Japan has drafted new cybersecurity guidelines outlining approximately 150 measures for businesses operating critical infrastructure. The guidelines cover sectors including finance, railways, electricity, and other essential services and warn operators that even closed networks disconnected from the internet are “not necessarily safe.” Companies are urged to prepare for system failures and strengthen their ability to recover from successful attacks rather than relying solely on preventive defenses.
The draft also addresses emerging and systemic risks, recommending measures to mitigate the financial impact of ransomware attacks while discouraging ransom payments. It calls for defenses to evolve in response to cyberattacks using advanced AI models and recommends preparing for the transition to post-quantum cryptography as quantum-computing capabilities advance. Japan’s National Cybersecurity Office developed the guidelines to support more consistent cybersecurity standards across critical-infrastructure sectors.
Why it matters: Japan’s approach reflects a shift from primarily preventing cyberattacks toward ensuring that critical services can continue and recover when defenses fail. The emphasis on closed-network risks, ransomware resilience, AI-enabled threats, and post-quantum security illustrates how governments are broadening critical-infrastructure cybersecurity requirements to address both current operational risks and emerging technologies.
Source: The Japan Times
Author: Jiji
Published: August 24, 2026