[Credit Card Companies and Regional Financial Institutions] How Incident Response Will Change with the Enforcement of the Cyber Response Capability Enhancement Act

    July 23, 2026

    Author of this article

    President and CEO

    Takaaki Kanetsuki

    The public-private partnership provisions of the so-called “Cyber Response Capability Enhancement Act” (official title: Act on the Prevention of Damage Caused by Unauthorized Acts Against Important Computers), which was enacted in May 2025, will take effect in October 2026.The 15 critical infrastructure sectors include “Finance” and “Credit Cards” as separate sectors, and designated operators will be legally required to file notifications regarding their system assets and report cyber incidents to the government.

    However, the “impact” of this law will differ between megabanks and major credit card companies on the one hand, and regional banks and credit unions on the other. This is because designation is limited to businesses that meet certain size criteria, so it is expected that many regional financial institutions will not be directly subject to the designation.

    Does this mean that regional banks and credit unions are unaffected? Not at all. The “Guidelines on Cybersecurity in the Financial Sector,” formulated by the Financial Services Agency in October 2024, apply to a wide range of financial institutions, including regional financial institutions, and the substance of the incident response requirements is essentially the same regardless of whether an institution is designated or not. In this article, we will outline what is required and what preparations should be made from the perspectives of both credit card companies and regional financial institutions.

    Legal Requirements: Notifications and Incident Reporting

    The entities directly subject to the Strengthening Act are “specified social infrastructure operators” (core infrastructure operators) designated under the Economic Security Promotion Act; as of April 1, Reiwa 8, a total of 257 entities across all sectors have been designated. Both the financial and credit card sectors have been covered since the system’s inception; the Financial Services Agency publicly announced the designation of specified social infrastructure operators in the financial sector on November 17, Reiwa 5, and has continued to make additional designations since then.You can verify whether your company (or institution) is subject to this designation by checking the public notices issued by the Financial Services Agency and the Ministry of Economy, Trade and Industry.

    The Strengthening Act imposes the following obligations on designated businesses: They must report to the government the vendor names, product information, and other details regarding “specified critical computers” among the information systems involved in their core operations. They must also report incidents in the event of a cyberattack.

    Regarding the reporting framework, the draft guidelines for implementation presented to the Cabinet Office’s Expert Panel outline a two-stage reporting process.Upon becoming aware of an incident, an organization must promptly issue a “preliminary report” and submit a “detailed report” within 30 days. In both cases, organizations are only required to report the information known at that time; they are not expected to provide a complete root cause analysis during the initial response phase. The scope of reporting includes not only traces of “specified unlawful acts,” such as unauthorized access, but also related events. The system is designed so that the reporting obligation begins as early as the warning signs stage.

    The rules regarding cloud usage have also been clarified. In the case of SaaS or PaaS (related to middleware or operating systems), “awareness” is deemed to have occurred at the time the cloud service provider issues a notification. Regarding penalties, a fine of up to 2 million yen is prescribed for failure to comply with the reporting obligation or to follow a corrective order issued by the regulatory authority, and a fine of up to 300,000 yen is prescribed for failure to comply with requests to submit documents or similar requirements.

    Furthermore, a particularly critical issue in the financial industry is the potential ripple effect on non-designated businesses and entities.It has been pointed out that IT vendors and group companies entrusted with the operation of Specified Important Computers, as well as equipment owned by subcontractors—depending on the system configuration—may also be subject to these regulations. In the regional financial sector, where it is common practice to outsource core banking systems to shared service centers and rely on external vendors for online banking and payment processing, and in the credit card industry, where processing operations are outsourced and subcontracted through multiple layers, it is actually quite common to find situations where a company is not designated itself but is “connected to the same system as a designated operator”or “We are a subcontractor of a designated operator.”

    Regional Financial Institutions: The Financial Services Agency’s Guidelines Serve as the De Facto Standard

    For regional banks and credit unions, the primary practical focus is not the Strengthening Act, but rather the “Guidelines on Cybersecurity in the Financial Sector” formulated by the Financial Services Agency on October 4, Reiwa 6. These guidelines cover a wide range of institutions—from major banks to small and medium-sized financial institutions, regional financial institutions, insurance companies, money transfer service providers, and cryptocurrency exchange operators—and provide concrete details on the key aspects of cybersecurity management that had previously been addressed only in general terms in supervisory guidelines.

