
[Water Utilities] How Incident Response Will Change with the Enforcement of the Cyber Response Capability Enhancement Act
July 20, 2026
Author of this article
President and CEO
Takaaki Kanetsuki
The public-private partnership provisions of the so-called “Cyber Response Capability Enhancement Act ( Explanatory Article )” (official title: Act on the Prevention of Damage Caused by Unauthorized Acts Against Important Computers), which was enacted in May 2025, will take effect in October 2026.Along with electricity, gas, and telecommunications, water supply is included among the covered sectors; designated water utilities will be legally required to file notifications regarding their system assets and report cyber incidents to the government.
“We’re on a closed network, so this doesn’t apply to us” and “Monitoring and control have always been separate” are common remarks heard on the front lines of core industries. However, when you read this law alongside the “Safety Guidelines for Ensuring Information Security in the Water Supply Sector” enacted by the Ministry of Land, Infrastructure, Transport and Tourism in March 2025, it becomes clear that these assumptions themselves are in need of reevaluation.In this article, we will outline the practical incident response measures required of water utilities, organized into three categories: laws, ministerial ordinances, and guidelines.
Legal Requirements: Notifications and Incident Reporting
The entities directly subject to the Enhanced Act are operators in the 15 critical infrastructure sectors designated under the Economic Security Promotion Act; as of July 2025, a total of 257 such entities have been designated. Water supply is one of these 15 sectors. Designated operators must report to the government the vendor names and product information of “specified critical computers” among the information systems related to their core operations, and must also report any incidents in the event of a cyberattack.
Regarding the content of the report, the draft guidelines for implementation presented to the Cabinet Office’s Expert Panel outline the following framework:
First, reporting occurs in two stages: a “Preliminary Report” must be issued promptly upon becoming aware of an incident, and a “Detailed Report” must be submitted within 30 days. For both reports, organizations are only required to report the information known at that time; they are not expected to provide a complete root cause analysis during the initial response.The reporting requirements cover not only traces of “specific malicious acts,” such as unauthorized access, but also related events. In other words, the system is designed so that the reporting obligation begins at the early warning stage, rather than waiting to report only after an intrusion has been confirmed.
Guidelines for handling cloud services have also been established at the draft stage. In the case of SaaS and PaaS (related to middleware and operating systems), “awareness” is deemed to have occurred at the time the cloud service provider issues a notification. Businesses that have migrated their meter reading, billing, and ledger systems to the cloud must establish in advance a designated point of contact for receiving notifications of outages or security breaches from vendors, as well as procedures for incorporating such notifications into their reporting workflow.
The penalties cannot be overlooked either. Violating the reporting obligation and failing to comply with a corrective order issued by the regulatory authority is punishable by a fine of up to 2 million yen, while failing to comply with a request to submit documents or other materials is punishable by a fine of up to 300,000 yen.
While direct designation is limited to large-scale operators, entities not subject to designation are not entirely unaffected. It has been pointed out that IT vendors and group companies entrusted with the operation of specified critical computers, as well as equipment owned by subcontractors—depending on the system configuration—may also fall under the scope of these regulations. In the water supply sector, where joint operations, regional consolidation, and comprehensive outsourcing are on the rise, organizations should be aware of the possibility that they themselves could be implicated as “subcontractors.”
Matters that are “already” required by ministerial ordinance
Although it is often overlooked, mandatory cybersecurity standards already exist in the water supply sector. Article 1, Item 11-2 of the “Ministerial Ordinance Establishing Technical Standards for Water Supply Facilities ” requires that necessary measures be taken to ensure cybersecurity for computers used to manage facility operations, so as to prevent any significant disruption to the water supply. This provision was established through an amendment to the ordinance in Reiwa 1 and has been in effect since April Reiwa 2.
Specific actions to be taken are outlined in the “Points to Note” section of the Section Chief’s Notice, which was revised in February Reiwa 7 to coincide with the enactment of the first edition of the Safety Guidelines. The notice lists measures such as implementing subject authentication functions for computers in control systems and installing antivirus software and keeping it up to date. The accurate current status is that operators of monitoring and control systems are already subject to legal compliance obligations, even before the Enforcement Act takes effect.
