterrence. D communicated and explained all of this company-wide, and observed a deterrent effect beyond the direct prevention. Monitoring is easily resented internally; designing the communication of it as part of the measure is the practical detail.

Case E: the front line already knew. There was just nowhere to report it

This case gave me the most to think about.

Case E: establishing a dedicated economic security function after a technology leakage incident, showing how the new team interviewed business units and channeled threat information and countermeasures up to management

Source: METI, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.13

At Company E, an employee handling government relations had been telling management that economic security needed an organizational rather than an individual response. Management did not see the need.

Then, in year A, an employee supervising a key project improperly removed multiple sets of experimental data with the intention of changing jobs. AI monitoring detected the removal, and E opened an internal investigation. The employee left the following month. The investigation confirmed improper removal of sensitive information, and E consulted the police. The following year, the police investigation established that a party with a background in country X had approached the employee to obtain E's technology.

Prompted by the incident, management decided the following year to establish a dedicated economic security function. This is where it gets interesting.

When the new team interviewed business units handling sensitive technology, it emerged that the year-A incident had not been isolated. Many business units had long been aware of suspicious approaches to E's former employees and counterparties by parties believed to have a background in country X. Why had none of it surfaced? The collection's explanation:

Because no dedicated function existed at the time, business units did not know where to report risk cases, and only issued warnings within their own units.

The information was not missing. There was no address to send it to. Creating the team was what caused information already inside the company to arrive.

The following year the team consolidated the interviews and recommended measures centered on the two highest-volume risks — approaches to former employees and approaches to counterparties. The year after that, management allocated budget and concentrated staff on exactly those two areas.

The stated takeaway:

Because business units will not necessarily share threat information with the economic security function on their own initiative, it is essential for that function to go and get the information. A passive posture means risks go unnoticed.

Anyone who has stood up an internal process will recognize that creating the mailbox is not sufficient.

Case F: from a near miss to a critical technology list

Company F started not from an incident but from a near miss.

Case F: identifying critical technologies at company level, with the dedicated economic security function issuing assessment criteria and business units inventorying and reporting their technologies

Source: METI, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.15

Business Unit B at Company F received enquiries from several companies in country X wanting to buy its technology Y. The technology was not recognized internally as critical, and at first nobody understood why multiple parties were asking. The unit found it odd enough to escalate to corporate planning, and under its direction re-examined technology Y — establishing that the technology was specific to F and held an advantage over competitors.

The company learned about its own strength from outside enquiries. That is not a joke at F's expense; it is what happens routinely when technology is assessed unit by unit.

Concluding that business units alone could miss the significance of a technology, F set up a cross-functional economic security team and began a company-wide inventory of critical technologies.

The procedure is specific. The team directs each unit to inventory, but because units cannot always judge economic security significance alone, the team supports the selection. That is the two-way flow in the figure: (1) issue assessment criteria, (2) identify and report. The result was a company-wide critical technology list, plus a structure for managing leakage prevention and for scrutinizing acquisition proposals from other companies.

The stated effect is making the sources of competitiveness visible. A defensive exercise that doubles as an inventory of your own strengths — that is what makes this case interesting.

The applied section: moving what is hardest to move

Chapter 2 is subtitled "making economic security work requires bringing others in and deepening the effort." The scope stops being internal.

Case G: surveying suppliers is not enough. You walk alongside them

Company G, a manufacturer with many suppliers, had measures in place for its own security but nothing specific for the security environment of its counterparties. Then a cyberattack on an affiliated supplier leaked technical information.

G's response came in two stages.

(1) Survey. Led by the business unit's information security officer, G listed "important counterparties" based on the significance of the technology involved and its dependence on them. Officers from the unit and from head office visited sites in person, conducting interviews, monitoring, and security assessments by third parties.

There is a note attached. Because the survey requires the understanding and cooperation of these suppliers, G routinely explains the background, including the international situation, to their top management. Not a questionnaire mailed out and collected.

(2) Support through remediation. G feeds back the issues found and then walks alongside the supplier through designing and implementing fixes. The collection describes working on remediation together.

The stated takeaway:

Where counterparties have limited resources and cannot build adequate management systems on their own, surveying them and supporting remediation makes their issues visible and creates an environment where sensitivity to economic security risk, including technology leakage, can rise.

And a closing line: some investors evaluate this kind of supplier management. Supporting your suppliers becomes an asset rather than a cost.

