The government plans to bolster cybersecurity measures in fiscal 2027 to probe whether attackers have infiltrated and remained hidden within the systems of operators of critical infrastructure, such as power utilities and telecommunications companies.
The government will develop methods to detect cyberattack threats and share them with private-sector firms in order to prevent possible crises caused by infrastructure shutdowns during a contingency.
So-called threat hunting is one of the key methods of active cyberdefense, for which related legislation took effect on Thursday. The government’s National Cybersecurity Office (NCO) will use specific information on possible threats to re-create attacks in a virtual environment and develop and test threat detection methods that can be used by the private sector.
The Defense Ministry will also provide direct assistance, including dispatching personnel to critical infrastructure operators at their request, drawing on its threat-hunting capabilities developed through the Self-Defense Forces’ information systems.
The NCO and the Defense Ministry included related expenses in their budget requests for fiscal 2027.
Such efforts come amid concerns that disruptions to privately operated critical infrastructure could lead to a national crisis.
U.S. authorities estimated in 2024 that Volt Typhoon, a hacker group believed to be sponsored by the Chinese government, had maintained access to some U.S. critical infrastructure for more than five years.
The group apparently exploited legitimate administrative tools to evade detection and remained hidden so that it could halt infrastructure functions during a contingency.
But accumulating and analyzing the logs needed for threat-hunting requires labor and incurs other costs.
NTT Data Japan has conducted threat-hunting in its in-house systems since 2024. It searches logs for suspicious activity even when there are no warnings, based on the assumption that a specific attack could be underway.
“To expand this activity, we need to demonstrate its cost-effectiveness to management,” Yusuke Nakajima, a company official in charge of the threat hunting program, said.
An NCO official said that preparing only for attacks involving hidden threats is unlikely to persuade company executives to invest in such measures. The official pointed out that threat-hunting can also help tackle ransomware, a more familiar threat to companies, as it employs similar tactics such as probing systems after gaining entry.
