In an era when the most dangerous intrusions are the ones that go unseen, Japan is preparing to search its own critical infrastructure for threats that may already be present. Beginning in fiscal 2027, the National Cybersecurity Office will develop active threat-hunting methods—born from simulated attacks in controlled environments—and extend them to the private utilities and telecom firms that underpin modern life. The initiative is shaped by a sobering precedent: a state-backed group that quietly inhabited American infrastructure for five years before anyone noticed. Japan is betting that th
Japan launches cyber threat-hunting program for critical infrastructure
Waiting for alarms to sound is no longer enough.
So the government is going to hunt for cyberattacks that are already inside critical infrastructure systems. Why now? What changed?
The Volt Typhoon case in the U.S. showed that a state-sponsored group could sit inside power grids and telecom networks for five years without being detected. Japan looked at that and realized it could happen here.
Right, but we should be clear: the U.S. detected Volt Typhoon eventually. We don't know how many other groups might still be hiding. The threat is real but also somewhat speculative.
So the government is going to develop detection methods and share them with private companies. How does that actually work?
The National Cybersecurity Office will recreate attacks in virtual environments, test detection techniques, and then hand those methods to utilities and telecom companies so they can search their own networks.
That assumes the private sector will actually use them. NTT Data has been doing threat-hunting since 2024, and even they're struggling to justify the cost to management.
That's the real problem, isn't it? The cost.
Exactly. Threat-hunting is expensive and labor-intensive. You're paying people to search through logs looking for something that might not be there.
And here's the thing: companies are more worried about ransomware, which is visible and immediate. A hidden five-year infiltration feels theoretical.
But the government is arguing threat-hunting helps with both?
Yes. Ransomware attackers use similar tactics—they probe systems after getting in. So if you're hunting for hidden threats, you're also building defenses against ransomware.
That's a reasonable argument, but we won't know if it works until companies actually adopt these methods. The government can develop the tools, but adoption is a different problem.
Le Pouls
- The threat is not hypothetical — state-sponsored actors have already demonstrated they can live inside critical infrastructure for years, invisible and patient, waiting for the right moment to act.
- Japan's power grids and telecom networks face the same vulnerability, and conventional security tools are poorly equipped to detect attackers who deliberately mimic normal administrative behavior.
- The National Cybersecurity Office will simulate suspected intrusions in virtual environments to forge detection techniques, while the Defense Ministry stands ready to dispatch trained personnel directly to operators who ask for help.
- Private companies remain the weak link — threat hunting is expensive, its benefits are hard to quantify, and executives accustomed to the visible urgency of ransomware are reluctant to fund searches for dangers they cannot yet see.
- New active cyberdefense legislation, enacted this same week, gives the government the legal footing to pursue a more assertive posture — but the real measure of success will be whether utilities and telecoms actually deploy the tools they are handed.
In an era when the most dangerous intrusions are the ones that go unseen, Japan is preparing to search its own critical infrastructure for threats that may already be present. Beginning in fiscal 2027, the National Cybersecurity Office will develop active threat-hunting methods—born from simulated attacks in controlled environments—and extend them to the private utilities and telecom firms that underpin modern life. The initiative is shaped by a sobering precedent: a state-backed group that quietly inhabited American infrastructure for five years before anyone noticed. Japan is betting that the discipline of looking before the alarm sounds may be the only defense that matters.
Japan's government is preparing to search for cyberattacks that have already slipped inside the systems of power companies and telecommunications firms — intrusions engineered to lie dormant for months or years before being activated. From fiscal 2027, the National Cybersecurity Office will develop detection methods for these hidden threats and share them with private operators, so companies can search their own networks before an adversary decides to act.
The urgency is grounded in recent history. In 2024, U.S. authorities revealed that a group called Volt Typhoon, believed to be Chinese state-sponsored, had maintained undetected access to American critical infrastructure for more than five years, using ordinary administrative tools to blend seamlessly into normal network traffic. Japan sees itself as a plausible next target and is responding with a discipline called threat hunting — the practice of actively combing through logs and network activity on the assumption that an attacker may already be inside, rather than waiting for an alarm to confirm it.
