Cybersecurity Research

Japan Moves to Mandatory Cyber Reporting, and the Ripple Effects Reach Suppliers and Partners

Recorded Future · 8 Oct 2026
Key Takeaway If you supply or connect to larger organisations, make sure you can escalate incidents quickly, preserve evidence and meet the reporting and remediation expectations written into your contracts.

Japan is changing how it responds to cyber threats. Its Active Cyber Defense (ACD) framework moves the country away from voluntary information sharing and after-the-fact investigation towards mandatory reporting, preventive analysis of communications, and limited disruption of attack infrastructure. From 1 October 2026, designated critical infrastructure operators must notify the government about covered systems and report qualifying incidents. Operators with existing systems have six months to submit initial notifications. The new powers to collect and act on communications information will not take effect until 23 November 2027.

Recorded Future's analysis points to ongoing Chinese strategic collection, North Korean revenue-driven operations and Russian espionage. In cases linked to Japan, related indicators were often seen among victims, overseas affiliates, vendors, carriers, hosting providers and government agencies. The analysts assess with moderate confidence that connecting those indicators quickly enough to spot wider campaigns and warn others will be ACD's main operational constraint. Its reach will extend beyond designated operators: overseas compromises may trigger Japanese reporting duties, vendors should expect remediation requests, carriers may be asked to assist, and hosting providers may see action against malicious systems on their infrastructure.

The analysts also assess that better visibility inside covered organisations may make foreign subsidiaries, non-designated suppliers, employees and external platforms more attractive entry points for attackers, without reducing overall attack volume. Companies should treat ACD as a change to incident escalation, contracting, evidence preservation and intelligence sharing across their supply chains, not just a compliance task.

Japan Active Cyber Defense Supply Chain Risk Critical Infrastructure Incident Reporting
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Recorded Future, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.