Crisis Management

Cyber Incident and Data Breach Response

A cyber attack is no longer just an IT problem: it is a management-level crisis that affects business continuity, reputation and legal liability all at once. In line with our policy of supporting companies "from the first response through to resolution," we advise on the legal aspects of the immediate response, statutory and contractual reporting, communications with affected individuals and business partners, public disclosure, pursuing those responsible and preventing recurrence. For technical measures such as forensic investigations and system containment and recovery, we support coordination with external specialist vendors as the case requires.

Last updated:

Immediate Checklist upon Discovery

  1. Notify the responsible officers immediately, and record the time of discovery, the facts confirmed so far and the actions taken
  2. Isolate devices suspected of being infected or compromised from the network; do not power off, reinitialize, remove malware or restore systems without specialist guidance
  3. Do not delete or overwrite logs, emails, devices or ransom-demand screens, and do not connect backups to the compromised environment
  4. Contact forensic vendors, legal counsel and your cyber insurer, and confirm statutory and contractual reporting deadlines and prior-approval clauses
  5. Do not make snap decisions on ransom payment, public disclosure or explanations to affected individuals and business partners based on unverified information; in the case of wire fraud through business email compromise (BEC), contact the banks and the police immediately

* The necessary measures depend on the nature of the attack. Prioritize containment, such as network isolation, and consult specialists before operating on affected devices or communicating externally.

How we can helpInitial legal response / statutory reporting, notification and disclosure / coordination with external technical specialists

Contact Form
Contents
  1. 1. Typical Incident Scenarios
  2. 2. Initial Response Immediately After Discovery
  3. 3. Reporting and Notification Obligations under Laws and Contracts
  4. 4. Should You Pay a Ransomware Demand?
  5. 5. Wire Fraud through Business Email Compromise (BEC)
  6. 6. Responding to Leaks of Trade Secrets and Confidential Information
  7. 7. Dealing with Affected Parties, Public Disclosure and Directors' Liability
  8. 8. How We Support You
  9. FAQ

1. Typical Incident Scenarios

  • Ransomware attacks: systems and data are encrypted and a ransom is demanded for decryption. In recent years, "double extortion" attacks — where data is first exfiltrated and the attacker threatens to publish it unless payment is made — have become common.
  • Leakage of personal information (customer or employee data) through unauthorized access or targeted attacks.
  • Trade secrets (technical information, customer lists, etc.) taken by officers, employees or former employees and leaked to competitors.
  • Email account takeover and wire fraud through business email compromise (BEC).
  • Leakage of your company's data caused by an attack on a business partner or subcontractor (supply-chain incidents).

2. Initial Response Immediately After Discovery

In a cyber incident, the hours and days immediately after discovery require parallel work on containment, evidence preservation, business continuity and assessment of statutory reporting obligations. Because reporting deadlines differ by applicable law, it is important to record the time of discovery and the time at which each part of the organization became aware of the incident, and to start managing the deadlines from the outset.

(1) Establishing a Response Team and Fact-Finding

Promptly establish a response team that includes management, and begin identifying when, from where, what and to what extent data was leaked or systems were compromised. The fact-finding at this stage forms the basis for later regulatory reports, public disclosure and liability assessments, so it is essential to record the facts while distinguishing what has been verified from what is speculation. The decision-making process of the response team and the board should also be documented.

(2) Evidence Preservation and Containment

Devices suspected of being infected or compromised should be isolated from the network as quickly as possible. Powering devices on or off, reinitializing them, deleting logs or restoring from backups may destroy evidence or volatile data, so these steps should not be taken unilaterally but under the guidance of forensic specialists. Credentials should be changed from devices and environments that have not been compromised, in a manner consistent with the containment plan. We advise from a legal perspective on the scope of the investigation, the matters to be reported and the documentation of the process, and support coordination with external specialist vendors as needed.

