On the 7th, Japan's Financial Services Agency (FSA) announced a proposal to standardize the reporting format for cyber attack damages affecting financial institutions, including cryptocurrency exchanges.
The proposed revisions to the "Comprehensive Supervision Guidelines for Major Banks" and others fundamentally review the reporting procedures for system failures and cybersecurity incidents.
Previously, financial institutions reported cyber attacks using a unique format established by the FSA. With this revision, the reporting format will transition to a common format used across government agencies, aligning with the broader initiative to standardize reporting formats for cyber attack damages.
In recent years, the number of cyber attacks has been on the rise, and reporting to multiple ministries has become a burden for businesses. This initiative aims to reduce the reporting burden on affected organizations and expedite government responses.
The scope of this initiative is not limited to traditional financial institutions such as banks, insurance companies, and securities firms. It also broadly includes cryptocurrency exchanges, money transfer businesses, and electronic payment service providers.
With this revision, cryptocurrency exchanges will also report incidents of system failures or hacking using the same common format as other financial institutions to the FSA.
This aligns the cryptocurrency business with mainstream financial regulations, necessitating a consistent response across the entire financial sector.
The new reporting format is clearly categorized into three types based on the nature of the incident.
Specifically, there are the "Common Format for DDoS Attack Incidents," the "Common Format for Ransomware Incidents," and a newly established "Common Format for Other Cyber Attack Incidents."
When a financial institution recognizes an incident, it must immediately report the facts to the FSA and submit a detailed report using the applicable format.
Additionally, the common format for ransomware incidents can also be used as a report concerning personal data breaches.
This harmonizes regulations for cybersecurity and personal data protection, consolidating multiple reporting obligations to reduce practical burdens.
On the other hand, flexible transitional measures are also in place for the system's transition. Businesses not designated as "Specific Social Infrastructure Providers" under the Economic Security Promotion Act can continue to use the existing reporting format until the end of March 2027.
The new system will be prioritized for businesses that are critical social infrastructure providers, aiming for a phased transition.
The FSA is currently soliciting public comments on this proposal until September 7. Based on the feedback received, the final system design is expected to be developed.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

























Join the WEEX ADA Airdrop and learn how to complete deposit, spot trading, referral, and futures tasks to share 50,000 USDT rewards.




