Security1 publisherNot yet confirmed elsewhere2 min readPublished
Japan mandates cyber incident reports 13 months before its communications-analysis powers start
Japan's Active Cyber Defense law has made designated critical-infrastructure operators register covered systems and report incidents since October 1, 2026. Powers to collect and act on communications data wait until November 23, 2027, so reporting runs about 13 months ahead of the detection meant to support it.
The Watch · Security desk

What happened
- Operators that already run covered systems get six months from October 1, 2026 to file their initial notifications.
- The framework replaces voluntary information sharing and after-the-fact investigation with mandatory reporting, preventive communications analysis and limited disruption of attack infrastructure.
- It rests on Acts 42 and 43 of 2025: Act 42 covers reporting, sharing, communications analysis and oversight, while Act 43 authorizes neutralization measures and reorganizes cyber institutions.
- Recorded Future says vendors can expect to be asked to remediate, carriers could be obliged to help with government measures, and hosting providers could face action over malicious systems running on their infrastructure.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Operators with legacy estates must settle which systems are covered and file by about the start of April 2027, nearly eight months before the communications powers begin.
- exposure A breach at an overseas affiliate can become a Japanese reporting matter once it reaches a covered system, so a foreign security team's escalation path can end in a Japanese filing.
- exposure Recorded Future expects more targeting of foreign subsidiaries, non-designated suppliers, employees, consumer platforms and short-lived hosting infrastructure, all positions with no direct ACD reporting duty.
Recorded Future assesses that better visibility inside covered organizations will likely steer intruders onto routes around them, with no reduction in overall attack volume [17]. The reasoning is about scope and timing. Early activity on those routes likely falls outside the mandatory-reporting perimeter, or happens before anyone has recognized a qualifying incident [17].
The traffic figures count attempts. Japanese agencies logged 686.2 billion attack-related packets in 2024, up from 63.2 billion in 2015, and 99.4% of observed attack packets came from overseas source addresses [7]. Recorded Future puts that at roughly one attempted attack per IP address every 13 seconds [13]. The reporting duty attaches to qualifying incidents involving covered systems [1].
Recorded Future sets the law against persistent state activity with distinct drivers. China pursues enduring strategic intelligence collection, North Korea prioritizes sanctions-driven revenue, and Russia pairs standing espionage requirements with disruption that can track Japanese policy decisions [10].
The traces of that activity are scattered across many parties. In cases directly linked to Japan, the firm found related indicators at victims, overseas affiliates, vendors, carriers, hosting providers and government agencies [11]. It assesses with moderate confidence that connecting those indicators fast enough to identify a campaign, warn likely targets and coordinate a defense will be ACD's principal operational constraint [16].
The report's summary does not define which incidents qualify or how fast a report is due. Its advice to companies covers four areas: incident escalation, contracting, evidence preservation and public-private intelligence sharing, applied across their own operations and their supply chains [12].
What to watch
- Government guidance that defines a qualifying incident and sets the reporting clock for designated operators.
- How many existing-system notifications are filed before the six-month window closes around April 2027.
- Whether intrusions through foreign subsidiaries and non-designated suppliers rise after October 1, 2026, as Recorded Future predicts.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives40
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Beginning October 1, 2026, designated critical infrastructure operators in Japan must notify the government about covered systems and report qualifying incidents.
- [2]
Operators with existing systems have six months to submit initial notifications.
- [3]
New authorities that allow the Japanese government to collect and act on communications information will not take effect until November 23, 2027.
- [4]
Japan's Active Cyber Defense framework shifts the country from voluntary information sharing and post-incident investigation to mandatory reporting, preventive communications analysis, and limited disruption of attack infrastructure.
- [5]
ACD is a two-statute framework, Acts 42 and 43 of 2025. Act 42 establishes the reporting, information-sharing, communications-analysis and oversight framework; Act 43 amends existing laws to authorize neutralization measures and reorganize Japan's cybersecurity institutions.
- [6]
There is a gap of roughly 13 months between the October 1, 2026 reporting duty and the November 23, 2027 communications-information collection capacity intended to support it.
- [7]
Japanese agencies recorded an eleven-fold increase in cyberattack-related packets, from 63.2 billion in 2015 to 686.2 billion in 2024, while 99.4% of observed attack packets used overseas source IP addresses.
- [8]
Overseas compromises may trigger Japanese reporting duties when they reach covered systems.
- [9]
Vendors should expect remediation requests; carriers may be required to assist government measures; hosting providers may encounter action against malicious systems operating on their infrastructure.
- [10]
The transition comes amid persistent Chinese strategic collection, North Korean revenue-driven cyber operations and Russian cyber espionage. China pursues enduring strategic intelligence collection, North Korea prioritizes sanctions-driven revenue generation, and Russia combines standing espionage requirements with disruption that can track Japanese policy decisions.
- [11]
In cases directly linked to Japan, indicators related to these threat activities were frequently observed among victims, overseas affiliates, vendors, carriers, hosting providers, and government agencies.
- [12]
Companies should treat ACD as a change to incident escalation, contracting, evidence preservation, and public-private intelligence sharing across their operations and supply chains.
- [13]
The packet volume is equivalent to roughly one attempted attack per IP address every thirteen seconds.
- [14]
The six-month initial-notification window for existing systems runs to about April 1, 2027.
- [15]
The existing-system notification window closes nearly eight months (about 7.7 months) before the communications-information powers take effect.
- [16]
Recorded Future assesses with moderate confidence that connecting indicators quickly enough to identify broader campaigns, warn potentially affected organizations, and coordinate defensive action will be ACD's principal operational constraint.
- [17]
Improved visibility within covered organizations will likely make foreign subsidiaries, non-designated suppliers, employees and external platforms comparatively attractive access paths for threat actors without reducing overall attack volume, because initial activity along these routes likely falls outside ACD's mandatory-reporting perimeter or precedes recognition of a qualifying incident.
- [18]
Threat actors will likely emphasize five access paths with limited visibility under ACD: foreign subsidiaries, non-designated suppliers, individual employees, consumer platforms, and short-lived infrastructure distributed across hosting providers. Organizations in these positions may face greater targeting despite having no direct ACD reporting obligation.
Sources
1 independent publisher whose own reporting we read for this story.
- recordedfuture.comJapan Adopts Proactive Cyber Defense Strategy
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Critical Infrastructure CybersecurityFollow
- State-Sponsored Cyber OperationsFollow
- Cyber Incident Reporting RulesFollow