Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Japan mandates cyber incident reports 13 months before its communications-analysis powers start

Japan's Active Cyber Defense law has made designated critical-infrastructure operators register covered systems and report incidents since October 1, 2026. Powers to collect and act on communications data wait until November 23, 2027, so reporting runs about 13 months ahead of the detection meant to support it.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Japan mandates cyber incident reports 13 months before its communications-analysis powers start
Generated illustration

What happened

  • Operators that already run covered systems get six months from October 1, 2026 to file their initial notifications.
  • The framework replaces voluntary information sharing and after-the-fact investigation with mandatory reporting, preventive communications analysis and limited disruption of attack infrastructure.
  • It rests on Acts 42 and 43 of 2025: Act 42 covers reporting, sharing, communications analysis and oversight, while Act 43 authorizes neutralization measures and reorganizes cyber institutions.
  • Recorded Future says vendors can expect to be asked to remediate, carriers could be obliged to help with government measures, and hosting providers could face action over malicious systems running on their infrastructure.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Operators with legacy estates must settle which systems are covered and file by about the start of April 2027, nearly eight months before the communications powers begin.
  • exposure A breach at an overseas affiliate can become a Japanese reporting matter once it reaches a covered system, so a foreign security team's escalation path can end in a Japanese filing.
  • exposure Recorded Future expects more targeting of foreign subsidiaries, non-designated suppliers, employees, consumer platforms and short-lived hosting infrastructure, all positions with no direct ACD reporting duty.

Recorded Future assesses that better visibility inside covered organizations will likely steer intruders onto routes around them, with no reduction in overall attack volume [17]. The reasoning is about scope and timing. Early activity on those routes likely falls outside the mandatory-reporting perimeter, or happens before anyone has recognized a qualifying incident [17].

The traffic figures count attempts. Japanese agencies logged 686.2 billion attack-related packets in 2024, up from 63.2 billion in 2015, and 99.4% of observed attack packets came from overseas source addresses [7]. Recorded Future puts that at roughly one attempted attack per IP address every 13 seconds [13]. The reporting duty attaches to qualifying incidents involving covered systems [1].

Recorded Future sets the law against persistent state activity with distinct drivers. China pursues enduring strategic intelligence collection, North Korea prioritizes sanctions-driven revenue, and Russia pairs standing espionage requirements with disruption that can track Japanese policy decisions [10].

The traces of that activity are scattered across many parties. In cases directly linked to Japan, the firm found related indicators at victims, overseas affiliates, vendors, carriers, hosting providers and government agencies [11]. It assesses with moderate confidence that connecting those indicators fast enough to identify a campaign, warn likely targets and coordinate a defense will be ACD's principal operational constraint [16].

The report's summary does not define which incidents qualify or how fast a report is due. Its advice to companies covers four areas: incident escalation, contracting, evidence preservation and public-private intelligence sharing, applied across their own operations and their supply chains [12].

What to watch

  • Government guidance that defines a qualifying incident and sets the reporting clock for designated operators.
  • How many existing-system notifications are filed before the six-month window closes around April 2027.
  • Whether intrusions through foreign subsidiaries and non-designated suppliers rise after October 1, 2026, as Recorded Future predicts.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Beginning October 1, 2026, designated critical infrastructure operators in Japan must notify the government about covered systems and report qualifying incidents.

    ReportedSupportedSource: Recorded Future researchView cited source
  2. [2]

    Operators with existing systems have six months to submit initial notifications.

    ReportedSupportedSource: Recorded Future researchView cited source
  3. [3]

    New authorities that allow the Japanese government to collect and act on communications information will not take effect until November 23, 2027.

    ReportedSupportedSource: Recorded Future researchView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. recordedfuture.com

    1 article · October 7, 2026

    Japan Adopts Proactive Cyber Defense Strategy

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

  • Recorded FutureFollow
  • Active Cyber Defense (Japan)Follow
  • Cyber Response Capability Strengthening Act (Act No. 42 of 2025)Follow
  • Cyber Response Capability Strengthening Act Arrangement Act (Act No. 43 of 2025)Follow
  • National DietFollow
Loading related stories