## 1jpnea2024005 - EXECUTIVE SUMMARY

## Source details

**Canonical URL:** [1jpnea2024005 - EXECUTIVE SUMMARY](https://www.imf.org/-/media/files/publications/cr/2024/english/1jpnea2024005.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2024/english/1jpnea2024005.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2024/english/1jpnea2024005.pdf.json)

---

### Key findings
- Japan’s financial system is digitalizing rapidly, increasing exposure to cyber risk.
- Cyber incidents have surged in recent years; the number of phishing and ransomware attacks have nearly doubled every year since 2019 (BOJ, 2023, Chart IV-5-4).
- The tight interdependencies within the financial system, and beyond, make Japan vulnerable to evolving cyber threats.
- The cyber ecosystem in Japan is mature, with multiple stakeholders involved, including NISC, FSA, BOJ, Financials ISAC Japan, and industry trade associations.
- The FSA and BOJ have made progress in enhancing cyber resilience, but further work and enhancements are needed across strategy, supervision, oversight of FMIs, interconnectedness analysis, and response/recovery capabilities.
- According to a BOJ survey, digital channels were increasing notably even before the pandemic, and about two-thirds of regional financial institutions expect internet banking services and mobile apps to be adopted more widely as a mode of business in 2023 and beyond.
- The authorities currently have strong cyber incident reporting regimes with clear definitions, taxonomies, thresholds, and communication channels.
- The FSA conducts the annual Delta Wall exercise, testing more than 160 financial entities on incident response capabilities across multiple cyber scenarios.
- Financials ISAC Japan has participation by 436 financial entities.
- The NISC's 2022 cross-sector exercise included 434 financial sector institutions.

### Strategy and governance
- Institutional roles and milestones:
  - NISC: secretariat of the Cybersecurity Strategy Headquarters; develops the Cybersecurity Strategy and the Cybersecurity Policy for Critical Infrastructure Protection.
  - FSA: competent authority for critical infrastructure operator for the financial sector; published "The Policies to Strengthen Cyber Security in the Financial Sector (Ver. 3.0)" in February 2022.
  - BOJ: publishes "On-Site Examination Policy" annually; oversees and operates FMIs such as BOJ-NET.
- Cybersecurity Strategy: primary aim to ensure a cyberspace which is “free, fair, and secure”; five key principles and three key policy areas.
- FSA future focus areas: (1) advancement of monitoring and exercises; (2) preparing for new risks; (3) organization-wide efforts to ensure cybersecurity; (4) strengthening cooperation with related organizations; (5) Economic Security Responses.
- Testing and exercises observations:
  - Mega banks conduct TLPT; approaches differ across financial entities in the absence of industry framework.
  - Recommendation: FSA could develop industry guidance on TLPT and other testing (scenario-based, red team, grey box, purple team, gold team) to provide a standardized framework and enable proportional application across entities.
- Footnote definition preserved: TLPT is a controlled attempt to compromise the cyber resilience of an entity by simulating the tactics, techniques, and procedures of real-life threat actors. It is based on targeted threat intelligence and focuses on an entity’s people, processes, and technology, with minimal foreknowledge and impact on operations.

### Institutional framework and coordination
- High-level assessment: Japan has a mature cyber ecosystem with broad public and private stakeholder coordination (NISC, FSA, BOJ, Financials ISAC Japan, FISC, CEPTOARs, JPCERT/CC, NPA, PPC, Ministry of Defense, Public Security Intelligence Agency).
- Core stakeholder roles:
  - Policy: NISC;
  - Regulation/Supervision: FSA;
  - Oversight/Examination and Monitoring: BOJ;
  - Industry Guidelines: FISC, Industry Associations;
  - Technical Operation/Facilitation of Mutual Assistance: Financials ISAC Japan.
- Coordination mechanisms:
  - Liaison Council for Cybersecurity Stakeholders (launched June 2019) for mutual information coordination and desktop exercises.
  - Financial Monitoring Council (established June 2021) for senior-level FSA–BOJ coordination.
  - FSA holds monthly meetings with financial industry associations; example: February 2023 engagement following Delta Wall VII.
  - FSA coordinates with National Police Agency and Public Security Intelligence Agency for threat intelligence.

### Governance arrangements at the FSA and BOJ; resources
- FSA IT Cyber Monitoring Team:
  - Functions: develop/operationalize sector cyber strategy; monitor and inspect cyber/IT risks; plan/implement cyber exercises; develop supervisory guidelines; incident analysis; disseminate threat information; international cooperation.
  - Composition: mixture of experienced personnel recruited externally and internally trained staff; possesses cybersecurity, IT security, financial regulation, and financial system knowledge.
  - Structural gaps: no structured coordination between horizontal (IT Cyber Monitoring Team) and vertical supervisory functions; limited on-site cybersecurity inspections of FMIs to date; information across divisions could be better used to determine supervisory approach.
  - Resourcing: IT Cyber Monitoring Team is under-resourced while supervising more than 1,000 financial entities and conducting tasks including Delta Wall; essential to increase investment and resources.
- BOJ arrangements:
  - Dedicated IT and cyber monitoring unit; Payment and Settlement Systems Department oversees nine FMIs (including BOJ-NET and CSD-BOJ-NET JGB Services) on a moral suasion basis.
  - Identified weakness: the team of nine overseers in the Payment and Settlement Systems Department has no dedicated cyber expert.

### Cyber regulatory framework and supervisory practice gaps
- Supervisory framework observations:
  - The FSA should update its Comprehensive Supervisory Guidelines (CSG) for all supervised financial entities on cyber risk and align supervisory tools and methodologies to the updated CSGs.
  - The Cybersecurity Self-Assessment (CSSA) checklist contains 42 questions and is useful for high-level views but is not aligned to current CSG; CSSA should be updated once CSGs are updated.
  - Move toward a principles-based approach focusing on outcomes to allow proportionality and risk-based supervision.
- On-site inspection process and timing:
  - The FSA requests submission of necessary documents within approximately 12 business days after notification of inspection.
  - The on-site inspection lasts approximately four weeks.
  - Post-inspection: Inspection Results Notice delivered; financial entity must report facts, self-analysis, and corrective measures within a month under Article 24 of the Banking Act.
  - The FSA began conducting on-site inspections from 2020 and has summarized lessons learnt over the three-year period.
- Supervisory reporting gaps:
  - Reports do not currently link findings to risk/impact, indicate risk rating/severity, or reference supervisory guidelines/requirements; recommended to include a section explaining risk/impact and severity, and reference the supervisory expectation/requirement.
- Supervisory priorities:
  - Recent prioritization focused on deposit-taking institutions and securities firms; off-site/on-site assessment of insurance firms planned; FMIs have received less supervisory focus.
- Off-site monitoring and KRIs:
  - No structured set of Key Risk Indicators (KRIs) currently requested from financial entities; authorities would benefit from developing KRIs and an assessment framework mapped to inherent business risk.

### BOJ oversight of FMIs and BOJ operational recommendations
- Gaps in BOJ oversight:
  - No formal cyber-specific assessment of FMIs, including central bank operated FMIs, against CPMI-IOSCO Cyber Guidance.
  - Not all FMIs have conducted a self-assessment against the Guidance.
  - No joint FSA–BOJ cyber supervision/oversight of commonly supervised/overseen FMIs.
  - BOJ should secure cyber expertise within cyber-related teams.
- BOJ on-site/off-site examination timing:
  - On-site cybersecurity examinations over a period of three weeks to one month depending on size.
- BOJ operational actions recommended:
  - Strengthen cyber risk oversight of FMIs and leverage CPMI-IOSCO Cyber Guidance to gather self-assessments and conduct cyber assessments (including BOJ-operated systems).
  - Consider conducting cyber simulations/table-top exercises with BOJ-NET participants and FMIs connected to BOJ-NET.
  - Make progress on red team testing (TLPT) of its ICT environment.
  - Continue to upgrade BOJ-NET BCP with cyber-specific extreme but plausible scenarios that are regularly tested; BOJ-NET operator confirmed work is ongoing to include a range of extreme but plausible different cyber scenarios starting from 2024.

