
Why Is "Preparedness" Put on the Back Burner? — What the October Legislative Amendment Reveals
Author of this article
Public Relations
Tomoko Kaminosuna
Nice to meet you. I’m Kamisago, a public relations specialist at a SaaS company, and I’ll be writing this series.
To be honest, I’m not a crisis management PR professional who’s weathered countless crises.In fact, I’ve never even stood on the podium at a press conference. However, at my previous company, I worked closely with a consultant to seriously develop a crisis management and public relations manual. I also helped establish internal systems and actually planned and carried out drills simulating crisis scenarios. In this series, I’ll be reflecting on that experience—specifically, “What was difficult, and how should I have organized things?”—as I write. I hope you’ll read this not as a tale of heroic exploits, but as the account of someone who took the time to properly prepare.
For the first installment, we’ll start with a discussion of legislative amendments to provide an overview of recent social trends.
The Cyber Response Capability Enhancement Act: What Its October Implementation Signifies
On October 1, 2026, the "Act on the Prevention of Damage Caused by Unlawful Acts Against Important Computers," commonly known as the Cyber Response Capability Enhancement Act, will come into effect.
I imagine many of you are thinking, “This law seems kind of complicated,” so I’ll explain it in as simple terms as possible.
Simply put, this law establishes a rule requiring companies that support the foundations of daily life—such as electricity, gas, telecommunications, water, finance, and aviation (legally referred to as “core infrastructure operators”)—to properly report any cyberattacks they suffer to the government. It is estimated that approximately 257 companies across 15 industries are subject to this law.*1
*1 Cabinet Secretariat, National Cyber Coordination Office, “Regarding the Act on Strengthening Cyber Response Capabilities and the Act on the Establishment of Related Systems”
https://www.cas.go.jp/jp/seisaku/cyber_anzen_hosyo_torikumi/index.html
https://www.cas.go.jp/jp/seisaku/cyber_anzen_hosyo_torikumi/pdf/setsumei.pdf
The idea is that companies supporting the foundation of society are now subject to a new rule stating, “If a ‘cyberattack’—akin to a fire—occurs, they must report it to the government according to established procedures.” Failure to report will result in a corrective order from the supervising ministry or agency, and failure to comply with that order will result in a fine※2.
*2 Act on the Prevention of Damage Caused by Unlawful Acts Against Important Computers (Act No. 42 of Reiwa 7)
https://laws.e-gov.go.jp/law/507AC0000000042
The key point here is the danger of assuming, “This doesn’t apply to us because we aren’t a critical infrastructure operator.” Even if a company isn’t directly subject to this law, there are likely many companies that provide systems or services to covered entities, or that are connected to them as business partners or contractors. Once the entities supporting critical infrastructure take action, companies in their surrounding ecosystem will eventually be required to maintain the same level of preparedness.Rather than thinking, “We’re not subject to this, so we’re safe,” I believe it’s more accurate to view the situation as, “The companies that will be subject to this are already starting to change.”
To be honest, when I first saw the news about this law, I initially thought, “This doesn’t really have much to do with me.” But as I looked into it further, I realized that this isn’t just an issue for specific industries—it’s a sign that “society as a whole is moving toward expecting companies to be ‘prepared.’” This series began with that realization.
Why Doesn't Crisis Management Communications Move Up the Priority List?
Even when laws change, crisis management communications rarely rises to the top of the priority list at many companies. I think this is a hurdle that every public relations professional faces at least once.
The important thing here is not to reduce this to the simple explanation that “management lacks an understanding of crisis management.” If you put yourself in management’s shoes, you’ll see that there are valid reasons why investment decisions are difficult.
First, companies must generate revenue for today, next month, and the next fiscal year within their limited resources. Under these circumstances, it is very difficult to evaluate investments in “events that may or may not happen” compared to other types of investments. While the success of developing a new feature can be judged by its impact on revenue, the success of investing in crisis management communications can only be proven by “nothing happening.” It’s a somewhat perverse structure: the more successful it is, the less visible the results become.
Furthermore, internal evaluation systems are often designed to prioritize “offensive” achievements, and mechanisms to encourage investment in “defensive” measures are frequently lacking. I believe this is less a problem specific to management and more a structural challenge common to many companies.
That is precisely why I believe companies do not need to aim for perfection in their crisis management efforts while they are still small. As a general guideline, it is more realistic to begin addressing these issues gradually once the business has stabilized, the number of customers and employees has grown, and the stakes have become higher. For companies already implementing a BCP (Business Continuity Plan), the most manageable approach is to start by incorporating the perspective of crisis communications into that plan.Crisis management communications can be said to address the aspect of a BCP that deals with “how to explain the situation to the outside world.”
Turning External Pressure to Your Advantage
After reading this far, some of you may be wondering, “So, how do I explain this to management to get them to take action?”
Based on my own experience, I can say that it’s much more efficient to effectively leverage external pressure than to try to persuade management solely through internal arguments. Whether it’s legislative changes like the ones discussed here, due diligence by investors, audits by business partners, or guidelines from industry associations, the fact that something is “required from the outside” serves as a much stronger persuasive argument than building a case from scratch internally.
The reason we chose to focus on this legislative amendment as an entry point for the first session was precisely to encourage people to use this “external pressure” as their first step.
The Purpose of This Series
Finally, I’d like to reiterate the stance of this series.
I am not an expert who has been on the front lines of major system failures or press conferences. I am simply a practitioner who, in my previous job, once worked with a consultant to seriously develop a crisis management communications manual—and even conducted actual drills. I will be writing the following content from the perspective of “If I were to start from scratch again.”
Next time, I’ll discuss the big picture to help you move past the point where you feel like, “I don’t know where to start” with crisis management communications.
Author of this article
Public Relations
Tomoko Kaminosuna
I have worked in public relations for approximately 14 years. It has been nearly eight years since I shifted my focus from the culture and entertainment industry to the B2B SaaS sector. I remain deeply interested in the process by which the global economy—based on ESG management—is incorporating non-financial capital itself into business strategies as the “source” of medium- to long-term corporate value and competitiveness. Integrity is a core value I hold dear. To help Japan become a “leader in public relations,” I have made it my life’s work to promote the public relations profession itself.
List of Helpful Articles



