Government to strengthen cyber defense of critical infrastructure, sharing hidden threat investigation methods from FY2017
Quick Look
- In FY2027, the government will strengthen the creation of detection methods and information sharing for ``threat hunting,'' which investigates intrusions and hiding situations between the public and private sectors, in order to protect critical infrastructure such as electricity and communications from cyberattacks.
- The aim is to prevent infrastructure outages in emergencies.
AI-generated summary
Why It Matters
A law related to active cyber defense came into effect on the 1st. There are concerns about hidden attacks on critical infrastructure.
In fiscal 2027, the government will strengthen public-private efforts to investigate whether attackers have infiltrated or hidden within systems in order to protect critical infrastructure such as electricity and communications from cyberattacks. Build detection methods according to threat information and share them with private businesses. Preventing crises caused by emergency infrastructure outages.
Promoting the development of specialized AI Digital Minister Furukawa ``Data is the name of the game'' - Interview with new ministers
"Threat hunting," which detects threats hidden within systems, is one of the active cyber defense methods for which related laws came into effect on the 1st. Based on specific threat information, the National Cyber Control Office (NCO) will reproduce attacks in a virtual environment and build and verify detection methods that can be used in the private sector.
The Ministry of Defense will also utilize the search capabilities it has cultivated through the Self-Defense Forces' information systems to provide direct support by visiting critical infrastructure operators upon request. The NCO and the Ministry of Defense included related expenses in their budget request for fiscal year 2027.
The reason behind this is that the outage of critical private infrastructure could lead to a national crisis in an emergency. In 2024, U.S. authorities estimated that Bolt Typhoon, a group believed to be backed by the Chinese government, had maintained access to some critical U.S. infrastructure for more than five years. It is believed that the attacker exploited legitimate management tools to evade detection and hide in a way that would allow him to shut down the infrastructure in an emergency.
On the other hand, accumulating and analyzing the logs necessary for searching requires manpower and costs. NTT Data has been conducting threat hunting using its internal system since 2024. In order to respond to latent attacks, we formulate a hypothesis that a specific attack may be occurring even when there is no warning, and search for suspicious activity from logs. Yukio Nakajima, who is in charge of the project, pointed out, ``In order to expand our activities, we need to demonstrate cost-effectiveness to management.''
NCO officials explain that preparing for latent attacks alone is unlikely to lead to investment decisions by management. He says that even ransomware, which is a familiar threat, has common techniques such as searching inside the system after intrusion, and emphasizes the significance of ``threat hunting as a countermeasure against ransomware.''
What to Watch
AI outlook — possibilities, not facts
Related expenses will be included in the budget request for FY2017.
Very likely · Within months
Open Questions
- How much are the specific related expenses in the FY2017 budget?
- What will be the specific framework for support for private businesses?