### Interconnectedness and financial stability
- FSA status and needs:
  - The FSA has documented transmission channels and developed contagion scenarios, but would benefit from deepening analysis of operational interconnectedness ("cyber mapping") to identify critical nodes and transmission channels that could trigger financial instability.
  - Use collected data (e.g., vendors and service providers of IT systems, status of major external systems) to estimate spillovers from incidents at particular vendors or providers.
  - Develop a range of cyber contagion scenarios and use them for sector-wide crisis preparedness via scenario-based testing and incident response.
- Suggested uses of interconnectedness analysis:
  - Identify threats and impacts;
  - Develop scenarios threatening the sector on a systemic level and mitigation strategies;
  - Conduct scenario-based tests or stress testing based on cyber scenarios;
  - Improve incident response capabilities.

### Monitoring, response, and recovery
- Business continuity and CIR frameworks:
  - FSA BCP maintains action lists and manuals but "does not currently address cyber incidents sufficiently."
  - BOJ BCP basic framework published in 2003; three identified BCP scenarios involving Tokyo Head Office and main computer center.
  - BOJ has developed a Cyber Incident Response (CIR) framework classifying incidents in five categories.
  - Rationale: cyber incidents can create financial stability risks via interconnected IT systems, loss of confidence, or capital impacts from losses.
- Exercises and testing:
  - Delta Wall: annual industry-wide exercise since 2016; Delta Wall VIII (2023) had four scenarios and 165 participating financial institutions.
  - Assessment: Delta Wall is "a very well-run exercise" providing deep insight on industry capabilities; emphasizes ex-post evaluation and feedback.
  - Government-led NISC cross-sector exercises had 434 financial sector participants in 2022.
  - BOJ is positioned to conduct cyber simulations and desktop exercises with BOJ-NET participants and FMIs linked to BOJ-NET; industry-wide cyber crisis simulations can test decision-making, communication, collective contingencies, response protocols, and assess FMI ability to meet the two-hour recovery time objective and end of day settlements.
- Red team testing:
  - BOJ should make progress on red team testing (i.e., TLPT) on its ICT environment; a full-scope red team test would help assess protection, detection, and response capabilities by simulating attacks on critical functions and underlying systems.
- Recommendation on CIRR and BCP:
  - The FSA should update BCP or develop a standalone Cyber Incident Response and Recovery (CIRR) plan with a playbook of scenarios, governance arrangements, and thresholds for incidents that could trigger systemic risk.
  - The BOJ should continue to upgrade BOJ-NET BCP with cyber-specific extreme but plausible scenarios that are regularly tested and regularly test the BOJ’s CIR framework.

### Information sharing and incident reporting
- Threat intelligence ecosystem:
  - NISC shares vulnerability and threat information with FSA; NPA and Public Security Intelligence Agency share cybercrime trend information with FSA; Financials ISAC Japan facilitates private sector sharing.
  - FSA disseminates threat information using the Traffic Light Protocol and via the Information Sharing Tool (SIGNAL).
  - FSA staff conduct daily web patrols and receive irregular threat information from the FSA's senior adviser in cybersecurity and Financials ISAC Japan.
- Incident reporting regime:
  - FSA and BOJ have comprehensive incident reporting regimes with clear definitions, severity ratings, templates, and procedures; financial entities must report cyber incidents to their respective financial authorities.
  - The FSA receives incident notifications daily; the IT Cyber Monitoring Team reviews notifications daily and produces aggregated annual analysis.
  - The FSA participates in the FSB’s Cyber Incident Reporting working group and it is recommended that FSA and BOJ review and align their regime with the FSB framework once available.

### Key policy recommendations (extracted from Table 1)
- Strategy and Governance
  - Enhance the cyber strategy by developing industry guidance for a broader testing and exercising regime (e.g., TLPT, purple team testing, cyber simulations). (¶47) — MT — FSA
  - Strengthen governance arrangements and establish a more structured joint supervisory approach between horizontal (IT Cyber Monitoring Team) and vertical (supervisory divisions) functions. (¶48) — ST — FSA
  - Continue to explore means of increasing capacity to strengthen cyber resilience of the financial sector. (¶49) — ST — FSA
- Interconnectedness and Financial Stability
  - Further strengthen analysis of operational interconnectedness, developing network analysis to identify critical nodes. (¶53) — MT — FSA
- Cyber Regulatory Framework and Supervisory Practices
  - Update Comprehensive Supervisory Guidelines (for all sub-sectors) to comprehensively cover cybersecurity; align lessons from on-site inspections, CSSA, and supervisory methodologies/tools to the guidelines; include a section in supervisory reports explaining risk/impact and severity. (¶77) — MT — FSA
  - Increase off-site and on-site cyber supervision of FMIs, with relevant divisions working closely with the IT Cyber Monitoring Team. (¶78) — I — FSA
  - Further increase/enhance skills and expertise of FMI overseers with regard to cyber. (¶79) — ST — BOJ
  - Strengthen oversight approach on cyber resilience for FMIs (including BOJ-operated FMIs) against the CPMI-IOSCO Cyber Guidance. (¶80) — ST — BOJ
  - Enhance coordination/cooperation to strengthen supervisory/oversight approach on cyber for commonly supervised/overseen FMIs. (¶81) — I — FSA and BOJ
  - Develop a set of Key Risk Indicators (KRIs) to improve off-site monitoring of financial entities. (¶82) — ST — FSA and BOJ
- Monitoring, Response and Recovery
  - Consider developing a Generic Threat Landscape (GTL) Report setting out the specific threat landscape for the Japanese financial system. (¶111) — MT — FSA and BOJ
  - Make progress on red team testing on its ICT environment. (¶112) — ST — BOJ
  - Update BCP or develop a standalone CIRR plan with a playbook of scenarios that are regularly tested; set governance arrangements and thresholds for incidents that could trigger systemic risk. (¶113) — ST — FSA
  - Continue upgrading BOJ-NET BCP with cyber-specific extreme but plausible scenarios that are regularly tested. (¶114) — ST — BOJ
  - Test the BOJ’s CIR framework regularly. (¶115) — ST — BOJ
  - As overseer and operator of BOJ-NET, consider conducting cyber exercises/simulations (e.g., table-top exercises) for BOJ-NET with relevant parties. (¶116) — ST — BOJ
- Information Sharing and Incident Reporting
  - Review whether existing incident reporting regime is appropriate in light of international CIR discussions (e.g., at the FSB) and bring it into alignment with the FSB’s cyber incident reporting framework, once completed, if appropriate. (¶121) — ST — FSA and BOJ

- Timing legend (preserved as in source): I Immediate (within 1 year); ST Short Term (within 1-2 years); MT Medium Term (within 3î5 years).

*Source: EXECUTIVE SUMMARY (1jpnea2024005) — IMF technical note for Japan.*

### EXECUTIVE SUMMARY __________________________________________________________________________ 5

### 1jpnea2024005 - EXECUTIVE SUMMARY

### Key findings
- Japan’s financial system is digitalizing rapidly, increasing exposure to cyber risk.
- Cyber incidents have surged in recent years; the number of phishing and ransomware attacks have nearly doubled every year since 2019 (BOJ, 2023, Chart IV-5-4).
- The tight interdependencies within the financial system, and beyond, make Japan vulnerable to evolving cyber threats.
- The cyber ecosystem in Japan is mature, with multiple stakeholders involved, including NISC, FSA, BOJ, Financials ISAC Japan, and industry trade associations.
- The FSA and BOJ have made progress in enhancing cyber resilience, but further work and enhancements are needed across strategy, supervision, oversight of FMIs, interconnectedness analysis, and response/recovery capabilities.
- According to a BOJ survey, digital channels were increasing notably even before the pandemic, and about two-thirds of regional financial institutions expect internet banking services and mobile apps to be adopted more widely as a mode of business in 2023 and beyond.
- The authorities currently have strong cyber incident reporting regimes with clear definitions, taxonomies, thresholds, and communication channels.