"Practical Incident Response" as Outlined in the Guidelines
Although the Ministry of Land, Infrastructure, Transport and Tourism’s safety guidelines (enacted in March 2025; first edition) are recommendations rather than mandatory requirements, it is safe to say that these guidelines provide the practical foundation for fulfilling reporting obligations under the amended law. When considering the elements involved in incident response, the process generally follows the flow outlined below.
Normal Times: Establish Systems and Plans. The guidelines require the establishment of a CSIRT or similar body to handle incidents, as well as prior agreement on the division of roles with relevant departments. Since a CSIRT may be either a permanent organization or one established only when an incident occurs, even small and medium-sized organizations that find it difficult to secure dedicated personnel can design such a system.In addition, the guidelines call for the development of a contingency plan that specifies initial response procedures following the recognition of a critical infrastructure service disruption (or the risk thereof), as well as the establishment of BCPs and IT-BCPs. To meet the Enhanced Act’s requirement to “report promptly upon recognition,” it is effectively a prerequisite to specify in this initial response plan the specific pathway through which information travels from the moment on-site personnel notice an anomaly until it reaches senior management or the designated reporting channel.
Detection: Taking Action from the Early Warning Stage
The guidelines address responses to “early warning signs” of cyberattacks in the chapter on crisis management, which is consistent with the fact that the scope of reporting under the Enhanced Act includes “events leading to specific unlawful acts.” An approach that waits to see how things develop until a breach is confirmed does not meet the legal requirements.
Response and Recovery: Factoring in the Limitations of Manual Operation
One of the strengths of water supply systems is that, even if the monitoring and control systems fail, manual operations can, to some extent, serve as a fallback. However, as the guidelines themselves point out, operational efficiency declines during manual operations, and disruptions to water service are to be expected. Rather than simply assuming, “It’ll be fine because we can run things manually in the worst-case scenario,” contingency plans should include decision criteria, procedures, and staffing arrangements for switching to manual operation.
Information Sharing: Utilizing CEPTOAR
CEPTOAR serves as a framework for sharing incident information and early warning signs of attacks in the water supply sector, with the Japan Water Works Association acting as its secretariat. Following the enforcement of the Enhanced Security Act, two parallel channels—statutory reporting to the government and information sharing within the industry—will operate simultaneously. Therefore, clarifying which information should be shared through which channel and by whose decision will help minimize confusion.

Image source: Ministry of Health, Labor and Welfare, “Comprehensive Survey on Cybersecurity Measures in the Water Supply Sector,” p. 37
Training: Turning Plans into Action. The guidelines list the conduct of drills and training as a separate item. Report formats and communication networks are areas where gaps can be identified even by conducting a single tabletop exercise. Training that involves actually drafting preliminary reports is highly cost-effective as part of preparations prior to implementation.
Why the Argument "It's Safe Because It's a Private Network" Doesn't Hold Water
A significant portion of the guidelines is devoted to warning against overreliance on closed networks. According to the guidelines’ definitions, configurations that merely restrict communication using firewalls or routers, or those accessible via an Internet VPN (SSL-VPN, IPsec-VPN), do not qualify as closed networks. Even if a closed network is established using a dedicated line, physical isolation is compromised if any single point on the connected network is connected to the Internet.
Real-world examples have also been reported. In 2010, at a nuclear fuel facility in Iran, a control system that was physically isolated from the Internet was infected with malware—likely via a USB flash drive brought onto the premises—causing the centrifuges to shut down.In 2015, at a Ukrainian power utility, a control system that had been logically isolated by a firewall and VPN was compromised via the VPN using legitimate credentials stolen from an employee’s work computer, leading to a large-scale power outage. In the context of water utilities, connection points between administrative and control systems, as well as field sensors and tablets using Internet-based communication protocols, could serve as entry points in the same manner.
From an incident response perspective, this issue is important because if a risk is overlooked during risk assessment simply because “it’s a closed network,” neither detection mechanisms nor reporting triggers will be designed. The reporting obligations under the Enhanced Security Act begin with “awareness.” Without the means to become aware of an incident, it is impossible to fulfill these obligations.
