
[Electricity and Gas Utilities] How Incident Response Will Change with the Enforcement of the Cyber Response Capability Enhancement Act
July 22, 2026
Author of this article
President and CEO
Takaaki Kanetsuki
The public-private partnership provisions of the so-called “Cyber Response Capability Enhancement Act” (official title: Act on the Prevention of Damage Caused by Unauthorized Acts Against Critical Computers), which was enacted in May 2025, will take effect in October 2026.Electricity and gas are listed at the top of the 15 critical infrastructure sectors, and designated operators will be legally required to register their system assets and report cyber incidents to the government.
When looking back at cyberattacks around the world, the energy sector is the one where the most severe damage has actually occurred. In 2015, in Ukraine, the control systems of an electric utility were tampered with, causing a large-scale power outage; and in 2021, in the United States, a major fuel pipeline was hit by a ransomware attack, halting operations for about five days and causing fuel shortages on the East Coast.
In response to these circumstances, Japan’s electricity and gas industries—which were among the first sectors within critical infrastructure to develop legal frameworks and guidelines—are now seeing the Critical Infrastructure Protection Act add a new layer of requirements in the form of “reporting obligations to the national government.”
In this article, we will organize the incident response requirements for electric and gas utilities into three categories: laws, safety regulations, and guidelines.
Legal Requirements: Notifications and Incident Reporting
The entities directly subject to the Strengthening Act are “specified social infrastructure operators” (core infrastructure operators) designated under the Economic Security Promotion Act; as of April 1, Reiwa 8, a total of 257 such operators across all sectors had been designated. The electricity and gas sectors have been covered by the system since its inception; operators in these sectors were designated in November Reiwa 5, and the regulations governing prior review for the introduction of specified critical facilities have been in effect since May 17, Reiwa 6.
The Strengthening Act imposes the following obligations on designated operators: They must report to the government the vendor names and product information for “specified critical computers” among the information systems involved in core business operations; and they must report incidents in the event of a cyberattack.
Regarding the reporting framework, the draft guidelines for implementation presented to the Cabinet Office’s Expert Panel outline a two-stage reporting process. Upon becoming aware of an incident, a “preliminary report” must be issued promptly, followed by a “detailed report” within 30 days. In both cases, reports need only include the information available at that time; there is no requirement for a complete cause analysis during the initial response phase.
Reports must cover not only evidence of “specific misconduct,” such as unauthorized access, but also related incidents. The system is designed so that the reporting obligation takes effect from the early warning stage.
The procedures for handling such incidents in cloud environments have also been clarified. In the case of SaaS or PaaS (related to middleware or operating systems), an incident is deemed to have been “acknowledged” as soon as a notification is received from the cloud service provider. Businesses operating in sectors where cloud adoption is advancing—such as customer management and billing systems—must establish in advance a designated point of contact for receiving incident and breach notifications from vendors, as well as procedures for incorporating these notifications into their reporting workflow.
The penalties cannot be overlooked either. Violating the reporting obligation and failing to comply with a corrective order issued by the regulatory authority is punishable by a fine of up to 2 million yen, while failing to comply with a request to submit documents or other materials is punishable by a fine of up to 300,000 yen.
Furthermore, businesses not directly designated are not entirely unaffected. It has been pointed out that IT vendors and group companies entrusted with the operation of designated critical computers, as well as equipment owned by subcontractors—depending on the system configuration—may also be subject to these requirements.
In the electric power industry, where the separation of power generation, retail sales, and transmission and distribution—as well as the outsourcing of operations to group companies—has become widespread, and in the natural gas industry, where joint transportation and contract manufacturing are common, it is entirely possible that your company could be involved in the system as a “contractor for a designated operator.”
Requirements that are “already” mandated by security legislation
As professionals in the electricity and gas industries are well aware, this is not the first time cybersecurity regulations have been strengthened in this sector. In fact, it is one of the earliest sectors within critical infrastructure to have had mandatory standards established.
With regard to electricity, Article 15-2 of the “Ministerial Ordinance Establishing Technical Standards for Electrical Installations” stipulates that cybersecurity must be ensured for computers used to manage the operation of commercial electrical installations, so as to prevent any risk of harm to human beings or damage to property, as well as any risk of causing significant disruption to the electricity supply.
This provision was introduced by the 2016 (Heisei 28) amendment, and the interpretation of the technical standards stipulates that specific guidelines—such as the “Power Control System Security Guidelines”—must be followed. Furthermore, the amendment in June Reiwa 4 expanded the scope to include private electrical installations (effective October of the same year), and operators of covered facilities are now required to explicitly stipulate cybersecurity measures in their safety regulations.
