Japan’s Financial Services Agency Publishes Report on Third-Party Cyber Risk Management

According to Japan’s Financial Services Agency, its crypto exchange cybersecurity policy uses a three-layer defense framework to protect investor assets as risks from social engineering and outsourced service providers increase.

Summary

Japan’s Financial Services Agency published a policy on April 3 to strengthen cybersecurity for crypto asset exchange operators, with investor asset protection as the central objective. The framework is built around a three-layer defense system spanning firms, self-regulatory bodies, and regulators, and it warns of rising threats from social engineering and compromised outsourcing providers. The policy also includes self-help, mutual support, and public support measures, calls for threat-led penetration testing, revises administrative guidelines, and was released after 18 public comments.

Terms & Concepts
  • Crypto asset exchange operators: Businesses that facilitate the buying, selling, and custody of cryptocurrencies under regulatory oversight.
  • TLPT: Threat-Led Penetration Testing, a cybersecurity exercise that simulates realistic attacks based on threat intelligence to test defenses.
  • Social engineering: A type of cyberattack that manipulates people into revealing sensitive information or granting unauthorized access.