Case H: what is not visible does not get credited

Company H's story also reads as a story about internal politics.

Until year A, a view persisted inside H and across its industry that cybersecurity was somebody else's job — something for security specialists. H's chief information security officer had concerns about that climate and about the lack of visibility into the company's own security posture, but could not get internal traction.

The way the concern is phrased is precise:

Without visibility, the effort becomes dependent on individuals, does not translate into recognition for those doing it, and as a result no effective measures are taken until an incident occurs.

Invisible work goes uncredited; uncredited work does not continue; work that does not continue means nothing happens until something breaks. Three links, all sound.

The turning point came in January of year A. Against a background of frequent cybersecurity incidents across the industry and the enactment of Japan's Economic Security Promotion Act, a dedicated economic security function was created inside H. The CISO used that as tailwind, working with the president and the new function to issue a message from the top. From June that year, the CISO and security officers in each business unit met monthly.

The following year H introduced an external tool that scored each unit's cyber risk and displayed it on a dashboard shared company-wide. Addressed and unaddressed items became visible, and units could see objectively why their score was low. Then: units comparing scores with each other generated a sense of urgency and competition, which drove them to act.

The effects are concrete. Outside parties asked about adopting the same system, and an external assessment rated H's security level among the best in Japan. The shared understanding that cybersecurity is investment rather than cost took hold internally.

H also asks its counterparties to raise their security level, presenting system development contractors and suppliers with a set of "security principles" that are simple and easy to act on. Deliberately not making the ask complicated.

The advanced section: defensive spending becomes a reason to keep the business

Chapter 3 is subtitled "economic security leads to increased corporate value, through new business opportunities and customer trust." The polarity flips here.

Case I: burned once, ready the second time

Case I: securing stable supply capability through early risk response, showing the shift from a defensive posture to an offensive one via inventory buffers and sourcing diversification

Source: METI, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.23

In year A, country X imposed export controls on raw material A, on which Company I depended, and I took a serious hit. Over a decade later, in year B, country X signalled it would tighten controls on raw material A again.

What I's management recognized here is operationally sharp:

Because country X might also cause exports to stall through practice not grounded in law, ahead of any formal tightening, I's management recognized the need to move first.

Waiting for the effective date would be too late. A month later, management decided to raise inventory levels of raw material A. It would cost money, but weighed against the risk of running short, building stock was the right call. They spent several months doing it.

There is craft in how the inventory is held. To minimize storage costs they kept it in their own warehouses rather than external ones, improved forecasting of raw material A consumption, and calibrated the right stock level while projecting procurement lead times. The following year, for materials other than A, they added second sources within country X and pursued sourcing from outside it.

Then in year C, country X tightened controls again. Because I had prepared in advance, there was no significant impact on the business.

The effects section is the heart of this case. After the year-C tightening, an institutional investor asked I's IR team about the impact. I explained the inventory and sourcing diversification it had been building all along, and satisfied the investor. Separately, its customers rate it highly on quality, cost and supply stability, and that "stable supply capability" is one reason the business continues.

A decision that in isolation worsens financial ratios — holding more inventory — became both the answer to an investor's question and a reason customers stay. Defensive spending turned into an offensive asset.

Case J: tracing the supply chain before anyone required it

Case J: voluntary upstream supply chain investigation, showing J asking tier 1 for cooperation and relaying the request through tier 2 to identify the smelter

Source: METI, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.25

Around the world, countries are legislating human rights due diligence requirements and imposing import restrictions tied to forced labor. Company J decided to conduct due diligence voluntarily as a CSR effort, before it was directly required to.

The smart part is how it bounded the scope. To allocate limited resources effectively, it started by tracing the supply chain for a handful of minerals from conflict-affected areas with severe human rights risk. It then revised its policy flexibly as conditions changed, expanding the set of minerals covered.

The tracing method is equally concrete. J explained its effort and its rationale to tier 1 suppliers and asked for cooperation, then relayed the request from tier 1 through tier 2 and beyond. Because many parties are involved, it used a template in wide international use. It also drew on internal engineering expertise: to make dependence on specific sources visible early, J had been surveying the design and manufacturing methods of upstream components from the development stage.

It succeeded in identifying upstream smelters and assessed the human rights risk, disclosing the work to stakeholders through its integrated report. The institutional investor verdict:

Specific and highly transparent. Where many companies define human rights narrowly, J has voluntarily taken a broad view of human rights risk and is acting on it.