    These guidelines are structured in two tiers: “Basic Response Measures” that all financial institutions and similar entities should implement, and “Recommended Response Measures” that are encouraged based on an institution’s size, characteristics, and other factors. This allows regional financial institutions to design their response levels according to their own size. From the perspective of incident response, the following points are important to note:

    • The responsibilities of management are clearly stated

      Addressing cybersecurity risks is considered a responsibility of senior management, which requires the allocation of resources—such as the assignment of specialized personnel and the allocation of budgets—as well as the establishment of cross-organizational reporting, communication, and consultation channels, including those related to risks posed by third parties, and the establishment of a clear chain of command. The framework also incorporates mechanisms for continuous management, such as reviewing policies at least once a year and monitoring the situation using KPIs and KRIs.

    • Establishment of a Crisis Management System

      Organizations are required to establish reporting and public relations systems in the event of a cyberattack, as well as to set up emergency response teams, such as an in-house CSIRT. It is recommended that contingency plans—including recovery plans—be formulated for each type of attack, such as website defacement or malware infection, and the FISC (Financial Information Systems Center) guidelines are cited as a reference.

    • Continuity with Previous Reports by the Authority

      Financial institutions are already required, based on supervisory guidelines and other regulations, to report system failures and similar incidents to the authorities. The Financial Services Agency also conducts Cybersecurity Self-Assessments (CSSA) for regional financial institutions, providing them with the necessary tools to compare their own security measures against industry standards.For designated operators, the preliminary and detailed reports required under the Enhanced Security Act represent a new layer added on top of these existing reporting practices. Even for non-designated financial institutions, it is likely that the same benchmark—the “speed from detection to reporting”—will become the industry standard.

    It should be noted that from late 2024 through early 2025, there was a spate of DDoS attacks targeting domestic financial institutions and airlines, and temporary disruptions to online banking services were reported. Even attacks that do not involve actual intrusion can halt customer services, triggering the need for reporting to authorities and customer support. Rather than “waiting until evidence of a breach emerges before taking action,” it is essential to establish a system where reporting and public relations procedures are initiated as soon as service disruptions occur.

    Credit Cards: Incident Response That Overlaps with Fraud Prevention Measures

    The credit card industry has a long history of self-regulatory measures dating back to before the Enforcement Act. Article 35-16 of the Installment Sales Act requires businesses that handle credit card numbers and other related information to take necessary measures for the proper management of such information (measures for the proper management of card numbers, etc.). With the 2021 amendment to the Act—which expanded the scope to include QR code payment service providers and others—the scope of businesses subject to these requirements has been broadened to seven categories.The practical guidelines for this obligation are set forth in the “Credit Card Security Guidelines” issued by the Credit Transaction Security Measures Council, which were revised to Version 6.0 in March 2025.

    The underlying reason is the increasing severity of the damage. The amount of losses from credit card fraud reached a record high of 55.5 billion yen in 2024, with more than 90 percent of that figure attributable to “card number theft”—the use of card information stolen through data breaches or phishing.The guidelines promote measures to address vulnerabilities at e-commerce merchants and the adoption of EMV 3-D Secure, and credit card companies and payment service providers (PSPs) are expected to play a role in advising merchants and providing them with information.

    Reference: https://www.j-credit.or.jp/customer/5countermeasures-creditcard_fraud/

    What sets credit card companies’ incident response apart from other industries is that it involves a two-pronged approach: “system recovery” and “curbing fraudulent use.” If card information is leaked at a merchant or payment service provider (PSP), even if the company’s own systems remain intact, a series of measures are initiated simultaneously, including strengthening monitoring for fraudulent use, notifying affected members, replacing cards, and coordinating with merchants and card brands.While reports under the Enhanced Security Act are expected to focus primarily on attacks targeting core systems responsible for authorization and payment processing, incident response teams must design their workflows based on the assumption that statutory reporting, compliance with the Installment Sales Act, reporting under brand rules, and member support will all proceed simultaneously.

    Issues Unique to the Financial Sector: Agency Structures and the Design of “Perception”

    A key vulnerability shared by the financial and credit card industries is the depth of their outsourced system infrastructure. Whether it’s shared service centers, core banking system vendors, payment networks, or cloud-based SaaS—incidents occurring outside a company’s own operations can directly lead to service outages or data breaches.