### Strategy and governance observations
- NISC plays a leading role as a focal point coordinating intra-government collaboration and promoting public–private partnerships; it develops the Cybersecurity Strategy and the Cybersecurity Policy for Critical Infrastructure Protection.
- The FSA is responsible for developing and operationalizing the cyber strategy for the financial sector and coordinates closely with BOJ, NISC, Financials ISAC Japan, National Police Agency, and industry.
- The FSA could further enhance its cyber strategy by developing industry guidance around testing and exercising to allow heterogeneous financial entities to conduct proportionate tests (e.g., TLPT, purple team testing, cyber simulations).

### Cyber regulatory framework and supervisory practice gaps
- The FSA should update its Comprehensive Supervisory Guidelines (CSG) for all supervised financial entities on cyber risk.
- The FSA should implement a more structured, risk-based approach to cyber risk supervision, supported by adequate tools, and align supervisory tools and methodologies to the updated CSGs to enhance on-site inspections and off-site monitoring.
- The FSA should prioritize cyber supervision of Financial Market Infrastructures (FMIs).
- The FSA cyber supervision unit should be given sufficient resources and use a mix of regulatory tools (e.g., independent auditors) to maximize efficiency.

### BOJ oversight of FMIs
- The BOJ should strengthen cyber risk oversight of FMIs and leverage the CPMI-IOSCO Cyber Guidance to gather self-assessments and conduct cyber assessments of FMIs, including central bank–operated systems.
- The BOJ oversight function would benefit from securing cyber expertise within cyber-related teams to increase capabilities and effectiveness.
- The BOJ, as both overseer and operator (e.g., BOJ-NET), should consider conducting cyber simulations/table-top exercises with BOJ-NET participants and FMIs connected to BOJ-NET.

### Interconnectedness and financial stability
- The FSA would benefit from deepening analysis of operational interconnectedness (cyber mapping) to understand how financial entities and FMIs are operationally and technologically interconnected and to identify transmission channels that could trigger financial instability.
- The FSA should develop a range of cyber contagion scenarios and use them to build stronger sector-wide crisis preparedness through scenario-based testing and incident response.

### Monitoring, response, and recovery
- Authorities should keep upgrading extreme but plausible cyber scenarios and existing Business Continuity Plans (BCP) and/or Cyber Incident Response and Recovery Plans (CIRR) for the financial sector.
- The FSA conducts the annual Delta Wall exercise, testing more than 160 financial entities on incident response capabilities across multiple cyber scenarios, providing insight into sector strengths and weaknesses.
- The BOJ should continue to upgrade BOJ-NET BCP with cyber-specific scenarios and regularly test the BOJ’s Cyber Incident Response (CIR) framework.
- Progress is recommended on red team testing of the ICT environment and development/testing of standalone CIRR plans with playbooks that define governance arrangements and thresholds for incidents that could trigger systemic risk.

### Information sharing and incident reporting
- Japan has strong information and intelligence sharing practices between public and private sectors enabling a free flow of threat information.
- As the Financial Stability Board (FSB) completes work on Cyber Incident Reporting and develops a standard for reporting, Japanese authorities may benefit from reviewing and aligning their existing incident reporting framework with the FSB framework where appropriate to contribute to global convergence.

### Key policy recommendations (from Table 1: Japan: Recommendations on Cyber Resilience and Financial Stability)
- Strategy and Governance
  - Enhance the cyber strategy over the longer term by developing industry guidance for a broader testing and exercising regime e.g., threat-led penetration testing (TLPT), purple team testing, and cyber simulations, among others. (¶47) — MT — FSA
  - Strengthen governance arrangements and establish a more structured joint supervisory approach between the horizontal (i.e., IT Cyber Monitoring Team) and vertical (i.e., supervisory divisions) functions, including better information sharing between them. (¶48) — ST — FSA
  - Continue to explore means of increasing its capacity to fulfill its role in strengthening the cyber resilience of the Japanese financial sector. (¶49) — ST — FSA
- Interconnectedness and Financial Stability
  - Further strengthen the analysis of how the financial sector is operationally interconnected, developing network analysis to identify critical nodes. (¶53) — MT — FSA
- Cyber Regulatory Framework and Supervisory Practices
  - Update Comprehensive Supervisory Guidelines (for all sub-sectors) to comprehensively cover cybersecurity; align lessons from on-site inspections, CSSA, and supervisory methodologies/tools to the guidelines; include a section in supervisory reports explaining risk/impact and severity to facilitate prioritization and reference supervisory expectations/requirements. (¶77) — MT — FSA
  - Increase off-site and on-site cyber supervision of FMIs, with relevant divisions working closely with the IT Cyber Monitoring Team. (¶78) — I — FSA
  - Further increase/enhance skills and expertise of FMI overseers with regard to cyber. (¶79) — ST — BOJ
  - Strengthen oversight approach on cyber resilience for FMIs (including BOJ-operated FMIs) against the CPMI-IOSCO Cyber Guidance. (¶80) — ST — BOJ
  - Enhance coordination/cooperation to strengthen supervisory/oversight approach on cyber for commonly supervised/overseen FMIs. (¶81) — I — FSA and BOJ
  - Develop a set of Key Risk Indicators (KRIs) to improve off-site monitoring of financial entities. (¶82) — ST — FSA and BOJ
- Monitoring, Response and Recovery
  - Consider developing a Generic Threat Landscape (GTL) Report setting out the specific threat landscape for the Japanese financial system, considering geopolitical and criminal threats. (¶111) — MT — FSA and BOJ
  - Make progress on red team testing on its ICT environment. (¶112) — ST — BOJ
  - Update BCP or develop a standalone CIRR plan with a playbook of scenarios that are regularly tested; set out governance arrangements and thresholds for incidents that could trigger systemic risk. (¶113) — ST — FSA
  - Continue upgrading BOJ-NET BCP with cyber-specific extreme but plausible scenarios that are regularly tested. (¶114) — ST — BOJ
  - Test the BOJ’s CIR framework regularly. (¶115) — ST — BOJ
  - As overseer and operator of BOJ-NET, consider conducting cyber exercises/simulations (e.g., table-top exercises) for BOJ-NET with relevant parties to strengthen responses to incidents with material impacts on payment and settlement systems. (¶116) — ST — BOJ
- Information Sharing and Incident Reporting
  - Review whether existing incident reporting regime is appropriate in light of international CIR discussions (e.g., at the FSB) and bring it into alignment with the FSB’s cyber incident reporting framework, once completed, if appropriate. (¶121) — ST — FSA and BOJ

- Timing legend (preserved as in source): I Immediate (within 1 year); ST Short Term (within 1-2 years); MT Medium Term (within 3î5 years).

*Source: EXECUTIVE SUMMARY (1jpnea2024005) — IMF technical note for Japan.*

### 7.      Conclusions and recommendations of the FSAP review are aligned with international

### 7.      Conclusions and recommendations of the FSAP review are aligned with international

### Strategy and Governance — A. Cyber Strategy
- The FSAP review used internationally recognized regulatory good practice as the basis of this note, benchmarking against: the FSB “Stocktake of Publicly Released Cybersecurity Regulations, Guidance and Supervisory Practices” in 2017; the BCBS “Cyber-resilience: Range of practices” in 2018; the IMF Departmental Paper on “Cybersecurity Risk Supervision”; the G7 “Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector”; the “Basel Principles for Operational Resilience”; the revised “Principles for Sound Management of Operational Risk”; and, for FMIs, the CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures.

