Japan’s New Cyber Security Strategy

Japan has recently issued the outline for its ‘Next Cyber Strategy’ which is likely to be approved by Cabinet in September 2021. Importantly, this is the first time that Japan has mentioned any country that is posing threat to Japan’s national security - that country is China.

The strategy is intended to run for three years and has been prepared in the backdrop of increasing cyber attacks from China and deteriorating relations with that country on the issue of Taiwan

Japan has also gradually integrated cyber security into boosting its relations in the ASEAN region, offering platforms for collaboration with individual Southeast Asian countries as well as the United States through additional coordination. Japan’s relations with Russia are also deteriorating and Japan perceives that Russia was also responsible for cyber attacks on Japan’s critical infrastructures.

The new national strategy has been formalised after soliciting public comment and states that China is believed to be conducting cyber attacks to steal information from firms linked to the military and others with advanced technologies, while Russia is suspected of carrying them out with military and political purposes.The strategy has been finalised by the special task force on cybersecurity strategies headed by Chief Cabinet Secretary, Katsunobu Kato. He had instructed the members to “enhance defence, deterrence and assessment capabilities and strengthen cooperation among relevant bodies to protect security interests.” 

Realising that cyberspace has become a foundation of social and economic activity, it commits to establish a Digital Agency with the aim of achieving “people-friendly digitalisation, with no-one left behind.” In the external environment, it observes the growing interstate competition in the spheres of politics, economy, military affairs, and technology causing geopolitical tensions, even during normal times. 

The outline states that circumstances surrounding cyberspace have taken on an appearance that is neither peacetime nor wartime. On the nature of threats, it observes that there are increasing threats of organised and sophisticated cyber attacks, including those suspected of being state-sponsored, with the aim of service disruption of critical infrastructure, theft of personal information and intellectual property, and interference with democratic processes. It also observes that China, Russia and North Korea are building their cyber capabilities of their military and other institutions.

In 2014, Japan established the national Cybersecurity Strategic Headquarters reporting to the Cabinet for the purpose of effectively and comprehensively promoting cybersecurity policies. The Cybersecurity Strategic Headquarters is headed by the Chief Cabinet Secretary and comprises his deputy who is the Minister-in-charge of Cybersecurity, and other senior government Minister. This body closely coordinates with the National Security Council of Japan reflecting importance given to the cybersecurity in overall national strategy.

A year later in 2015, the National Centre of Incident Readiness and Strategy for Cybersecurity (NISC) was created by upgrading the National Information Security Centre, which was established in 2005. The NISC serves as the secretariat of the Cybersecurity Strategy Headquarters, working together with the public and private sectors on a variety of activities to create a “free, fair and secure cyberspace”. It functions as the focal point in coordinating intra-government collaboration and promoting partnerships between industry, academia, and public and private sectors. .

The Japanese strategy considers cyber security as value creation enabler for socio-economic vitality and sustained development as also an essential aspect for national security. 

  • It stresses on development of secured IoT system, protection of critical infrastructure through public -private partnership, creation of new effective information sharing and collaboration framework, enhancing security measures for national government, encouraging cyber security at academia and research institutes, and enhancing readiness for massive cyber-attack crisis and importantly taking proactive measures for cyber defence and combating cyber crime.
  • Japan places considerable importance to building a trustworthiness in value chains and decides to take appropriate steps in this direction. It states: “security products and services provided in the market must be trustworthy.” Japan emphasises the use of indigenous services and equipment. It plans to make inexpensive, effective, and accessible security services and simple insurance products widely available for SMEs.
  • Japan places greater emphasis on public awareness programme. It plans to advance “DX with Cybersecurity” (DX is a strategy of enabling business innovation predicated on the incorporation of digital technologies into your operational process, products, solutions, and customer interactions) as a society-wide effort to provide “Plus Security” knowledge to various human resources who may not necessarily have expertise or work experience related to IT or security, including management and executives, and ensure smooth collaboration with security experts both inside and outside the organization.
  • Data protection is an important priority: The personal information of the people and information concerning intellectual property, which is a source of international competitiveness, are important assets that the national government must protect. The vulnerabilities for data hosted on cloud has been focused and Japan commits to make people aware about it.
  • Japan commits to strengthen its defence capabilities by securing the nation’s resilience through enhanced capabilities of the Self Defence Forces and other government institutions. Japan also plans to enhance capabilities to detect, investigate, identify the attackers and deter. 
  • It commits support for ‘Free, Fair and Secure Cyberspace’, for strengthening capabilities of defence, deterrence and situational awareness and international cooperation and collaboration and would promote the rule of law in cyberspace. Japan along with others is pushing for strict international law for the governance of the cyberspace.

