Japan Enacts Landmark Cyber Defence Legislation

Japan has introduced a historic new law aimed at strengthening its cybersecurity capabilities amid rising digital threats. The Active Cyberdefence Law (ACD) marks a significant shift in the country's national security strategy, granting the government new powers to monitor and respond to cyber attacks more proactively.

The ACD significantly expands Japan’s ability to counter cyber threats by legally permitting government agencies to monitor communications data during peacetime and to neutralise hostile servers when necessary.

This legislation represents a major departure from Japan’s traditional approach to cyber security, which has been constrained by its postwar pacifist constitution and privacy protections.

The law was enacted in response to a surge of cyber attacks from criminal gangs and state-sponsored hackers, which have caused disruptions to airlines, banks, and critical infrastructure. The government aims to have all measures fully operational by 2027.

Key Provisions of the Active Cyberdefence Law

The legislation allows the Japanese government to:

  • Monitor communications data during peacetime.
  • Take offensive actions such as neutralising enemy servers.
  • Establish an independent oversight panel that authorises data collection, analysis, and offensive operations.
  • Require businesses to report cyber breaches and the implementation of communication devices.
  • Promote cooperation between the public and private sectors, especially in sharing sensitive information to bolster infrastructure defence.

However, the law explicitly prohibits the government from analysing domestic internet traffic, as most cyber attacks are believed to originate from abroad.

Balancing Security With Privacy  Safeguards

Tokyo’s efforts to enhance digital resilience have been historically restrained by constitutional limitations. Article 21 of Japan’s constitution states that “the secrecy of any means of communication” must be protected, necessitating warrants for wiretapping and restricting the scope of surveillance.

The new law introduces oversight measures, including a panel that must give prior approval for data collection and offensive operations, aiming to safeguard civil liberties while improving security.

Urgent Strategic Necessity

When the legislation was first approved earlier this year, Itsunori Onodera, the chair of the government’s policy research council, warned that failure to upgrade cybersecurity would put Japanese lives at risk. The law empowers Japan’s police and Self-Defense Forces to conduct offensive cyber operations to protect critical infrastructure against foreign and domestic threats.

Security Workforce Shortages

The Ministry of Economy, Trade and Industry highlighted that Japan faces an estimated shortfall of 110,000 qualified cybersecurity professionals, hindering its ability to defend against evolving threats.

Penalties for Misuse

Officials who illegally use or leak information acquired through these new powers face penalties of up to four years in prison or fines of up to ¥2 million ($13,760). The legislation signals Japan’s move toward a more assertive and independent cyber defence stance in the region amid escalating geopolitical tensions.

A New Era of Digital Defence

The enactment of the Active Cyberdefence Law represents Japan’s efforts to foster a robust national security framework capable of pre-empting and responding to complex cyber threats.

As regional tensions rise, the country aims to bolster its cyber resilience through proactive measures, even as it balances civil liberties and international cooperation.

Kyodo News  |   Japan Times  |   FT  |   The Record  |   SL Guardian  |  Japan News 

Image: Ideogram

You Might Also Read: 

Preparing For A South China Sea Cyber Storm:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« FBI Warns Of Surging Use Of Vishing
US Confirms Pause In Cyber Operations Against Russia »

Infosecurity Europe
CyberSecurity Jobsite
Check Point

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT GRC Forum

IT GRC Forum

The IT GRC Forum is an online resource and networking platform for the Governance, Risk Management, and Compliance (GRC) community

Wireless Logic

Wireless Logic

Wireless Logic delivers a range of secure and resilient value-added M2M/IoT managed services that empower remote devices to communicate cost-effectively, two ways.

Applied Security (APSEC)

Applied Security (APSEC)

APSEC provides products and services in the areas of encryption, digital signature, authentication and data loss prevention.

Insight Partners

Insight Partners

Insight Partners is a leading global private equity and venture capital firm investing in growth-stage technology, software and Internet businesses.

CoverWallet

CoverWallet

CoverWallet combines deep analytics, thoughtful design and state of the art technology to help small businesses with all their insurance needs including Cyber Liability.

CyFIR

CyFIR

CyFIR is a network investigation and Incident Response tool for performing live computer investigations across any size enterprise.

Raonsecure

Raonsecure

Raonsecure is one of Korea’s leading ICT security software companies – providing a variety of PC and mobile security solutions to financial institutions, government, and enterprise.

Blaick Technologies

Blaick Technologies

Blaick is an Israeli cyber-security company which deploys proprietary Artificial Intelligence threats detection technology for early prevention of online cyber crime.

VCG Group

VCG Group

VCG provides everything you need for the design, implementation and management of data centres, cyber-secure enterprise networks, cloud and connectivity services.

Almond

Almond

Almond is positioned as a key independent French player in audit and consulting in the fields of Cybersecurity, Cloud and Infrastructure.

NANDoff Data Recovery

NANDoff Data Recovery

NANDoff is a flat rate data recovery service. We serve the electronics industry around the globe 24/7.

Centroid

Centroid

Centroid is a cloud services and technology company that provides Oracle enterprise workload consulting and managed services across Oracle, Azure, Amazon, Google, and private cloud.

Zitec

Zitec

One of Europe's largest and most prominent full-cycle software development services companies, Zitec is the digital transformation partner to companies in the EU, UK, USA, Canada and ME.

ZAG Technical Services

ZAG Technical Services

ZAG Technical Services is an award-winning information technology consulting firm delivering digital transformation solutions, IT assessments, managed services, security, and support.

SPIE Switzerland

SPIE Switzerland

SPIE Switzerland AG, a subsidiary of the SPIE Group, is a Swiss full-service provider of ICT, multi-technical and integral facility services.

eGeneration

eGeneration

eGeneration is one of the leading technology solutions and system integration companies in Bangladesh.