- Institutional milestones and documents:
  - Cybersecurity Strategic Headquarters established under the Cabinet in November 2014; headed by the Chief Cabinet Secretary with the Minister in charge of Cybersecurity as deputy head.
  - National center of Incident readiness and Strategy for Cybersecurity (NISC) established since 2015 as secretariat of the Cybersecurity Strategy Headquarters; responsible for developing the Cybersecurity Strategy and the Cybersecurity Policy for Critical Infrastructure Protection (CIP).
  - Cybersecurity Strategy published in September 2015 and revised in July 2018 and September 2021; decided by the Cabinet based on Article 12 of the Basic Act on Cybersecurity.
  - Cybersecurity Policy for Critical Infrastructure Protection (latest version published on June 17, 2022) designates the financial sector as one of 14 critical infrastructures and assigns the FSA as the competent authority for critical infrastructure operator for the financial sector.
  - FSA published "The Policies to Strengthen Cyber Security in the Financial Sector (Ver. 3.0)" in February 2022; prior versions were published in July 2015 and October 2018.
  - BOJ annually publishes the "On-Site Examination Policy," content determined by the Policy Board.

- Cybersecurity Strategy aims and principles:
  - Primary aim: ensure a cyberspace which is “free, fair, and secure”.
  - Five key principles: (i) assurance of the free flow of information; (ii) the rule of law; (iii) openness; (iv) autonomy; and (v) collaboration among multiple stakeholders.
  - Three key policy areas: (1) advancing digital transformation and cybersecurity simultaneously; (2) ensuring the overall safety and security of cyberspace as it becomes increasingly public, interconnected, and interrelated; and (3) enhancing initiatives from the perspective of Japan’s national security.

- Cybersecurity Policy for Critical Infrastructure Protection expectations (five measures):
  - (i) enhancement of incident response capability;
  - (ii) maintenance and promotion of the safety principles;
  - (ii i) enhancement of information sharing system;
  - (iv) utilization of risk management;
  - (v) enhancement of the basis for CIP.

- FSA assessment of progress (six key areas improved since 2018):
  - 1) response to accelerated digitalization;
  - 2) engagement in international discussions;
  - 3) response to the Tokyo 2020 Games;
  - 4) strengthening the cybersecurity of financial entities;
  - 5) improvement of the information sharing framework;
  - 6) improvement of human resources development in the financial sector.

- FSA future focus (five areas):
  - 1) advancement of monitoring and exercises;
  - 2) preparing for new risks;
  - 3) organization-wide efforts to ensure cybersecurity;
  - 4) strengthening cooperation with related organizations;
  - 5) Economic Security Responses.

- FSA planned actions to address the five focus areas:
  - Increasing its inspections and monitoring of financial entities to enhance their cyber risk management and incident response capabilities;
  - Developing and using a self-assessment tool on cybersecurity for regional financial institutions, to assess their cyber posture and direct improvements in their cybersecurity measures;
  - Continuing to run the cyber exercise (Delta Wall) to help improve the ability of the financial sector to respond to cyber-attacks;
  - Developing forward looking policy on new risk areas, such as cloud usage and cashless payment services;
  - Emphasizing the need of senior management at financial entities to prioritize cyber risk, through their own increased involvement and investment in human resources;
  - Strengthening collaboration with other agencies (e.g., NISC).

- BOJ on-site examination focus areas for cybersecurity (to be examined):
  - (1) the appropriateness of the collection and sharing of information on developments in ever-changing cybersecurity threats;
  - (2) the effectiveness of countermeasures against vulnerabilities;
  - (3) the appropriateness of the management of access rights for important data such as customer information;
  - (4) the effectiveness of measures to prevent cyber-attacks and limit damage caused by such attacks, including effectiveness of frameworks and contingency plans to recover critical operations, implementation of drills, and review of management frameworks reflecting the outcomes of such drills.

- Observations and recommendation on testing and exercises:
  - Current state: mega banks conduct TLPT; approaches differ across financial entities in the absence of industry framework.
  - Recommendation: FSA could enhance overall cyber strategy by developing industry guidance on TLPT and other forms of testing (e.g., scenario-based testing, red team testing, grey box testing, purple team testing, gold team testing, etc.) to:
    - provide a standardized framework for legitimate TLPT and other tests;
    - catalyze broader range of tests across industry and enable regulators to obtain greater assurance on resilience;
    - allow proportional application of test types across different sizes and types of financial entities given costs and resource intensity of TLPT.

- Footnote definition preserved:
  - TLPT is a controlled attempt to compromise the cyber resilience of an entity by simulating the tactics, techniques, and procedures of real-life threat actors. It is based on targeted threat intelligence and focuses on an entity’s people, processes, and technology, with minimal foreknowledge and impact on operations.

### Institutional Framework — B. Institutional Framework
- High-level assessment:
  - Japan has a mature cyber ecosystem with broad public and private stakeholder coordination.
  - NISC, FSA and BOJ have built capacity across the industry and established strong public-private structures for information flow and initiatives.
  - Roles include policymaking, supervisory and operational functions with well-defined responsibilities and clear collaboration.

- Core stakeholder roles (as summarized in Table 2 structure):
  - Policy: NISC;
  - Regulation/Supervision: FSA;
  - Oversight/Examination and Monitoring: BOJ;
  - Industry Guidelines: FISC, Industry Associations;
  - Technical Operation/Facilitation of Mutual Assistance: Financials ISAC Japan.
  - Source attribution for table: IMF staff.

- Additional non-financial stakeholders with roles in financial sector cybersecurity:
  - NISC, Japan Computer Emergency Response Team Coordination Center (JPCERT/CC), National Police Agency (NPA), Financials ISAC Japan, Center for Financial Industry Information Systems (FISC), CEPTOARs (Japanese Bankers Association, Life Insurance Association of Japan, General Insurance Association of Japan, Japan Securities Dealers Association, and Japan Payment Service Association), Ministry of Defense, Public Security Intelligence Agency, and the Personal Information Protection Commission (PPC).

- FISC role:
  - Not an authority but a public interest incorporated foundation accredited by the Prime Minister.
  - Engaged in cybersecurity-related activities and, with involvement of FSA and BOJ, developed information security guidelines for the financial industry which have become the de facto standard for risk management and cybersecurity for IT systems in the financial industry.

- FSA engagement with broader cybersecurity governance:
  - FSA is a member of the Cyber Security Council established under Article 17 of the Basic Act on Cybersecurity; JPCERT/CC serves as the Secretariat of the Council.
  - FSA maintains cooperative relationship with JPCERT/CC through Council activities.

### Coordination and Cooperation — C. Coordination and Cooperation
- FSA–NISC coordination:
  - Two-way information sharing (threat intelligence, incident reporting, etc.) and participation in NISC-hosted meetings underpinned by the Basic Act on Cybersecurity.
  - When a cyber incident occurs, the FSA receives an immediate report from the affected financial entity; if the entity is critical infrastructure (deposit-taking institutions including banks, insurance companies, securities companies, payment service providers and FMIs), the FSA shares the matter with the NISC in accordance with Article 32 of the Basic Act on Cybersecurity and the agreement with the NISC.

- Public-private cooperation mechanisms:
  - "Liaison Council for Cybersecurity Stakeholders" launched in June 2019 to enable mutual information coordination in the event of cyber incidents, including large-scale incidents, in collaboration with BOJ, respective sub-sector’s CEPTOAR, Financials ISAC Japan and FISC.
  - The Liaison Council shares cooperation procedures with related public and private organizations and assesses effectiveness of cooperation framework via desktop exercises.

- FSA–BOJ coordination:
  - Financial Monitoring Council established in June 2021 as a senior-level meeting platform between the FSA and the BOJ to promote initiatives for enhanced coordination to conduct effective monitoring (including cybersecurity).
  - In the Council, FSA shares information with BOJ and coordinates status of coordination and policies of initiatives between the two.