With regard to gas, amendments to the Enforcement Regulations of the Gas Business Act (promulgated in 2019) have designated the assurance of cybersecurity for computers used to manage the operation and control of gas facilities as a matter that must be incorporated into safety regulations.Based on the principle of placing safety regulations—which form the foundation of safety activities—at the center of legal compliance efforts, the Japan Gas Association has developed the “Guidelines for Security Measures for Control Systems Related to Production and Supply” as industry guidelines and has supported operators in establishing their internal regulations.
In addition, the so-called “smart safety” amendments to the law promulgated in Reiwa 4 (partial amendments to the High-Pressure Gas Safety Act, the Gas Business Act, the Electric Utilities Act, etc.) introduced a mechanism whereby the national government can request the Information-technology Promotion Agency (IPA), an independent administrative agency, to conduct an investigation to determine the cause in the event of a serious cybersecurity incident related to safety, or when such an incident is suspected.A framework for government involvement in the “aftermath” of incidents has already been incorporated into safety legislation.
In other words, it is more accurate to view the Enhanced Act as not imposing a new obligation on electricity and gas utilities from scratch, but rather as adding an operational requirement—namely, to “report to the national government promptly upon detection”—on top of the measures they have already established through safety regulations and technical standards.
"Practical Incident Response" as Outlined in the Guidelines
The Ministry of Economy, Trade and Industry (METI), the Agency for Natural Resources and Energy, and industry associations have developed several guidelines for the electricity and gas sectors. In the electricity sector, the “Electric Power Control System Security Guidelines” call for the planning, implementation, inspection, and improvement of security measures based on the PDCA cycle. In March of Reiwa 6, the Agency for Natural Resources and Energy published the “Cybersecurity Risk Assessment Guide for Electric Power Systems,” which includes 108 risk assessment items based on the functions and categories of the NIST CSF.Underlying this guide is the recognition that, while security measures are advancing through the development of guidelines, threats are evolving daily, and current measures are by no means sufficient.
Here are some key points to keep in mind from an incident response perspective.
Plan on the assumption that IT disruptions will lead to supply disruptions
As exemplified by the U.S. pipeline incident, even if it is the business (IT) systems that are infected with ransomware, management may be forced to make the decision to shut down the supply side (OT) due to security concerns or the inability to manage billing and shipping. It is not necessarily true that “since the control systems are intact, supply can continue.”
The core of an energy provider’s incident response lies in establishing, in advance and during normal operations, the criteria for determining who will decide whether to continue supply when an IT-related incident occurs, and how that decision will be made.
Don't Overestimate the Boundary Between OT and IT
During the 2015 power outage in Ukraine, control systems that were logically isolated by firewalls and VPNs were compromised via the VPN using legitimate credentials stolen from employee workstations.
While the increase in connection points resulting from advancements in maintenance VPNs, remote monitoring, and smart security enhances efficiency, it also broadens the attack surface. The Reiwa 4 amendment, which extended the application of technical standards to private electrical installations, is nothing less than a response to the expanded risk landscape brought about by the widespread adoption of remote monitoring and control.
Start recording from the early warning stage and take action
Under the Enhanced Compliance Act, reporting requirements extend to “events leading to” specific acts of misconduct. Anomalies detected through monitoring of both control and information systems are recorded chronologically and fed into a process to determine whether they require reporting. The key challenge is whether this entire process can be executed quickly enough to meet the deadline for preliminary reports.
Making the Most of the Information-Sharing Framework
The electric power sector has industry-wide information-sharing frameworks such as the Electric Power ISAC and SEPTER, and the gas sector has also been steadily building up knowledge-sharing and training through SEPTER. Following the enforcement of the Enhanced Security Act, multiple channels—including statutory reporting to the national government, cooperation with the IPA in investigations, and information sharing within the industry—will operate in parallel. Which information should be disclosed, based on whose decision, and to whom? Establishing clear points of contact during peacetime can significantly reduce confusion in the event of an emergency.
What to Do Before the Law Takes Effect
With the law set to take effect in October 2026, the actions that designated (or potential designated) businesses need to take are becoming clearer.
Asset Inventory
We will identify specific critical computers and peripheral devices that may be subject to reporting requirements. This will involve identifying—based on the severity of potential impact—not only systems related to monitoring and control, power supply operations, and manufacturing and supply control, but also any other systems where an attack could lead to the suspension or degradation of supply operations. The list of facilities compiled in preparation for the preliminary review under the Economic Security Promotion Act should serve as a starting point for this process.
