Cybersecurity Presentation
Transcript: Japanese Cybersecurity Policy What is the government's role? Introduction Basic Cybersecurity Act Japanese Government's Role in Cybersecurity Article 15: Requires the state to promote awareness of the importance of cybersecurity Government needs to provide necessary information, advice and other necessary measures to private business operators and educational and research institutions to protect the intellectual property information held by them Article 14: Requires the state to take necessary measures such as developing basic standards to be followed, providing drills, training and promoting information sharing and other voluntary efforts What is the private sector's view? Japan: 55% US: 80% Japan: 27% US: 78% Cost: 63% Investment: 18% How much do they invest in cybersecurity? 1. Not a requirement to ensure cybersecurity Government don't have the power to impose any mandatory obligations on private business operators to ensure cybersecurity. Why isn't it working ? 2. Not a requirement to report any cyberattacks There is no law or regulation that requires a private business to report any cyberattacks. No penalty is imposed on it in the event of a failure to make such report. Challenges Challenge 1. The government cannot make the regulation legally binding 2. Not all businesses are aware of the importance of cybersecurity Areas for growth • Promote importance of cybersecurity to the senior executives • Create a culture that investment in cybersecurity is a norm • Increase amount of information-sharing platforms that are government entities • Both government and private sectors can benefit • Increase amount of money invested in R&D for cybersecurity Recommendation Raise awareness of cybersecurity in Japan, explain the cyberthreat landscape and best practices 1. Make business executives aware Describe potential risks from business strategy and risk management perspectives by using simple, easy-to-digest terms. Example: Government conducting programs for businesses executives NYSE analyzes companies cybersecurity during the M&A process Low cybersecurity = lower price 1. Need more Information Sharing and Analysis Centers (ISACs) Japan has 6 ISACs (Auto ISAC, NCC/ Communication ISAC, Financial Services ISAC, Information Technology ISAC, Electricity ISAC, and ICT ISAC) US has 23 ISACs 2. Information Sharing To strengthen cybersecurity, sharing information between public and private sectors and across different sectors in various forms of communication is necessary 2. Create more cross-sector industry forums Japan: 48 companies are working to increase cybersecurity capacity Japanese government should invest more into R&D for cybersecurity 3. Investment in R&D The U.S. government has traditionally been effective in using R&D funding to stimulate innovation and has established effective ways of technology expansion. The Japanese government needs to be more committed to its domestic cybersecurity industry and can learn how to do so by studying the U.S. experience. Become part of government official or lawyer to change the Basic Cyber Act What can YOU do? Work for a company and inform the importance of investing in cybersecurity Vote for government officials who are aware of the importance of cybersecurity Questions? Thank you! Reference