- Ongoing industry engagement:
  - FSA holds monthly meetings with financial industry associations to share information and hold Q&A sessions on matters to be shared (including cyber risk).
  - Example: February 2023 meeting — FSA called on financial entities that participated in Delta Wall VII (held in October 2022) to use exercise results to improve incident response capabilities and called on non-participants to use common challenges and good practices identified to enhance incident response, including exercises and training.

- Coordination with intelligence agencies:
  - FSA coordinates closely with National Police Agency and Public Security Intelligence Agency to strengthen intelligence gathering on cyber threats and use information/intelligence in supervision of financial entities in a timely manner.

*Source: IMF staff based on the FSAP review content provided.*

### 33.      In Japan, cybercrime is defined by the Penal Code, and Special Acts such as the Act on

### 1jpnea2024005 - 33.      In Japan, cybercrime is defined by the Penal Code, and Special Acts such as the Act on

### Cybercrime, law enforcement, and financial supervision
- Cybercrime in Japan is defined by the Penal Code and Special Acts such as the Act on Prohibition of Unauthorized Computer Access.
- The FSA is not the competent authority for criminal laws; cooperation with law enforcement occurs primarily at the operational level.
- Law enforcement authorities provide intelligence on cyber threats through cybercrime investigations and expect financial entities to take actions to prevent incidents and mitigate damage from the viewpoint of crime prevention.
- The FSA expects financial entities to take actions to prevent incidents and mitigate damage by utilizing intelligence on cyber threats for the benefit of the financial system, financial entities, and their customers.
- Example of cooperation outcome: the FSA issued requests to financial entities and the general public to prevent cybercrime based on the National Police Agency's intelligence on phishing.
- In the Japanese criminal justice system, public prosecutors have a monopoly on the right to file criminal charges; public prosecutors and prefectural police conduct investigations and collect evidence for prosecution based on legal authority.
- The FSA and financial entities cooperate in investigations in response to requests from public prosecutors and the police; investigative activities necessary for criminal charges follow laws and regulations and do not require special arrangements between law enforcement, the FSA, and financial entities.

### Governance arrangements at the FSA and BOJ
- The FSA has established the IT Cyber Monitoring Team as a Cybersecurity Center of Excellence to enhance cyber risk supervision capabilities.
- The IT Cyber Monitoring Team composition and capabilities:
  - Mixture of experienced personnel recruited from the market and internally trained staff with extensive knowledge in cybersecurity.
  - Possesses knowledge of cybersecurity, IT security, financial regulations, business profiles of financial entities, and the financial system.
  - Aims to further improve staff capabilities through on-the-job training and internal training.
- IT Cyber Monitoring Team responsibilities include:
  - (1) developing and operationalizing the cyber strategy for the financial sector;
  - (2) monitoring and inspecting the risks related to cyber and IT systems, including data management, of financial entities;
  - (3) planning and implementation of cyber exercises;
  - (4) development of supervisory guidelines and regulations for cyber risk;
  - (5) dialogues on IT governance with stakeholders;
  - (6) analysis of the incidents related to IT system failure;
  - (7) dissemination of threat information to financial entities; and
  - (8) international cooperation.
- External and internal coordination:
  - Works closely with NISC, governmental ministries, the BOJ, FISC, Financials ISAC Japan and foreign authorities.
  - Must collaborate closely with vertical supervisory functions (prudential supervisors of banking, securities, insurance and FMIs) which are generalist supervisors and rely heavily on the IT Cyber Monitoring Team’s expertise.
- Structural coordination gaps:
  - No structured coordination between horizontal (IT Cyber Monitoring Team) and vertical supervisory functions, despite interaction and ad hoc assistance.
  - No on-site cybersecurity inspections of FMIs to date, limiting collaboration with supervisory divisions responsible for FMIs.
  - Information gathered across divisions (incident information, threat information, off-site and on-site supervisory data) could be better used to determine supervisory approach and actions; e.g., weaknesses in access control could have prompted different supervisory actions.
  - Strengthening internal coordination would support more effective, risk-based cyber supervision and increased awareness among internal stakeholders.
- Bank of Japan (BOJ) arrangements:
  - The BOJ has a dedicated IT and cyber monitoring unit staffed with experts responsible for monitoring and inspecting financial entities that have an account with the BOJ, as well as international cooperation.
  - The BOJ’s Payment and Settlement Systems Department oversees nine FMIs, including the central bank operated FMIs (BOJ-NET Fund Transfer System and CSD-BOJ-NET JGB Services) on a moral suasion basis.

### Resources
- FSA staffing and resource context:
  - The FSA has an IT Cyber Monitoring Team with several members dedicated to examining and monitoring IT and cyber risks in the securities sector; these teams, together with supervisors of individual financial entities, fulfill various cybersecurity functions.
  - The IT Cyber Monitoring Team is under-resourced while supervising more than 1,000 financial entities and undertaking tasks including developing and operationalizing the cyber strategy, updating supervisory guidelines, managing cyber incidents, and conducting the Delta Wall exercise.
  - Despite resource constraints, the IT Cyber Monitoring Team has made significant strides in developing cyber supervision capacity, but limited staff numbers have impacted capacity for effective regulation and cyber supervision.
  - Given increased cyber risk and criticality of the financial sector, it is essential the FSA increases investment and resources in this area.
- BOJ resources:
  - The BOJ has a financial institution IT and Cyber Monitoring team conducting on-site operational risk examinations, including IT and cyber risk.
- Overall resource assessment:
  - The central bank and financial regulator require significant additional resources and tools to fulfill mandates regarding cyber risk; there is a critical need for substantial additional resources, approaches, and tools to mitigate cyber risk to acceptable risk tolerance levels.

### Recommendations (FSA and supervisory practice)
- Short-to-longer term enhancements:
  - The FSA could enhance the cyber strategy by developing industry guidance for a broader testing and exercising regime, e.g., threat-led penetration testing (TLPT), purple team testing, and cyber simulations, among others.
  - Strengthen governance arrangements and establish a more structured joint supervisory approach between horizontal (IT Cyber Monitoring Team) and vertical (supervisory divisions) functions to:
    - increase awareness of cyber risk among supervisors;
    - allow a more focused and risk-based supervisory approach; and
    - improve information sharing to facilitate more focused, risk-based supervision across different types of financial entities.
  - Continue exploring means of increasing capacity to strengthen cyber resilience of the financial sector, including:
    - increasing specialized staff numbers;
    - recruiting highly skilled personnel;
    - upskilling generalist supervisors in cyber risk to reduce pressure on cyber risk specialists;
    - increasing the number of secondments from other agencies; or
    - using different approaches and tools such as increased use of third-party independent assurance reports.
- Interconnectedness and systemic risk analysis:
  - The FSA should deepen analysis of cyber interconnectedness (“cyber mapping”) to identify potential systemic risks from interconnectedness and concentrations, and to understand how shocks to one supervised entity/service provider can spread to others.
  - Use collected data (e.g., vendors and service providers of IT systems, status of major external systems) to estimate spillovers from incidents at particular vendors or providers.
  - Suggested uses of interconnectedness analysis:
    - Identify threats and their impact on the sector;
    - Develop a range of scenarios that could threaten sectors on a systemic level and develop mitigation strategies accordingly;
    - Conduct scenario-based tests or stress testing based on cyber scenarios; and
    - Improve incident response capabilities.
- Supervisory framework and tools:
  - Update the Comprehensive Supervisory Guidelines (CSG) for all sub-sectors to cover cybersecurity requirements more comprehensively; consider categories in Annex 1 and international standards and best practices.
  - Move toward a principles-based approach focusing on outcomes rather than prescriptive rules to allow proportionality and risk-based supervision.
  - Align supervisory tools with updated CSG:
    - The Cybersecurity Self-Assessment (CSSA) checklist contains 42 questions and is useful for high-level views but is not aligned to current CSG; once CSGs are updated, update CSSA questions to reflect CSG requirements to enable more structured and systematic supervision.
  - Recognize diversity of tools in use:
    - Large entities often use the U.S. FFIEC Cybersecurity Assessment Tool (research study and tentative Japanese translation published in August 2016).
    - The FSA reflects the G7 Cyber Expert Group's Fundamental Elements and the Principles for Financial Market Infrastructures (PFMIs) in supervision; these are more principles-based and differ extensively from the FFIEC.
  - Continue enhancing monitoring and exercises to respond to evolving threats (noting publication of "The Policies to Strengthen Cybersecurity in the Financial Sector (Ver. 3.0)" in February 2022).
  - Off-site cyber risk supervision areas include:
    - (1) corporate governance;
    - (2) risk and internal controls and risk;
    - (3) technical response, third party risk management, and other risk assessments and measures commensurate with the environment surrounding the institution;
    - (4) resilience (including contingency plan, training, and incident response); and
    - (5) audit.