Case K: pursuing its own indispensability brought production back to Japan

The last of the eleven operates at a different scale.

Material Y, required to produce product X, was difficult to source or make domestically, leaving dependence on foreign supply. Demand for product X was rising sharply, and for volume production many plants were built outside Japan, where sourcing material Y and labor costs were more attractive. Domestic producers built on material Y and added value by improving it. The collection reads this as having deepened Japanese industry's dependence on material Y and driven a sharp decline in Japan's global share of product X.

Company K went the other way. Rather than material Y, it focused on material Z, then not yet in practical use. Playing to its strengths, K compensated for material Z's weakness in durability and built the capability to source material Z's raw input domestically.

Opinion inside K was divided — unsurprising when you are betting against the direction competitors are taking. It nonetheless committed to a niche strategy that used its own strengths, increasing investment in stages.

What happened next is the interesting part. Some production steps for product X had been lost to offshoring, but because K's new material Z uses domestic raw inputs, some of those lost steps began returning to Japan. K also patented its core technology and limited the number of employees with visibility into the whole of it, to prevent leakage. It has extended beyond product development into implementation services and recycling, and aims to secure international standards.

And a movement grew to back a company taking on the world with Japanese-origin technology: its number of individual shareholders doubled.

Pursuing your own indispensability lifts the wider industry's autonomy, and that comes back as recognition. It is easy to see why the collection closes the advanced section here.

What financial institutions and investors are actually looking at

The last six pages are a column answering companies' worries with the views of financial institutions and investors. I think this section is worth more than the main body, because it carries their own words, anonymized but unedited.

The background to the financial institutions column: three concerns raised by companies, and the five themes into which the responses were grouped

Source: METI, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026), p.28

Three concerns are listed from the company side.

  • Do investors and banks actually care about economic security efforts at all?
  • Disclosing that we run scenario-based risk analysis is difficult from a business strategy standpoint
  • If we disclose our measures, aren't we showing our hand?

All three are familiar. The responses are grouped into five themes.

"More inventory is not automatically bad"

From an equity manager at a Japanese asset management firm:

Inventory increases to prepare for supply chain risk are, from an investor's point of view, investment in business continuity rather than cost. Even if cash flow deteriorates because inventory rose, we accept it if it is a strategic response such as diversifying sources. We also reference historical inventory turnover and peer inventory levels, and judge through dialogue.

Another comes at it from the opposite direction:

Business continuity is a precondition, not a bonus. Preparing in advance so you are not caught short of materials in a contingency is what matters. If we discover it has not been addressed, we judge business continuity risk to be high and discount the valuation.

Do it and you are not rewarded; fail to do it and you are penalized. That asymmetry is worth sharing in a management meeting. The collection's own prompt suggests articulating your inventory and multi-sourcing rationale in advance so it can be explained as strategic investment.

Not disclosing is what lowers the score

Acknowledging that "Japanese companies tend to be reticent, and there are cases where it is hard to speak up because a particular country is implicated," the response continues:

But if it is a constructive effort to prepare for risk, communicate it actively. Being recognized by the market creates value.

With an example: when shortages of a component were feared, one company answered at its results briefing that it held over a year of inventory and was therefore fine for the time being — and avoided a discount from the market.

There is also a note that you do not have to publish everything:

You do not need to disclose everything. If your integrated report shows the risk management process and the organizational structure, that becomes the starting point for further dialogue. Seeing a change such as "an economic security structure that did not exist last year has been established this year" is welcome from an investor's perspective.

A structure chart and a year-on-year delta. That is not a high bar.

They look past tier 1 to "your customer's customer"

Two quotes on autonomy:

A company's risk response capability shows up clearly in its track record — how it came through past contingencies such as the earthquake or the pandemic while minimizing the impact on earnings.

In investment decisions on manufacturers, we check suppliers and customers in nearly every case, including whether they depend on a single source, and we place weight on visibility into the supply chain. A state in which you can see tier 1 but not tier 2, tier 3 and beyond is evaluated as a clear risk.

"In nearly every case" is a strong phrase. And the absence of visibility past tier 1 is itself the object of evaluation. That is where Case J's upstream tracing connects, and why it sits in the advanced chapter.

With technology leakage, they cannot tell "won't say" from "isn't doing"

The indispensability theme is the most uncomfortable one for companies.

Technology leakage measures are highly confidential at the company level, and the sticking point for evaluation is that investors cannot distinguish between "doing nothing" and "cannot say because it is sensitive."

