IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
As Japan widens bank cyber oversight to data partners, identity becomes the perimeter

As Japan widens bank cyber oversight to data partners, identity becomes the perimeter

Mon, 7th Sep 2026 (Today)
Takanori Nishiyama
TAKANORI NISHIYAMA Senior Vice President, APAC Sales and Japan Country Manager Keeper Security

Financial regulators in the United States, the European Union and the United Kingdom have expanded the scope of third-party risk that banks must manage, and Japan is now following that model. Japan's Financial Services Agency expects institutions to look past the vendors they directly contract with and to account for the wider network of partners connected to their systems, including fintech and telecommunications companies that exchange data without a formal outsourcing agreement. Japanese banks stopped building everything in-house years ago, and the partner ecosystems that now power their services have steadily multiplied the number of external connections a security team must account for.

That shift reflects a reality: Advanced AI models help cybercriminals find and exploit software weaknesses, shrinking the window for defense from months to minutes, and every data connection becomes a potential entry point. Japan's National Police Agency recorded 4,677 cases of fraudulent transfers involving internet banking in 2025, with losses of approximately 10.2 billion yen, both record highs, and phishing remains the dominant method for stealing the credentials behind those transfers.

Japanese financial institutions should treat every connected identity, human and non-human alike, as part of their attack surface. The first step is a comprehensive inventory of every data-linked partner, weighted by the consequences a disruption at each would carry. Security expectations should then be written into contracts as enforceable obligations, including encryption baselines and the right to audit and inspect. Within those relationships, institutions should apply least-privilege access to each connection and remove standing privilege in favor of just-in-time access that expires when a task ends. Multi-factor authentication and privileged access management belong at every point where credentials or tokens grant entry, including the AI agents now operating inside banking systems. 

Trust has always been the foundation of Japanese banking, built over decades of reliability and precision. That trust now runs through every fintech integration, API connection and AI agent operating inside the institution. Customers will not distinguish between a breach at a bank and a breach at one of its partners, and neither will regulators. Extending the same rigor that built that reputation to every connected identity is how institutions preserve it.