### Interconnectedness and financial stability: analysis and BOJ role
- FSA actions and status:
  - The FSA has documented transmission channels by which cyber-attacks could trigger financial instability, developed contagion scenarios, and identified potential impacts and mitigation strategies.
  - Conducting interconnectedness analysis would further strengthen documentation of transmission channels and contagion scenarios.
- BOJ actions:
  - BOJ regularly identifies and analyzes latest trends in cyber threats, collects data on phishing, ransomware attacks, fraudulent money transfers, and distinctive cyber-attacks through published materials and interviews with security vendors, and utilizes on-site and off-site monitoring.
  - BOJ conducts ad-hoc surveys based on latest cyber threat trends and uses survey results to encourage financial entities to implement cyber security measures, publishing findings externally in the Financial System Report (FSR) Annex Series.

*Source: FSA; and IMF staff.*

### 62.      On top of this, the FSA conducts through-the-year monitoring of the three mega

### 1jpnea2024005 - 62.      On top of this, the FSA conducts through-the-year monitoring of the three mega

### On-site inspections and supervisory process
- The FSA conducts on-site inspections in accordance with laws and regulations to assure financial stability and customer protection and selects financial entities to be inspected on a risk basis.
- In conducting on-site cybersecurity inspections, the FSA conducts tests to verify the effectiveness of controls at the financial entities in question.
- Inspections are conducted in accordance with the procedures prescribed in the CSG.
- Timeline and procedural steps:
  - The FSA will request the submission of necessary documents within approximately 12 business days after the notification of the inspection and investigate the matters to be focused before the on-site inspection through pre-hearing interviews.
  - The on-site inspection lasts approximately four weeks.
  - During the inspection period:
    - (1) Problems identified up to the pre-hearing will be verified in light of the evidence, discussed with the financial entities, and their background causes will be investigated and identified.
    - (2) Facts and problems will be clearly documented and confirmed with the financial entities.
    - (3) A report of inspection results will be prepared by integrating the confirmed facts and problems and it will be sent to the FSA back office for quality control review process including consistency with other inspections.
    - (4) After the review, a high rank official of the FSA will deliver the Inspection Results Notice to the senior management of the financial entity to articulate points requiring improvement.
  - When the Inspection Results Notice is delivered, the financial entity will be ordered based on Article 24 of the Banking Act to report the facts behind the findings, self-analysis of the causes, measures for improvement and correction, etc. within a month.
  - During subsequent follow-up, the FSA evaluates the concreteness and effectiveness of the improvement plan, requests submission of evidence as necessary, and verifies whether the root cause of the identified problematic issue has been resolved.
  - In cases where the entity’s cybersecurity management posture is deemed to have a serious problem based on inspection results, etc., the supervisory departments should take actions such as issuing an order for business improvement under Article 26 of the Banking Act.
  - The progress of improvement shall be periodically reported to the supervisory departments, and the progress shall be examined until the rectification plan is completed.
  - The FSA will make additional interventions (such as business improvement orders) if the self-rectification mechanism does not work and if it is deemed that there will be a serious impact on the soundness of the financial entity, customer interests, or financial stability.
- The FSA began conducting on-site inspections from 2020 and have recently summarized the lessons learnt from on-site inspections based on experience gathered over the three-year period.
- The FSA should update the lessons learnt to align them with the updated CSG to allow supervisors to evaluate financial entities more effectively against the supervisory requirements and enable a more standardized and systematic approach to supervision.
- Post-inspection supervisory reports:
  - Supervisory reports are well drafted and clearly articulate the issues and facts.
  - Reports currently do not:
    - Link the findings to the risk and impact of the weaknesses materializing.
    - Indicate the risk rating/severity of the finding and how they should be prioritized.
    - Indicate which supervisory guidelines/requirements the findings relate to.
  - The FSA could enhance supervisory reports by including a section that explains the risk/impact of the findings materializing and the severity/rating of the findings, and reference the supervisory expectation/requirement.

### Financial Market Infrastructures (FMIs) oversight and gaps
- Recent FSA supervisory prioritization:
  - The FSA prioritized supervisory efforts on deposit-taking institutions and securities firms and now intends to assess insurance firms through off-site, on-site, and surveys (i.e., CSSA).
  - There has been less focus on FMIs than banks.
- Importance of FMIs:
  - FMIs are essential to maintaining and promoting financial stability and economic growth.
  - If not properly managed, FMIs can be sources of financial shocks (liquidity dislocations, credit losses) or channels for transmission across markets.
  - Cyber resilience contributes to an FMI’s operational resilience and can be decisive for overall financial system resilience.
- FMIs regulated and supervised by the FSA (excluding foreign CCPs) include:
  - Japan Securities Clearing Corporation; JASDEC DVP Clearing Corporation; Tokyo Financial Exchange, Inc.; Japanese Banks' Payment Clearing Network (Zengin-Net); DTCC Data Repository (Japan) K.K.; Japan Securities Depository Center, Incorporated; and JGB Book-Entry System (BOJ-NET JGB Services).
- The FSA, in recent years, has not conducted a cyber assessment or on-site cybersecurity inspection of FMIs in Japan, whilst off-site monitoring has been minimal.
- The FSA should prioritize cyber supervision of FMIs, given their critical role.

### BOJ oversight of FMIs and cyber capability gaps
- The BOJ is not a regulator nor prudential supervisor of financial entities but oversees nine domestic FMIs, including two central-bank operated FMIs (its RTGS system—BOJ-NET Fund Transfer System—and the CSD-BOJ-NET JGB Services) on a moral suasion basis.
- Identified weaknesses in BOJ’s cyber oversight approach:
  - The Payment and Settlement Systems Department conducts annual assessments against the PFMIs, which includes Principle 17 (Operational Risk) but there has been no formal cyber-specific assessment of FMIs, including of the central bank operated FMIs.
  - Not all the FMIs have conducted a self-assessment against the CPMI-IOSCO Cyber Guidance (Guidance) for FMIs.
  - The FSA and BOJ have not conducted any joint cyber supervision/oversight of commonly supervised/overseen FMIs.
  - In the team of nine overseers at the BOJ’s Payment and Settlement Systems Department, there is no dedicated cyber expert; assistance is provided by senior-official(s) of the Department, as well as the IT and Cyber Monitoring teams in other departments when requested.

