IPA Releases 2026 Information Security White Paper PDF
Overview
The Information-technology Promotion Agency (IPA), an independent administrative institution, released the PDF edition of “Information Security White Paper 2026: A New Era of Cyber Defense—Prepare for Double-Edged Advances” on September 30, 2026, ahead of the print edition. The white paper covers cyber threats, policies, and support measures. The 2026 edition addresses cyber security, AI safety, supply chain threats, and systems for countermeasures. The print edition is scheduled for publication on October 19.
Key points
- IPA released the 2026 white paper PDF. The print edition is scheduled for publication on October 19.
- The white paper explains the status of frameworks for cyber security legislation and public-private cooperation.
- It covers AI safety, responses to malicious AI use, supply chain threats, and countermeasure systems.
Overview
The Information-technology Promotion Agency (IPA), an independent administrative institution headed by Yutaka Saito, released the PDF edition of “Information Security White Paper 2026: A New Era of Cyber Defense—Prepare for Double-Edged Advances” on September 30, 2026, ahead of the print edition. The print edition is scheduled for publication on October 19, 2026.
The “Information Security White Paper” has been published annually since 2008. It covers incidents and damage, threat trends, notable events, domestic and international policies and systems, survey reports, and support measures for security-related organizations.
Impact
IPA expects the white paper to be used in putting security measures into practice, internal training, learning, and business, and to help improve the public’s cyber security literacy and contribute to a safe and secure society.
Details
Section 1 of Chapter 2, “Status of Cyber Security-Related Measures,” covers the Cyber Response Capability Enhancement Act and its related legislation, enacted and promulgated in May 2025 following recommendations made in November 2024. It states that progress has been made in strengthening public-private cooperation, using communications information, and developing the environment and framework for neutralizing attack servers.
Section 2 of Chapter 2, “Initiatives to Ensure AI Safety,” covers the AI policy in the Cybersecurity Strategy, adopted by Cabinet decision in December 2025. The policy is organized around three perspectives: ensuring AI safety, responding to attacks that misuse AI, and using AI to ensure cyber security. Project YATA-Shield was developed following Anthropic’s announcement of a general-purpose AI model in April 2026.
Chapter 1 and Section 1 of Chapter 3 explain that ransomware and targeted attacks, made more sophisticated in part through AI misuse, have harmed broad supply chains, renewing recognition of the importance of business continuity. To raise the level of security measures at small and medium-sized enterprises, systems were developed for the Supply Chain Security Assessment System (SCS Assessment System) and the Cybersecurity Otasuketai Service (new type).