Japan outlines measures to protect infrastructure from cyberattacks
In light of a recent series of ransomware attacks, the draft urges such businesses to take measures, including taking out cybersecurity insurance.
The Japanese government has drafted guidelines proposing 150 measures to bolster cybersecurity for businesses managing critical infrastructure. The guidelines recognize that even closed networks disconnected from the internet remain vulnerable to threats. In response to a recent surge in ransomware attacks, the draft recommends that such businesses secure cybersecurity insurance, but advises against paying ransoms.
The government will accept public comments on the draft until Wednesday, after which it plans to revise the guidelines and release the final version by the end of September.
The guidelines target 16 sectors deemed critical infrastructure, such as finance, railways, and electricity. The draft emphasizes that cybersecurity is a "management issue" crucial for a company's survival, acknowledging that completely protecting against cyberattacks is challenging. Businesses in these sectors are urged to enhance their recovery capabilities, preparing for potential system failures.
The draft cautions against overconfidence, advising companies not to underestimate the risks of relying on closed networks, dedicated operating systems, or unique technical specifications.
Recommended measures include taking out cybersecurity insurance to mitigate the financial impact of ransomware attacks, while still discouraging companies from paying ransoms. The draft also highlights the need to urgently strengthen defenses against advanced AI models like Claude Mythos, including the use of sophisticated AI models. Furthermore, it calls for the adoption of postquantum cryptography (PQC) by as early as 2035 in response to advancements in quantum computing technology.
Written by urgent.news from Japan Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.