What to Do Before the Law Takes Effect
With the law set to take effect in October 2026, the actions that designated (or potential designated) businesses need to take are becoming clearer.
First, there is the asset inventory. This involves identifying specific critical computers and peripheral devices that may be subject to reporting requirements, a process that many affected businesses have already begun. The scope includes not only control systems—such as monitoring and control, pump station operations, and water management—but also peripheral devices that, if attacked, could lead to equipment shutdowns or performance degradation.
Second, we need to establish a reporting process. We will incorporate the definition of “awareness” (including cloud notifications), the procedures for drafting and approving preliminary reports, and the investigation framework for submitting detailed reports within 30 days into the contingency plan. We should also take this opportunity to streamline any overlaps with existing reporting systems, such as those for reporting data breaches under the Personal Information Protection Act.
Third, management involvement. The guidelines clearly state that if an organization suffers damage due to deficiencies in its cybersecurity framework, members of management who were involved in making decisions regarding that framework may be held liable for damages. It is important for organizations to confirm, prior to the guidelines taking effect, that incident response is not merely the responsibility of the IT department, but is in fact an integral part of management risk management.
Some details of the law will be finalized through Cabinet Orders, ministerial ordinances, and operational guidelines prior to its enforcement; therefore, items referred to as “drafts” in this article are subject to change. Please refer to the official documents published by the Cabinet Office (Cyber Security Division) and the Waterworks Division of the Ministry of Land, Infrastructure, Transport and Tourism for the most up-to-date information.
And so, Incident Lake

As we’ve seen so far, the real burden of complying with the Enhanced Security Act lies not so much in establishing rules during normal times as in “the practical work that begins the moment an incident occurs.” When you consider the process—organizing the facts as they are identified to issue a preliminary report promptly, documenting the progress in parallel with the response, compiling a detailed report within 30 days, and conducting a post-incident review to prevent recurrence and inform training—it is, frankly, not realistic to manage all of this manually with limited personnel.
Incident Lake is an incident management platform that supports this entire process. It automates everything from reporting an incident to restoring service, as well as the creation and management of reports, allowing staff to focus their time on what really matters: resolving the immediate issue at hand. Now that time-sensitive reporting—such as initial and detailed reports—is becoming an established practice, we recommend shifting your reporting and record-keeping systems away from relying on individual effort.
Reference Materials
Ministry of Land, Infrastructure, Transport and Tourism, “Safety Guidelines for Ensuring Information Security in the Water Supply Sector, First Edition” (Enacted March 5, Reiwa 7) https://www.mlit.go.jp/mizukokudo/watersupply/content/001889644.pdf
Director-General for Policy Coordination, Cabinet Office (in charge of Cybersecurity): “Draft Guidelines for the Enforcement of the Act on Strengthening Cyber Response Capabilities (Public-Private Partnership)” (December Reiwa 7) https://www.cao.go.jp/cybersecurity/kaigi/pdf/04shiryo05.pdf
Nikkei CrossTech: “Cyber Response Capability Enhancement Act to Take Effect in October; Risk of Being Excluded by Business Partners” (2026) https://xtech.nikkei.com/atcl/nxt/column/18/00989/042300207/
Article 1, Item 11-2 of the Ministerial Ordinance Establishing Technical Standards for Water Supply Facilities (Ministry of Health and Welfare Ordinance No. 15 of Heisei 12)
https://www.mhlw.go.jp/web/t_doc?dataId=79aa0299&dataType=0&pageNo=1
Comprehensive Survey on Cybersecurity Measures in the Water Supply Sector
Author of this article
President and CEO
Takaaki Kanetsuki
SIGQ Inc. Representative Director
Graduated from the University of Tsukuba Graduate School; specializes in databases and distributed systems.
An engineer who handles unstructured, real-time operational data—essential in the AI era.
Joined Money Forward, Inc. as a new graduate. Engaged in management and development at various development sites, including overseas locations, such as a secondment to the Vietnam office.
Joined Played Inc. in 2022 and is responsible for Platform Engineering. Involved in the development of large-scale distributed data systems.
Founded SIGQ Inc. in 2024.
List of Helpful Articles