### BOJ on-site and off-site examinations
- On-site cybersecurity examinations by the BOJ:
  - The BOJ assesses the content of relevant materials (evidence) submitted by financial entities and conducts interviews with the relevant personnel when on-site.
  - The BOJ visits relevant business departments to visually check whether the cybersecurity-related rules are appropriately operated.
  - On-site cybersecurity examinations are conducted over a period of three weeks to one month, depending on the size of the financial entity.
  - The BOJ checks the status of improvements of any identified issues at the time of the next examination.
  - The BOJ develops a follow-up policy for each entity identified as having a serious deficiency in its cybersecurity management frameworks and monitors the status of improvement through on-site and off-site monitoring.
  - The BOJ uses an On-site Practice Manual and a pre-defined checklist of documents for on-site examinations; the manual and checklist are well drafted and provide adequate coverage.
- Off-site monitoring:
  - The FSA and BOJ conduct off-site monitoring, but there is no structured set of Key Risk Indicators (KRIs) that the FSA and BOJ requests from its financial entities.
  - Cyber threat preparedness can change rapidly; on-site assessments give snapshots at infrequent intervals.
  - Given limited resources for on-site examinations, monitoring via KRIs is a useful tool to increase efficiency.
  - The FSA and BOJ would benefit from establishing an assessment framework to evaluate efficacy of controls based on KRIs mapped to inherent business risk.

### Threat monitoring, intelligence, and red team testing
- Sources and threat information:
  - The FSA and BOJ monitor the threat landscape using sources based on collaboration with public, private, domestic, and international agencies.
  - Authorities assess threats based on information provided by (i) the NISC, (ii) the NPA, (iii) financial institutions and FMIs, and (iv) information gathered by the FSA and BOJ themselves.
  - The NISC collects and analyzes cybersecurity threat information and disseminates it to the FSA and other ministries and agencies responsible for critical infrastructure.
  - The NISC is the most important source of information for the FSA and BOJ and alerts financial entities to threats that are observed to be increasing in severity.
  - The FSA, in cooperation with the NPA, shares phishing techniques and damage information to prevent crimes and minimize damage caused by fraudulent internet banking remittances.
- Incident reporting and information sharing:
  - Financial entities are required by orders pursuant to law to report cyber incidents to the FSA.
  - The FSA analyzes reported cyber incidents and, if a risk is identified that is not limited to an individual entity, urges financial entities to exercise caution.
  - The FSA shares vulnerability information with the Financials ISAC Japan through the Information Sharing Tool (SIGNAL).
  - The FSA's senior adviser in cybersecurity and the Financials ISAC Japan provide the FSA with threat information on an irregular basis.
  - FSA staff conduct daily web patrols, including social media and open source, to check the emergence of threats.
- Evolving threat landscape:
  - Since the COVID-19 crisis, cyber threats in Japan have become more sophisticated and malicious, shifting from individual actors to organized criminal groups and actors suspected of state involvement.
  - Types of attacks seen frequently recently include DoS/DDoS attacks and unauthorized logins to services.
  - Emerging major incident types by degree of materiality include:
    - (1) customer data leakage,
    - (2) unauthorized withdrawals of funds due to misuse of authentication information stolen through phishing,
    - (3) ransomware attacks,
    - (4) incidents that led to the suspension of business operations, such as the suspension of websites and online transactions.
  - Many incidents have involved exploitation of third-party vulnerabilities, such as misconfiguration of access authority to cloud services or attacks on outsourcers.
- Threat intelligence ecosystem and recommendations:
  - The Japanese ecosystem for threat intelligence is strong with a range of public and private bodies providing threat information to the financial authorities.
  - Both authorities could improve their overall analysis by combining different sources and developing a Generic Threat Landscape (GTL) Report that elaborates on the specific threat landscape of the Japanese financial system.
  - The GTL Report could consider key market participants and their critical functions (wholesale and retail banks, broker-dealers, FMIs, financial market utilities, other critical third parties), the different threat actors (including their tactics, techniques, and procedures), and common vulnerabilities.
  - Benefits of a GTL include better foresight of attack patterns, facilitation of scenario development, playbook building, exercising, and support for smaller financial entities to broaden access to TLPT and reduce overall costs.
- Red team testing:
  - The BOJ should make progress on red team testing (i.e., TLPT) on its ICT environment.
  - A full-scope red team test would help assess protection, detection, and response capabilities by simulating attacks on critical functions and underlying systems.

### Recommendations (supervisory and operational)
- The FSA should:
  - Update its Comprehensive Supervisory Guidelines (for all its sub-sectors), comprehensively covering cybersecurity.
  - Align the lessons learnt from on-site inspections, CSSA, and supervisory methodologies/tools to the supervisory guidelines.
  - Include a section in supervisory reports that explains the risk/impact of the findings materializing and the severity/rating of the findings, to facilitate better prioritization by the financial entity, as well as the reference to the supervisory expectation/requirement.
  - Increase its off-site and on-site cyber supervision of the FMIs, with the relevant responsible divisions working in close collaboration with the IT Cyber Monitoring Team.
  - Consider developing a set of Key Risk Indicators (KRIs) to improve its off-site monitoring of financial entities.
- The BOJ should:
  - Further increase and enhance the skills and expertise of its FMI overseers with regards to cyber to address the changing cyber threat landscape surrounding the overseen FMIs.
  - Strengthen its oversight approach on cyber resilience for FMIs (including the BOJ-operated FMIs) against the CPMI-IOSCO Cyber Guidance.
  - Make progress on red team testing (TLPT) of its ICT environment.

### Monitoring, escalation, and incident response
- The FSA and BOJ monitor threats using multiple sources and share information with domestic and international partners.
- The FSA has a mechanism to escalate computer system failures including cyber incidents, based on the significance of incidents of any financial institutions and FMIs.
- In the event of a large-scale cyber-attack:
  - The supervisor of the entity will promptly escalate the incident to senior FSA officials and the Prime Minister's Office and will report the incident to the NISC.
  - The FSA maintains a contact list with relevant individuals for escalation.

*Source: Excerpt from 1jpnea2024005 PDF chapter/section.*

### 93.      In addition, if the incident affects not only a single financial entity but also the entire

### Information Sharing and Incident Reporting

### Business continuity, CIR frameworks, and vulnerabilities
- The FSA will issue alerts to some or all sub-sectors if an incident affects not only a single financial entity but also the entire financial sector; depending on content, the FSA will convene a Liaison Council meeting and share information at the meeting. In the event of a cyber incident with international impact, the FSA will share necessary information through the G7 financial authorities.  
- Under the FSA's Business Continuity Plan (BCP), the FSA maintains a list of action and manuals, including: (1) actions to be taken in the event of an emergency that causes particularly serious damage to the FSA for some reasons; (2) a manual for FSA staff to assemble in the event of a disaster; and (3) a BCP manual to assess the extent of damage to financial entities, monitor the business continuity of priority operations in financial entities, and monitor the appropriate handling of customers by financial entities.  
- The FSA has issued statements to the public and financial markets in a flexible and timely manner at various times, including at the time of the financial crisis in Japan, September 11 attacks in the U.S.   , the Great East Japan Earthquake in Japan, and during the COVID-19.  
- The FSA’s BCP is currently heavily focused on earthquakes and “does not currently address cyber incidents sufficiently.” The BCP states: “Constant efforts are required to strengthen the business continuity system in the event of an earthquake, etc. Going forward, the FSA will continue to make further efforts to strengthen its business continuity system and request financial institutions to verify its business continuity system, with the aim of building a business continuity system that is resilient to risks such as earthquakes throughout the financial system while continuing to work closely with related organizations”.  
- The BOJ has a BCP whose basic framework was published in 2003. BOJ disaster management consists of (1) minimizing the impact of a disaster on its business operations by implementing measures to prevent damage, and (2) ensuring, to the greatest extent possible, continuity of its critical business operations to fulfill the responsibilities it is expected to exercise even in times of disaster.  
- The BOJ has identified three BCP scenarios involving Tokyo Head Office and the main computer center: (i) Tokyo Head Office functional but main computer center unable to continue operations; (ii) main computer center functional but Tokyo Head Office headquarters functions affected; (iii) Tokyo Head Office affected and main computer center unable to operate. Specific action plans differ by scenario with careful consideration of BOJ-NET continuity.  
- BOJ-NET operators have business continuity arrangements that are regularly tested. The BOJ carries out system-wide testing of switch-over to the backup center on an annual basis. The BOJ-NET operator confirmed that work is ongoing to include a range of extreme but plausible different cyber scenarios in its BCP starting from 2024.  
- The BOJ has developed a Cyber Incident Response (CIR) framework classifying incidents in five categories: (1) domestic incident (i.e. major domestic incident); (2) international incident in Japanese bank (i.e. incident affecting Japanese banks operating internationally); (3) overseas incident affecting Japanese banks (incident that occurs overseas and involves Japanese banks); (4) overseas incident (an incident that occurred overseas and had little impact on Japanese banks); and (5) cross border incident (i.e. incident that has domestic and international impact). For each scenario, the CIR framework sets out internal governance arrangements to manage the incident.  
- Rationale for improving CIRR: cyber incidents can create financial stability risks from interconnected IT systems between multiple financial entities or between financial entities and third-party service providers; loss of confidence in a major financial entity or group; or impacts on capital arising from losses due to the incident.

