Cybersecurity exercises + drills are mandated per FSA Cybersecurity Guidelines for Tier 2/3 institutions + coordinated industry-wide via Delta Wall + FISC. (1) Institutional Tabletop Exercises: (a) Annual minimum per FSA expectation; (b) Quarterly for Tier 3 + critical infrastructure; (c) Cross-functional - technical + business + legal + comms + executive + Board; (d) Realistic scenarios with current threat landscape; (e) Decision-making under pressure + ambiguity; (f) After Action Review + improvement actions tracked; (g) Annual Board observation. (2) Scenario Diversity: (a) Ransomware - encryption + extortion + double/triple extortion; (b) Wire Transfer Fraud - BEC + insider + APT; (c) Customer Account Takeover; (d) DDoS attack on customer-facing; (e) Insider Threat - malicious + negligent; (f) Supply Chain Attack (SolarWinds-style); (g) Critical Service Provider Outage; (h) ATM/Card Network Attack; (i) Trading System Compromise; (j) Customer Data Breach; (k) Generative AI Manipulation; (l) Geopolitical Cyber Attack (nation-state); (m) Multi-vector Coordinated Attack. (3) Delta Wall (Saiba Sekyuritii Engan Bouei Enshu サイバーセキュリティ沿岸防衛演習) - FSA-Coordinated Industry-Wide Exercise: (a) Annual industry-wide cybersecurity exercise; (b) FSA + FISC + JFSA + sector industry associations coordination; (c) Banking + Insurance + Securities sectors participation; (d) Realistic threat scenarios; (e) Cross-institution dependencies tested; (f) Communications protocols exercised; (g) FSA observation + sector lessons learned; (h) Public reporting (anonymised). (4) FISC Industry Drills: (a) FISC-coordinated sector exercises; (b) Banking-specific scenarios; (c) Payment infrastructure (Zengin + BOJ-Net); (d) Cross-bank coordination; (e) Recovery testing; (f) Industry maturity benchmarking. (5) Cyber Range Exercises: (a) Dedicated cyber range facilities; (b) Realistic enterprise environment simulation; (c) Hands-on technical exercises; (d) Red team / Blue team / Purple team format; (e) Detection + Response capability validation; (f) Tier 3 + critical infrastructure investment; (g) Industry-shared cyber range emerging. (6) International Coordination Exercises: (a) G7 Cyber Expert Group exercises; (b) US-Japan bilateral cyber exercises; (c) UK-Japan + EU-Japan bilateral; (d) FSB Cross-Border Crisis Management Group exercises; (e) BIS Bank for International Settlements innovation; (f) APAC regional exercises. (7) Cross-Sector Crisis Coordination: (a) NISC National Center coordinated exercises; (b) Critical Infrastructure Information Sharing; (c) Cross-sector dependencies (telecom + power + transportation + financial); (d) Government coordinated crisis exercise; (e) Tokyo 2025 World Expo cybersecurity coordination (during preparation); (f) Pandemic + Olympic-style mass event coordination. (8) Exercise Methodology: (a) Tabletop Discussion-Based (lowest fidelity); (b) Walk-Through with documentation review; (c) Functional Exercise (some live actions); (d) Full-Scale (live response with limited disruption); (e) Live Fire (production environment - rare); (f) Adversarial Emulation (Red Team during exercise); (g) Plausible Deniability scenarios (insider threat). (9) Post-Exercise Activities: (a) After Action Review (AAR) - blameless + facts-focused; (b) Lessons Learned documentation; (c) Improvement Action items + tracking; (d) Plan + procedure update; (e) Training needs identification; (f) Tooling + capability investment; (g) FSA reporting on exercise outcomes; (h) Industry sharing (where appropriate). (10) Exercise KPIs: (a) Participation rate + cross-functional; (b) Decision quality under pressure; (c) Communication effectiveness; (d) RTO/RPO meeting; (e) Improvement actions completed; (f) Year-over-year maturity progression; (g) Industry comparison via Delta Wall benchmarking. (11) Generative AI Exercise Themes (2024+): (a) AI-powered phishing + deepfake voice/video impersonation of executives; (b) Generative AI-assisted prompt injection on customer-facing AI; (c) AI hallucination causing customer harm; (d) AI model extraction or poisoning; (e) Regulatory inquiry on AI-driven decision. (12) Quantum Computing Exercise Themes (Emerging): (a) Post-quantum migration planning exercise; (b) Cryptographic algorithm sunset; (c) Harvest Now Decrypt Later (HNDL) scenario; (d) Q-Day preparation. Coordinates with FSA + FISC + JFSA + Japan Bankers Association + Japan Life Insurance Association + Japan Securities Dealers Association + NISC + JPCERT/CC + Bank of Japan + Zengin Network + Japan Cybercrime Division + G7 Cyber Expert Group + FSB Cross-Border Crisis Management + BIS + CPMI-IOSCO + sector ISACs + FS-ISAC Japan + Bilateral arrangements (US OCC + UK FCA + EBA + ECB). Japan FSA Cybersecurity Exercises + Drills applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.