    The fact that the draft framework for the Strengthening Act defines the point at which a cloud service provider issues a notification as “awareness” carries significant weight. The design of the “notification reception point”—specifically, who receives notifications of outages or security breaches from vendors or shared service centers, through which channel, and within how many hours these notifications are escalated to the decision-making chain—effectively determines whether the reporting obligation can be fulfilled. Check whether notification clauses are included in outsourcing contracts or SLAs, and ensure that notification recipients’ email addresses have not been left as those of former employees.It may seem like a minor detail, but this is the first point to check.

    Industry mechanisms such as the Financial ISAC and Scepter have long served as frameworks for information sharing. Once the Strengthening Act takes effect, statutory reporting to the government and information sharing within the industry will proceed in parallel; therefore, clarifying in advance—during normal times—what information should be disclosed, by whose decision, and to whom will help reduce confusion in the event of an emergency.

    What to Do Before the Law Takes Effect

    First, check the official notice to confirm whether your company (or data center) has been designated as a Specified Social Infrastructure Operator. If so, your immediate priorities are to conduct an inventory of Specified Critical Computers that may be subject to reporting requirements and to establish a reporting workflow to submit preliminary and detailed reports by the deadlines. If you have an equipment list created in preparation for the prior review under the Economic Security Promotion Act, you can use that as a starting point.

    Even if no specific requirements are specified, the steps you need to take remain largely the same. Identify the gaps between the “Basic Response Measures” outlined in the Financial Services Agency guidelines and your organization’s current status, and establish a CSIRT, contingency plan, and reporting and public relations framework. Conduct a trial run of a drill where you respond to notifications from a shared response center or a vendor.For card issuers, in a scenario where data breach response and fraudulent use response proceed simultaneously, incorporate multiple reporting destinations—including the Installment Sales Act, the Personal Information Protection Act, brand rules, and (if applicable) the Enhanced Protection Act—into a single response workflow. As the number of reporting requirements increases, the benefits of centralized record-keeping—where “a single entry can be used for reporting under each system”—become increasingly evident.

    Finally, there is the issue of management involvement. As the Financial Services Agency guidelines clearly state that cybersecurity is a management responsibility, approving incident response plans and participating in training are tasks for management, not the IT department. It is important for the organization to confirm this role before the time-sensitive reporting system—comprising initial and detailed reports—is implemented.

    Some details of the law will be finalized through cabinet orders, ministerial ordinances, and operational guidelines prior to its enforcement; therefore, items referred to as “drafts” in this article are subject to change. Please refer to the official documents published by the Cabinet Office (Cyber Security and Economic Security Divisions), the Financial Services Agency, and the Ministry of Economy, Trade and Industry for the latest information.

    And so, Incident Lake

    As we have seen so far, incident response in the financial and credit card sectors is characterized by the sheer number of entities to which reports must be submitted. These include reports to regulatory authorities; preliminary and detailed reports under the Enhanced Security Act; reports to the Personal Information Protection Commission; notifications to card brands and industry associations; and notifications to customers and members. While working on the front lines to stop fraudulent use and restore services, it is simply not feasible to rely solely on manual labor to consistently submit all these reports on time and without inconsistencies.

    Incident Lake is an incident management platform that supports this entire process. It automates everything from reporting an incident to recovery, as well as the creation and management of reports, allowing staff to focus their time on what truly matters: “stopping the damage and protecting customers.” Now that time-sensitive reporting requirements—such as initial and detailed reports—are becoming standard practice, we recommend transitioning your reporting and record-keeping systems to a model that doesn’t rely on individual effort.


    Reference Materials

    Author of this article

    President and CEO

    Takaaki Kanetsuki

    SIGQ Inc. Representative Director

    Graduated from the University of Tsukuba Graduate School; specializes in databases and distributed systems.
    An engineer who handles unstructured, real-time operational data—essential in the AI era.
    Joined Money Forward, Inc. as a new graduate. Engaged in management and development at various development sites, including overseas locations, such as a secondment to the Vietnam office.
    Joined Played Inc. in 2022 and is responsible for Platform Engineering. Involved in the development of large-scale distributed data systems.
    Founded SIGQ Inc. in 2024.

    Share this article

    Facebook Share ButtonX Share Button
    Backspace key

    List of Helpful Articles