### Cyber exercising and industry testing
- The FSA has run an annual financial industry-wide cybersecurity exercise (Delta Wall) since 2016 to improve industry's incident response capabilities; exercises encourage participation from IT divisions and other divisions including public relations, various business lines, and senior management.  
- Delta Wall 2023 (Delta Wall VIII) included four scenarios targeting: (i) banks, (ii) Shinkin banks / credit unions, (iii) securities companies, and (iv) insurance companies / funds transfer service providers / prepaid payment instrument issuers / crypto-asset exchange service providers. 165 financial institutions participated in the exercise.  
- The FSA provided detailed feedback from the 2022 exercise (Delta Wall VII) to strengthen cybersecurity posture of financial entities, including non-participating ones, and will do the same for the 2023 exercise.  
- Assessment of Delta Wall: “Overall, the Delta Wall exercise is a very well-run exercise, with a range of different scenarios for a broad range of financial entities. The preparation, scenario-building and execution of the exercise is very well done, and the exercise provides deep insight on the capabilities of the industry.” The exercise emphasizes ex-post evaluation; the FSA analyzes findings, provides feedback, recommends action points, and shares best practices observed.  
- In 2021, the FSA hosted a desktop exercise at the Liaison Council for Cybersecurity Stakeholders attended by CEPTOARs, JPX, the BOJ, and Financials ISAC Japan to strengthen cross-sector coordination.  
- Government-led cross-sector exercises hosted by the NISC include participants from outside the financial sector. In 2022, the number of financial sector institutions participating in the NISC's cross-sector exercise was 434, including banks, securities firms, insurance companies, funds transfer service providers, and FMIs.  
- The BOJ, as operator of BOJ-NET and overseer of FMIs, is positioned to conduct cyber simulations and desktop exercises with BOJ-NET participants and other FMIs linked to BOJ-NET. Industry-wide cyber crisis simulation exercise goals: (i) test effectiveness of decision-making and crisis communication arrangements; (ii) validate collective contingencies; (iii) enable participants to practice response protocols; (iv) improve sector-level response coordination between public/private and with other jurisdictions. From an FMI perspective, such exercises allow authorities to assess FMI capabilities in meeting the two-hour recovery time objective and end of day settlements following a market-wide cyber crisis simulation.

### Recommendations (selected)
- The FSA and BOJ should consider developing a Generic Threat Landscape (GTL) Report that sets out the specific threat landscape of the Japanese financial system, considers key financial entities and their critical functions, the different threat actors (including their tactics, techniques, and procedures), and the common vulnerabilities.  
- The BOJ should make progress on red team testing on its ICT environment.  
- The FSA should update its BCP or develop a standalone Cyber Incident Response and Recovery (CIRR) plan, with a playbook of different cyber scenarios, which are regularly tested. The BCP or CIRR plan should set out the governance arrangements and thresholds for cyber incidents that could potentially trigger systemic risk.  
- The BOJ should continue to upgrade its BOJ-NET BCP with a range of extreme but plausible cyber-specific scenarios that are regularly tested, taking into consideration the feasibility of meeting the two-hour recovery time objective (RTO).  
- The BOJ’s CIR framework should be regularly tested.  
- The BOJ, as overseer of FMIs and operator of BOJ-NET, should consider conducting cyber exercises and simulations (e.g., table-top exercises) for BOJ-NET with relevant parties (e.g., BOJ-NET participants and other FMIs having link/connection with BOJ-NET) to strengthen responses to potential cyber incidents that could have material impacts on broader payment and settlements systems.  
- The FSA and BOJ should review whether their existing incident reporting regime is appropriate in light of trends in international CIR discussions, such as those at the FSB.

### Information and intelligence sharing ecosystem
- External stakeholders and flows:  
  - The NISC shares vulnerability and threat information with the FSA, who disseminates this information to all financial entities depending on the Traffic Light Protocol;  
  - The NPA and the Public Security Intelligence Agency share information on trends of cybercrime with the FSA, who in turn sends warnings and useful countermeasures to the financial sector;  
  - The FSA and BOJ gather information from cyber incident reports from financial entities, which they analyze and feed back to the financial sector;  
  - Private entities share information with each other through Financials ISAC Japan, in which 436 financial entities participate; and  
  - The FSA has established the Liaison Council for Cybersecurity Stakeholders (the FSA serves as Secretariat) including the Secretariats of the respective financial CEPTOARs, the BOJ, the Financials ISAC Japan, the FISC, and the JPX as members.

### Incident reporting regime and practices
- The FSA and BOJ have comprehensive cyber incident reporting regimes with clear definitions for cyber incidents, severity ratings, templates for reporting, and clear procedures for reporting. Financial entities must report cyber incidents to their respective financial authorities.  
- The FSA receives incident notifications daily. The IT Cyber Monitoring Team reviews notifications on a daily basis and judges the severity of each incident. The FSA reviews incidents annually and produces aggregated analysis of the incidents.  
- The FSA participates actively in the FSB’s Cyber Incident Reporting working group, which is developing a standard for incident reporting to achieve global convergence. It is recommended that the FSA and BOJ review their existing incident reporting regime and update it in line with the FSB’s framework, if appropriate.

### Appendix I: Comprehensive Supervisory Guidelines: Cybersecurity (headings)
- Governance  
- Identification of Assets  
- Technology and Cyber Risk Management (Project Management Framework; System Acquisition; System Development Life Cycle and Security-by-Design; System Requirements Analysis; System Design and Implementation; System Testing and Acceptance; Secure Coding, Source Code Review, and Application Security Testing; DevSecOps (Development, Security, and Operation) Management; Application Programming Interfaces (API))  
- IT Services Management (IT Service Management Framework; Documentation; Physical Controls; Software Management; Configuration Management; Technology Refresh Management; Patch Management; Change Management; Incident Management; Post-incident Review and Lessons Learned; Identity and Access Management; Network Management; Virtualization Security Management; Data Security and Privacy; “Bring Your Own Device” Security Management; Secured Disposal Management)  
- Cyber Security Operations (Cyber Threat Intelligence and Information Sharing; Cyber Event Monitoring and Detection; Cyber Incident Response, Management, and Reporting; Incident Reporting)  
- Response and Recovery (System Availability; Business Continuity Management and Disaster Recovery; Testing of Disaster Recovery Plan; Backup and Recovery; Data Center)  
- Scanning, Testing, Exercising, and Remediation (Vulnerability Scanning; Penetration Testing; Incident Response Exercises; Remediation Management)  
- Independent Assurance (Technology Risk Audits)  
- Outsourcing and Technology Service Provider Management (Governance; Risk Assessment; Vendor Contracts; Regulatory Oversight; Vendor Competency; Cloud Computing)

*Source: Excerpt from the IMF Japan country report chapter on cybersecurity, as provided in the supplied content.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2024/english/1jpnea2024005.pdf_
