On April 9, 2024, Japan's Ministry of Economy, Trade and Industry (METI) announced its intention to implement a cybersecurity rating system for companies by fiscal year 2025. Although the proposal is still in the consultation phase, with industry feedback expected to lead to potential refinements, key aspects of the planned system have been outlined:
METI aims to establish a five-level categorization of corporate cyber defense measures, enhancing clarity for business partners regarding the extent of cybersecurity implementations within a company. This stratification is designed to bolster overall industry responsiveness, particularly in combating attacks that exploit supply chain vulnerabilities.
Details of the Proposed Rating Levels:
- Levels 1-2: Fundamental measures including regular software updates, restricted access to sensitive information, and protocols for handling information leaks.
- Levels 3-4: Targeted at key players within the supply chain, these levels require more sophisticated information management systems.
- Level 5: The highest level, necessitating third-party certification of a company’s cyber defense capabilities.
The proposed rating system is expected to motivate companies to strengthen their cyber defenses and enable partners to better evaluate the cybersecurity preparedness of businesses. The desired outcome should be the ripple effect of higher cybersecurity performance expectations propagating from key industry pillars and effecting their ecosystems towards a higher state of cybersecurity maturity. Effectively, lower cybersecurity ratings could deter potential transactions, and directly impact the profitability of businesses. In summary, a lack of a credible cybersecurity strategy would pose a strategic risk for businesses.
This initiative is part of broader governmental efforts to enforce cybersecurity within critical infrastructure and high-risk sectors. It parallels the U.S. Cybersecurity Maturity Model Certification (CMMC), which utilizes a similar five-level grading system influencing defense procurements. Japan's initiative, however, extends its impact to the commercial sector, thereby facilitating more effective due diligence by both government and businesses.
Challenges and Strategic Considerations:
The technological and cybersecurity debt accumulated by Japanese businesses might cause initial resistance to this initiative. To address potential hesitations and accelerate cybersecurity enhancements, the government and businesses might consider several strategies in accordance to their own profile. Their cybersecurity implementation strategy may look something like this:
- Assessment and Planning: Essential first steps to identify current capabilities and outline strategic objectives.
- Policy Development: Establishing governance to guide cybersecurity efforts.
- Implementation: Deploying necessary cybersecurity measures.
- Training and Awareness: Educating staff on cybersecurity practices.
- Monitoring and Response: Continuously observing systems and preparing to respond to security incidents.
- Review and Audit: Regularly evaluating the effectiveness of cybersecurity measures.
- Improvement: Continuously refining cybersecurity practices.
- Third-Party Management: Overseeing the security postures of all associated third parties.