The government has drawn up draft guidelines outlining 150 measures that should be taken to enhance cybersecurity for businesses managing critical infrastructure. The draft said that even closed networks disconnected from the internet “are not necessarily safe.” In light of a recent series of ransomware attacks, the draft urges such businesses to take measures, including taking out cybersecurity insurance. The government will accept comments from the public on the guidelines until Wednesday.
It plans to revise the draft based on feedback and release the final version by the end of September. The government hopes that industry groups and government agencies will refer to the guidelines when developing safety standards. The draft seeks action from businesses in 16 sectors, including finance, railways and electricity, designated as critical infrastructure.
Describing cybersecurity as “a management issue that can be key to the survival of a company,” the draft said that “it is difficult to completely protect against cyberattacks.” Companies in the designated sectors are urged to improve their capabilities to recover from an attack, fully preparing for the possibility of system failures. The draft cautioned against “overconfidence,” advising companies not to let their guard down because their systems use closed networks or dedicated operating systems or have unique technical specifications. As recommended measures, the draft refers to taking out cybersecurity insurance to ease the possible massive financial impact caused by ransomware attacks, while asking companies not to pay ransoms.
To address cyberattacks utilizing advanced artificial intelligence models such as Claude Mythos, the draft mentions the need to strengthen defense measures promptly, including by using sophisticated AI models. In view of progress in the development of quantum computers, the draft also calls for the adoption of postquantum cryptography, or PQC, which is hard to crack, by as early as 2035.
Extract — continue reading at the source.