Establishing a Reporting Process
The definition of an incident (including notifications from cloud vendors), the procedures for drafting and approving preliminary reports, and the investigation framework for submitting detailed reports within 30 days will be incorporated into the emergency response plan.The electricity and gas sectors have existing accident reporting systems based on the Electricity Reporting Regulations and the Gas Business Act, respectively; the reporting requirements under the Enhanced Act differ from these in both purpose and intended recipients. Assuming that multiple reports will be filed for the same incident, we should standardize the reporting format so that “a single entry can be used to generate reports for each system.”
Management Involvement
The decision on whether to halt operations due to an IT-related incident cannot be left solely to on-site staff or the IT department. As indicated by the requirement to explicitly include cybersecurity in safety regulations, security in this area is a matter of safety itself—and thus falls under the purview of executive management. The final step before the regulations take effect is to establish the approval of incident response plans and participation in training as the responsibility of executive management.
Some details of the law will be finalized through cabinet orders, ministerial ordinances, and operational guidelines prior to its enforcement; therefore, items referred to as “drafts” in this article are subject to change. Please refer to the official documents published by the Cabinet Office (Cyber Security and Economic Security Divisions) and the Ministry of Economy, Trade and Industry (METI) and the Agency for Natural Resources and Energy for the most up-to-date information.
And so, Incident Lake
As we have seen so far, the real burden of complying with the Enhanced Act lies not so much in establishing rules during normal times as in “the practical response starting from the very moment an incident occurs.”Organizing the facts as they are known to issue a preliminary report promptly; maintaining a chronological record while simultaneously making decisions to ensure uninterrupted supply; compiling a detailed report within 30 days; and handling reports to multiple recipients—including statutory reports to the national government, existing accident reports, and information sharing within the industry—leaves almost no room to allocate personnel to reporting tasks at a time when all efforts should be focused on maintaining supply.
Incident Lake is an incident management platform that supports this entire process. It automates everything from reporting an incident to recovery, as well as the creation and management of reports, allowing staff to focus their time on what truly matters: “protecting and restoring supply.” Now that time-sensitive reporting requirements—such as preliminary and detailed reports—are becoming institutionalized, we recommend shifting your reporting and record-keeping systems away from relying on individual effort.
Reference Materials
Article 15-2 of the Ministerial Ordinance Prescribing Technical Standards for Electrical Installations (Ministry of International Trade and Industry Ordinance No. 52 of Heisei 9)
Ministry of Economy, Trade and Industry: “Ensuring Cybersecurity in Private Electrical Installations” https://www.meti.go.jp/policy/safety_security/industrial_safety/sangyo/electric/detail/cybersecurity.html
Agency for Natural Resources and Energy, “Guide to Assessing Cybersecurity Risks in the Electric Power System” (March Reiwa 6)
https://www.meti.go.jp/press/2023/03/20240322003/20240322003.html
Agency for Natural Resources and Energy, “Cybersecurity in the Electric Power Sector” (April 17, 2024; Materials for the Subcommittee on Basic Policies for Electricity and Gas) https://www.meti.go.jp/shingikai/enecho/denryoku_gas/denryoku_gas/pdf/073_07_00.pdf
Ministry of Economy, Trade and Industry, Industrial Safety Group, “Initiatives to Improve Cybersecurity Measures in the Gas Sector” (March 2019, Gas Safety Subcommittee Materials) https://www.meti.go.jp/shingikai/sankoshin/hoan_shohi/gas_anzen/pdf/019_04_02.pdf
Cabinet Office: “System for Ensuring the Stable Provision of Critical Infrastructure Services” https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/infra.html
Director-General for Policy Coordination, Cabinet Office (in charge of Cybersecurity): “Draft Guidelines for the Enforcement of the Act on Strengthening Cyber Response Capabilities (Public-Private Partnership)” (December Reiwa 7) https://www.cao.go.jp/cybersecurity/kaigi/pdf/04shiryo05.pdf
Nikkei CrossTech: “Cyber Response Capability Enhancement Act to Take Effect in October; Risk of Being Excluded by Business Partners” (2026) https://xtech.nikkei.com/atcl/nxt/column/18/00989/042300207/
Author of this article
President and CEO
Takaaki Kanetsuki
SIGQ Inc. Representative Director
Graduated from the University of Tsukuba Graduate School; specializes in databases and distributed systems.
An engineer who handles unstructured, real-time operational data—essential in the AI era.
Joined Money Forward, Inc. as a new graduate. Engaged in management and development at various development sites, including overseas locations, such as a secondment to the Vietnam office.
Joined Played Inc. in 2022 and is responsible for Platform Engineering. Involved in the development of large-scale distributed data systems.
Founded SIGQ Inc. in 2024.
List of Helpful Articles