Then the way through:

Even where it is difficult to disclose preventive measures or explicit responses, simply showing what you recognize and understand as a risk — for example leakage through a local joint venture — contributes to evaluation.

Not the content of the countermeasures, but the resolution of your risk perception. The second quote goes further:

Measures against leakage through former employees, black-boxing core technology when expanding overseas, and even considering business-transition scenarios that assume future imitation of the technology — companies taking realistic measures like these are judged to have strong management instincts.

"Business-transition scenarios that assume future imitation" is a striking item to see on the list. The question is not whether you will avoid being copied, but whether you have thought about how you eat afterwards.

Governance shows up in the board skills matrix

The last theme is organizational.

Japanese companies tend to be poor at seeing themselves objectively. Companies that hold their own intelligence — including market trends, not just what the parent company says or what the industry does in step — and can analyze the global situation and judge and respond autonomously, are rated highly.

Whether a director has economic security expertise is made visible in the skills matrix. If a dedicated department is difficult given company size, appointing a highly specialized outside director and rotating them flexibly as the company grows is also effective.

The skills matrix is a table many companies already disclose in their annual securities report or corporate governance report. Whether it has a row for economic security is visible from outside at a glance. Offering the outside-director route for companies too small for a dedicated function is a practical touch.

How to use this at your own company

It is an interesting read, but reading it is not the point. Here is the order I suggest when I talk this through with corporate planning and legal teams.

1. Pick one stage for your company. Unaware through sustaining. If different business units sit at different stages, decide per unit. Skip this and other companies' cases end in "we could never do that."

2. Lay your bill of materials over a map. This is where Case B bites. Which components depend on a single country or a single supplier? Not only tier 1. All of it is impossible, so start with what stops the business when it stops.

3. Restate your strengths in outside language. As in Case F, a technology that attracts enquiries may matter more than you think. A critical technology list is a defensive document and an inventory of your competitiveness at the same time.

4. Create an address for information. The lesson of Case E. The front line already knows, but with nowhere to report it stops at an internal warning. Make the channel, and go and get the information.

5. Put it in a form you can say out loud. If you hold inventory, why that level? If you split sourcing, on what logic? Working it out after an investor asks is too late.

Steps 2 and 4, plus the continuous counterparty evaluation from Case C, stop being manual work quickly. The number of parties to check grows, and their circumstances keep changing. TRAFEED, our export-control AI agent, exists to keep that classification and counterparty screening running continuously. Pricing is by usage rather than per seat, so it can sit where the decisions actually happen — sales, engineering, procurement. That is the mechanical side of what the collection keeps saying: go and get the information from the business units.

In summary

  • METI's collection of concrete cases (May 2026) answers the guidelines' "what you should do" with what other companies actually did, across 11 cases
  • It sorts companies into unaware, aware, preparing, acting, sustaining, and argues the blockage differs by stage. Decide your stage, then read
  • The cautionary cases feature companies with no sensitive technology. Concluding that economic security is unrelated is itself the risk
  • All three basics cases started moving when management decided to create the team. Information appears once there is an address for it
  • In the advanced cases, inventory buffers and voluntary supply chain tracing turn into investor confidence and reasons customers stay
  • Investors are already looking. Not doing it is penalized more than doing it is rewarded. On technology leakage, showing the resolution of your risk perception earns credit even when the measures cannot be disclosed

What stayed with me after reading is that the assumption "economic security is the government's job" no longer holds. The dangerous state is Case B's president — knowing the term, without it connecting to his bill of materials. The hard part is not the analysis. It is getting it onto the table once, as your own problem. I would be glad if this piece is used for that first pass.

If you want to work through how to systematize export control and counterparty screening at your company, get in touch.

Footnotes

  1. METI, Trade and Economic Security Bureau, "Collection of Concrete Cases on Corporate Management and Economic Security" (May 2026). Cases A–K, the behavior-change stage framework, and the quotes from financial institutions and investors are all drawn from this document. Company and country names are anonymized in the source, and this article does not attempt to identify them. https://www.meti.go.jp/policy/economy_security/index.html

  2. METI Journal ONLINE, "How should companies approach economic security? Practical hints from leading cases" (60-second explainer, 18 August 2026). The January 2026 issuance of the Economic Security Management Guidelines (First Edition), and the availability of explainer videos, a leaflet and an English edition, are from this article. https://journal.meti.go.jp/60sec/47309/ 2

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles