Financial Services Agency
Director for IT Risk, Cybersecurity and Economic Security
Akie Makino
| 9:00-9:30 | Registration&Preparing for live streaming |
| 9:30-10:00 | Keynote Speech 1 Strengthening Cybersecurity in the Financial Sector ![]() Financial Services Agency Director for IT Risk, Cybersecurity and Economic Security Akie Makino In recent years, cyberattacks have become increasingly sophisticated and complex, and the threat landscape facing financial institutions has changed significantly. Furthermore, there is a growing need to prepare for new challenges, such as the sophistication of attack methods driven by advances in frontier AI and the need to address post-quantum cryptography (PQC) in anticipation of the practical application of quantum computers. In light of these environmental changes, this article introduces the Financial Services Agency’s cybersecurity measures and future initiatives aimed at ensuring the stability of the financial system. |
| 10:05-10:35 | S-1 Continuous Visibility into the Cyber Landscape Surrounding Financial Institutions ITOCHU Techno-Solutions Corporation Senior Specialist Seiji Nagoya As frontier AI advances and digitalization expands, the risks facing financial institutions can no longer be captured by internal assessment alone. |
| 10:40-11:10 | S-2 Vulnerability Response in the Frontier AI Era: Risk-Based Prioritization with Splunk Splunk Japan Solutions Engineer Yuhi Koegaitsu Frontier AI has significantly reduced the time from vulnerability discovery to exploitation. However, on the ground, teams are often unable to immediately determine which of their systems are affected by a given vulnerability or which ones to address first. This is because asset information is scattered across various sources, and cross-referencing relies on manual processes. In this presentation, we will introduce an approach that uses Splunk to perform cross-platform analysis of vulnerability data, asset information, and logs, and derives risk-based priorities by taking into account actual exploitation history and the public exposure status of assets. |
| 11:15-11:45 | S-3 Vulnerability Management in the Age of Frontier AI: Patch Management and Privileged Identity Management ZOHO Japan Corporation Leader / Evangelist Shun Horiuchi The May 2026 joint request from Japan's Financial Services Agency and the Bank of Japan calls for resolving technical debt—through patch application and removal of privileged IDs—in light of the shifting threat landscape driven by frontier AI. The July IT resilience analysis report warns that conventional patch management approaches may be insufficient, underscoring the need for a mid- to long-term shift toward automation. This session introduces ManageEngine's approach to automating patch distribution and managing privileged identities based on the principles of least privilege and separation of duties. |
| 11:50-12:20 | S-4 The Reality of Data Loss and Practical Strategies for Prevention – How to Prevent Insider Threats That Occur Four Times More Often Than Cyberattacks – Proofpoint Japan K.K. Chief Security Evangelist Japan / Sr. Director, Japan Yukimi Sohta Did you know that in Japan, data loss caused by insider threats is more prevalent than data breaches resulting from cyberattacks? As workforce mobility continues to increase, the unauthorized removal of sensitive information by departing employees has become a growing business risk. In this session, we will examine the latest trends and real-world examples, explore the current insider threat landscape through data-driven insights, and share practical strategies for preventing data loss by focusing on human behavior and risk. |
| 12:20-13:00 | Lunch (Standing Buffet) |
| 13:00-13:40 | Panel Discussion Global Economic/Geopolitical Development and Implication for the Financial Sector <Facilitator> ![]() Deloitte Tohmatsu LLC Managing Director Shiro Katsufuji <Panelist> ![]() JPMorgan Securities Japan Co. Ltd. Managing Director Ayako Fujita ![]() General Incorporated Association Japan Risk Forum Representative Director Atsuhito Sakai How should we identify the global economy and geopolitical risks in the midst of changes, and how should financial institutions take them as opportunities and control risks? |
| 13:45-14:15 | S-5 Threat Intelligence for Financial Institutions: Insights from 2026 Threat Cases Kaspersky Labs Japan Enterprise Solution Expert Takehiro Ito Based on the latest threat cases observed in 2026, this session explores how hacktivist activities are evolving beyond purely political motivations and how crimeware targeting the financial sector is becoming more sophisticated. We will also highlight the value of threat intelligence in understanding attackers’ motives, targets, TTPs, and infrastructure from a financial-sector perspective. |
| 14:20-14:50 | S-6 Third-Party Risk Management: Practical Challenges and Approaches KPMG Consulting Co., Ltd. Financial Services - Solution Kazuyoshi Horiba KPMG Consulting Co., Ltd. Financial Services - Solution Kyoka Kawai With third-party cyber risk on the rise, efforts to enhance risk management are gaining momentum. Addressing the increasingly complex risks embedded in the supply chain requires putting in place appropriate management arrangements. This session examines key regulatory developments in Japan and globally, highlights the practical challenges confronting financial institutions. It then discusses how effective risk assessment can be approached and tools deployed to sustain robust risk management with limited resources. |
| 14:55-15:35 | Keynote Speech 2 JCB's Initiatives Toward Effective Cybersecurity Management (TBD) ![]() JCB Co.,Ltd. Vice President System Planning Department Masahiro Hirano The threat posed by cyberattacks is growing year by year, and the rapid recent advancements in generative AI, in particular, are not only increasing attackers’ productivity but also forcing a transformation in how we view the assets we must protect, as well as our approaches to risk management and security measures. In this presentation, we will discuss how to enhance the effectiveness of risk management in light of these changes in the external environment, drawing on our company’s initiatives. |
| 15:35-15:55 | Coffee Break |
| 15:55-16:25 | S-7 KELA Group Solutions for Financial Institutions KELA Co., Ltd Enterprise Sales Division 3 Senior Sales Manager Akira Nakashima The KELA Group offers a portfolio consisting of KELA, which provides dark web monitoring; ULTRARED, which supports ASM/CTEM; and SLING, which supports ASM/TPRM. |
| 16:30-17:00 | S-8 Cyberattacks Know No Borders: Determining Defense Priorities Through Cross-Border Data in Japan, South Korea, and Taiwan S2W K.K. Country Manager Heita Miyoshi The same threat groups are striking Japan and Taiwan—or South Korea and Taiwan—sequentially within days. In the first nine months of 2026, 13 such incidents were observed. We can no longer ignore actors who do not seem to target us directly. While monitoring scope expands, defense resources do not. This makes prioritization critical. In this session, we will leverage real dark web data from these three markets to reveal the reality of cross-border attacks and how Japanese financial institutions are perceived from the outside. |
| 17:10-17:50 | Fireside Chat How Should We Understand and Address the Cybersecurity and Supply Chain Risks Posed by Emerging Technologies? ![]() Financial Services Agency Banking and Securities Business Supervision Bureau Director of the Banking Business Division Ⅱ Yoshichika Imaizumi ![]() Armoris Executive Director / CTO Keisuke Kamata Advances in emerging technologies such as AI, quantum computing, and stablecoins expand the possibilities for financial services, but also create new cyber and supply chain risks affecting organizations of all sizes. This session will explore how financial institutions can identify evolving threats early and rapidly implement appropriate organization-wide measures. It will also examine how effective communication between management and frontline teams can help institutions navigate challenges for which there is no definitive endpoint, especially as the pace of technological change continues to accelerate. |
| 17:50-18:50 | Networking Cocktail |