Japan has passed a historic piece of legislation that significantly expands its ability to respond to cyber threats, marking a turning point in its national security strategy. The Active Cyberdefence Law (ACD), enacted by Japan’s parliament on Friday, is designed to bolster the country’s response to an unprecedented surge in cyber attacks targeting its infrastructure, corporations, and government systems.
According to a report by the Financial Times, the new law represents a “pivotal moment” in Tokyo’s shift toward a more assertive cyber posture, after years of hesitation rooted in its pacifist postwar constitution and stringent privacy protections.
“For years, Japan’s cybersecurity strategy has been shackled by legal and cultural limitations,” said a senior government adviser. “But the volume and sophistication of attacks, many state-sponsored, have made inaction untenable.”
The law was spearheaded by the ruling Liberal Democratic Party and first introduced in January. It empowers the National Police Agency (NPA) and Japan’s Self-Defense Forces to actively engage hostile cyber actors, including disabling overseas servers used in attacks. It also mandates critical infrastructure operators to report breaches—something they have historically been reluctant to do due to fears of reputational damage.
Chief Cabinet Secretary Yoshimasa Hayashi emphasized the significance of the law, stating it will help Japan “identify and respond to cyber attacks more quickly and effectively” and bring its capabilities in line with major Western powers.
While the ACD stops short of allowing domestic surveillance, it permits the government to monitor international IP communications that pass through Japanese networks—offering a workaround to Article 21 of the constitution, which protects the secrecy of communications within the country.
The push for reform has been driven by a surge in cyber threats. A recent NPA report revealed record levels of ransomware and phishing attacks, with many targeting Japan’s critical infrastructure. Government officials also disclosed a years-long cyber-espionage campaign dubbed “MirrorFace”, believed to be backed by China and aimed at stealing sensitive national security and technological data.
The Financial Times reports that the law’s passage also reflects Japan’s effort to reduce its reliance on foreign-built cyber tools, particularly from the U.S. and Israel, and develop indigenous solutions tailored to its legal and cultural framework.
“Japan needs cybersecurity built for Japan,” said Toshio Nawa, chief technology officer of Nihon Cyber Defence and former head of air defence command. “Our laws, our threats and our cultural context are different—and our cyber defences must be too.”
The Ministry of Economy, Trade and Industry has warned of a critical shortfall of cybersecurity professionals, estimating the country is lacking 110,000 skilled workers. Closing that gap is now seen as essential to the successful implementation of the ACD and Japan’s broader cyber strategy.
With this new legislation, Tokyo signals a more aggressive and independent approach to digital defence amid escalating geopolitical tensions in the Asia-Pacific region.