This strategy calls for enhancing deterrence through the Japan-US alliance by holding joint exercises of the Japanese Self-Defense Forces, US forces.ASEAN partners.

For economic security, this strategy focuses securing the safety of key infrastructure for overseas communications, including submarine communication cables, and creating safety and credibility standards for information technology devices.The strategy reflects the current perception of cyber threats and its ambition to develop a strong deterrent capability against its adversaries. The strategy also indicates growing confidence in dealing with its neighbours.

The Chinese Foreign Ministry has severely criticised Japan for the new cyber security strategy and spokesman  blamed Japan for “groundless slander” against China and Russia on cybersecurity.  He further stated that Japan bad relations with all its neighbours.

While Japan alone may not be able to counter Chinese cyber attacks, in coordination with US and others it can achieve the strategic equilibrium in cyberspace.  In this respect, it can play an important role in countering the forces that are creating instability in that region.   

Intelligence Online:        Bangkok Post:      Times of India:     IFRI:        Image:Unsplash

You Might Also Read:

IISS: Cyber Capabilities & National Power Rankings:

 

« Endpoint Security Is More Important Than Ever
New CSPM Report Highlights The Perceived Security Gap For Cloud Infrastructure »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Entreda

Entreda

Entreda offers a unified platform to automate cybersecurity and compliance policy enforcement for your devices, users, networks, applications.

Silensec

Silensec

Silensec is a management consulting, technology services and training company specialized in information security.

Information & eGovernment Authority (iGA) - Bahrain

Information & eGovernment Authority (iGA) - Bahrain

The Information & eGovernment Authority facilitates many services catering to different parts of the community within the IT sector in Bahrain including information security.

Armis

Armis

Armis offers the markets leading asset intelligence platform designed to address the new threat landscape that connected devices create.

Metrarc

Metrarc

Metrarc has developed a ground-breaking technology called ICMetrics™ for deriving secure encryption keys from the properties of digital systems without the need to store any of the encryption keys.

Red4Sec

Red4Sec

Red4Sec are experts in ethical hacking, audits of web and mobile applications, code audits, cryptocurrency audits, perimeter security and incident response.

Plexal

Plexal

Plexal is East London's innovation centre and co-working space. We offer startups flexible memberships, giving them access to office space plus all the benefits and support they need to scale.

Pentest360

Pentest360

Pentest360 is a 24x7x365 Penetration testing service offered through a feature-rich, centralised platform on the cloud that delivers instant visibility during security assessments.

Wolverhampton Cyber Research Institute (WCRI)

Wolverhampton Cyber Research Institute (WCRI)

Wolverhampton Cyber Research Institute builds on the strength of its members in the area of network and communication security, artificial intelligence, big data and cyber physical systems.

MetaCert

MetaCert

MetaCert’s Zero Trust browser software reduces the risk of organizations being compromised with a phishing-led cyberattack by more than 98%.

Enzoic

Enzoic

Enzoic is an enterprise-focused cybersecurity company committed to preventing account takeover and fraud through compromised credential detection.

SecurIT360

SecurIT360

SecurIT360 is a full-service specialized Cyber Security and Compliance consulting firm.

Reach Security

Reach Security

Reach is the first generative AI platform purpose-built to empower enterprise security teams. With Reach, organizations measure, manage, and improve their enterprise security posture at scale.

Prophet Security

Prophet Security

Prophet Security empowers organizations to triage, investigate, and respond to alerts with unparalleled speed and accuracy.

Longbow Security

Longbow Security

Longbow automates root cause for your application and cloud risks, enabling teams with intelligent remediation actions that reduce the most risk with the least effort.

GoCloud Systems

GoCloud Systems

GoCloud is an IT consulting firm. We provide IT strategy and cloud adoption services to the New Zealand Government, Non-Profit Organisations and private industry.