3. Reporting and Notification Obligations under Laws and Contracts

(1) Reports to the Personal Information Protection Commission and Notification to Data Subjects

Where personal data has been — or may have been — leaked, lost or damaged, and the incident falls into any of the following categories: (i) special care-required personal information is involved; (ii) there is a risk of financial harm through misuse; (iii) the incident may have been caused with a wrongful purpose; or (iv) more than 1,000 data subjects are affected, then, as a rule, a report to the Personal Information Protection Commission and notification to the affected individuals are required under the Act on the Protection of Personal Information. Leaks caused by unauthorized access will often fall under category (iii); however, the mere fact of having been subject to a cyber attack does not automatically trigger the reporting obligation — the data concerned and the access actually gained need to be examined.

* The "wrongful purpose" category also covers personal information that has been, or was about to be, acquired and that was to be handled as personal data.

Reporting takes place in two stages: a preliminary report to be made "promptly" after becoming aware of a reportable incident (as a guideline, within roughly 3 to 5 days), and a final report within 30 days in principle — or within 60 days where the incident may have been caused with a wrongful purpose — counted from the day the incident became known. Notification to affected individuals must be made promptly in light of the circumstances.

(2) Other Reporting, Notification and Disclosure

  • Where personal data is handled on entrustment: if the entrusted party (service provider) gives the prescribed notice to the entrusting party that bears the reporting obligation, the entrusted party is exempted from the report to the Commission and the notification to data subjects, and the entrusting party responds instead.
  • Listed companies: consider whether timely disclosure is required under stock exchange rules.
  • Sector-specific reporting: financial institutions, telecommunications carriers and other regulated businesses may be subject to separate reporting obligations to their supervisory authorities. In addition, under the Act on Strengthening Cyber Response Capabilities (Act No. 42 of 2025), a framework for public-private cooperation — including the establishment of a council and incident reporting and asset notification by key infrastructure operators — is scheduled to start on October 1, 2026. Special social infrastructure providers subject to the Act (designated critical infrastructure providers under the Economic Security Promotion Act that use specified critical computer systems) will need to confirm whether they are covered and the scope and requirements of the notifications and reports concerned.
  • The GDPR may apply where personal data is processed in the context of the activities of an establishment in the EU/EEA, or where a business outside the EU/EEA offers goods or services to, or monitors the behaviour of, individuals in the EU/EEA. A controller subject to the GDPR must notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A processor must notify the controller without undue delay after becoming aware of a breach. We also examine the application of other foreign laws.

(3) Contractual and Cyber Insurance Notice Requirements

Apart from statutory reporting obligations, contracts with business partners and cyber insurance policies may contain incident notice deadlines, requirements to use designated vendors, or prior-approval clauses for expenses. Without delaying containment, review these contracts promptly after discovery and give the required notices.

4. Should You Pay a Ransomware Demand?

There is no general Japanese statute that categorically prohibits paying a ransom. Depending on the recipient, the payment route and the parties involved, however, economic sanctions under the Foreign Exchange and Foreign Trade Act — and, where there is a U.S. nexus, OFAC regulations — may become an issue. Payment does not guarantee decryption, deletion of the stolen data or protection against repeat attacks. The National Police Agency has also warned that payments can fund criminal groups and that recovery is not assured. The decision should be approached with payment avoidance as the baseline, after notifying your cyber insurer, consulting the police, checking available backups and decryption options, and assessing recovery prospects under your business continuity plan. We help organize and document the considerations — technical, business continuity, legal and sanctions-related — and the decision-making process.

5. Wire Fraud through Business Email Compromise (BEC)

If a fraudulent transfer is discovered, contact the remitting bank immediately and request a remittance recall and coordination with the receiving bank, and consult the police. It is also important to preserve — not delete — the emails, payment instructions, transfer records and access logs concerned.

6. Responding to Leaks of Trade Secrets and Confidential Information

To be protected as a trade secret under the Unfair Competition Prevention Act, information must satisfy three requirements: it must be managed as a secret, be commercially useful and not be publicly known. How the information was managed — access controls, confidentiality markings, internal rules and non-disclosure agreements — has a significant impact on whether rights can be enforced and proven. Where the information qualifies as a trade secret and the acquisition, use or disclosure concerned constitutes trade secret infringement under the Act, remedies such as injunctions, damages claims and measures to restore business reputation can be considered depending on the case. Where the elements of criminal trade secret infringement appear to be satisfied, a criminal complaint is also an option. For confidential information that does not qualify as a trade secret, contractual remedies and notice obligations should be examined as well.