The National Cybersecurity Office will recreate suspected attacks in virtual environments to test and refine detection techniques. The Defense Ministry will contribute expertise developed within the Self-Defense Forces and will send personnel directly to critical infrastructure operators who request support. Both agencies have included funding in their fiscal 2027 budget requests, and the effort arrives alongside new active cyberdefense legislation that took effect this week.
The harder challenge is cultural and economic. NTT Data Japan, which began its own threat-hunting program in 2024, knows the difficulty firsthand: the work is painstaking, the costs are real, and the threat it guards against feels abstract compared to ransomware, which announces itself loudly and demands immediate attention. The government's answer is to reframe threat hunting as a defense against multiple attack types — ransomware included — in hopes of making the investment case easier for executives to accept. Whether utilities and telecoms will actually use the detection methods once they receive them remains the question Japan cannot yet answer.
Japan's government is preparing to hunt for cyberattacks that have already breached the systems of power companies and telecommunications firms—the kind of intrusions designed to hide for months or years before striking. Starting in fiscal 2027, the National Cybersecurity Office will develop methods to detect these dormant threats and hand the blueprints to private operators so they can search their own networks before attackers activate whatever access they've gained.
The push reflects a specific fear: that hostile actors, particularly state-sponsored groups, could infiltrate critical infrastructure and simply wait. In 2024, U.S. authorities documented exactly this scenario with a hacker group called Volt Typhoon, believed to be backed by the Chinese government, which had maintained access to American critical infrastructure for more than five years. The group used legitimate administrative tools to blend in, making detection nearly impossible through conventional means. The longer such access persists undetected, the greater the potential for catastrophic disruption—power grids down, communications severed, a nation's essential services compromised during a crisis.
Threat hunting, as the practice is known, represents a shift in defensive thinking. Rather than waiting for alarms to sound, security teams actively search through system logs and network activity for signs of compromise, assuming an attacker may already be inside. The Japanese government's National Cybersecurity Office will recreate suspected attacks in controlled virtual environments, then develop and test detection methods that private companies can deploy. The Defense Ministry will contribute its own expertise, drawn from threat-hunting work done within the Self-Defense Forces' information systems, and will dispatch personnel directly to critical infrastructure operators who request assistance.
Both agencies have included funding for these efforts in their fiscal 2027 budget requests. The timing aligns with new legislation on active cyberdefense that took effect this week, giving the government a legal framework to pursue more aggressive security postures.
But threat hunting is labor-intensive and expensive. NTT Data Japan, one of the country's largest technology companies, began conducting threat-hunting within its own systems in 2024. The work means searching through logs for suspicious patterns even when no alarm has been triggered, based on the premise that an attack could be underway undetected. Yusuke Nakajima, the company official overseeing the program, acknowledged the central challenge: convincing executives that the investment is worth the cost. "To expand this activity, we need to demonstrate its cost-effectiveness to management," he said.
A National Cybersecurity Office official noted that companies are unlikely to fund threat-hunting if they think of it only as protection against hidden, long-term infiltrations—a threat that feels abstract compared to ransomware, which strikes visibly and demands immediate payment. Yet threat-hunting can address ransomware too, since attackers often use similar tactics: they probe systems after gaining entry, looking for valuable data or critical functions to encrypt. By framing threat-hunting as a tool that defends against multiple attack types, the government hopes to make the case for private investment more compelling. The real test will be whether utilities and telecom companies, once they have the detection methods in hand, actually use them.
Citations marquantes
To expand this activity, we need to demonstrate its cost-effectiveness to management.— Yusuke Nakajima, NTT Data Japan threat-hunting program official
Preparing only for attacks involving hidden threats is unlikely to persuade company executives to invest in such measures.— National Cybersecurity Office official