7. Dealing with Affected Parties, Public Disclosure and Directors' Liability

Notifying the individuals, business partners and employees affected by a leak, setting up an inquiry desk, responding to damages claims and, where necessary, making public announcements or holding press conferences all require a design that balances legal accuracy with reputational considerations. Measures to prevent secondary harm, such as impersonation and phishing, should be communicated as well. Depending on the company's size, business, the information it handles and the foreseeability of the incident, the adequacy of its cybersecurity arrangements may also raise issues concerning directors' duty of care and internal control systems. In the resolution phase, we support the preparation of investigation reports and the formulation and announcement of measures to prevent recurrence.

8. How We Support You

  • Legal advice on the immediate response (evidence preservation, containment, running the response team) and support in coordinating with external specialist vendors
  • Drafting and handling preliminary and final reports to the Personal Information Protection Commission, notifications to data subjects, reports to supervisory authorities and timely disclosure
  • Support in deciding how to respond to ransom demands, dealing with the police, and checking sanctions issues under the Foreign Exchange and Foreign Trade Act and other regimes (for foreign law, coordinating with qualified foreign counsel as needed)
  • Responding to affected individuals and business partners, handling damages claims, and preparing public statements and Q&A materials
  • Civil claims for trade secret infringement, and support for criminal complaints and reports
  • Root-cause analysis and recurrence prevention, and building incident response frameworks for ordinary times (CSIRT, internal rules and training)

FAQ

Q1. We have not yet confirmed whether data was actually leaked. Should we still report?

The reporting obligation arises even at the stage where a reportable leak "may have occurred." That said, an abstract possibility without any supporting indications does not automatically trigger the obligation. While examining the traces of unauthorized access, the data concerned and the state of the logs, a preliminary report should be made without waiting for confirmation once a reportable incident appears likely.

Q2. Are we prohibited from paying the ransom?

There is no general Japanese statute that categorically prohibits payment, but depending on the recipient, the payment route and the parties involved, regulations under the Foreign Exchange and Foreign Trade Act may apply, and where there is a U.S. nexus, OFAC regulations also need to be considered. Payment does not guarantee recovery. Whether to pay is ultimately a management decision weighing business continuity, legal risk and reputation, and it is important to document the deliberations so that the decision can be explained afterwards.

Q3. Is a public announcement always required?

The law does not always require a general public announcement. However, where notification to the affected individuals is difficult for a reportable incident, alternative measures necessary to protect their rights and interests must be taken — publication on your website and setting up an inquiry desk are examples. The appropriate method should be chosen in light of the nature of the incident, the likelihood of the information reaching the affected individuals and the need to prevent secondary harm. The timing and content of any announcement should be designed together with the regulatory reports and the response to affected individuals.

Q4. How are the reporting deadlines counted?

The preliminary report should be made within roughly 3 to 5 days, as a guideline, from the point at which any part of the organization became aware of the reportable incident. The final report is due — counting the day the incident became known as day one, and including weekends and holidays — within 30 days in principle, or within 60 days where the incident may have been caused with a wrongful purpose. If the final-report deadline falls on a weekend, public holiday or the year-end/new-year closure, the deadline moves to the next business day. Because long holidays shorten the number of working days available, an early start is essential.

Prompt and appropriate action is critical both to contain the damage and to meet legal requirements. You are welcome to contact us even at the stage of "we may have been attacked." Please consult us first.

Contact

Contact Us at an Early Stage

Consulting us early helps preserve your options for response.

Contact Form

This article is provided for general informational purposes only and does not constitute legal advice on any specific matter. Please consult us regarding your specific situation. The content is based on the laws and regulations in effect as of the date of the last update.