Financial Services Agency Unifies Cyber Reporting Formats Across 17 Areas
Key Points of This Article
- Introduction of a new format called "Common Format for Other Cyber Attacks and Incidents"
- Transitional measures will be in place until the end of March 2027; businesses not covered can continue using the old format
Unification of Cyber Reporting Formats Across 17 Areas
On August 7, the Financial Services Agency (FSA) announced a partial amendment proposal to the "Comprehensive Supervisory Guidelines for Major Banks and Others." The proposal aims to unify the reporting formats that businesses must submit to authorities in the event of computer system failures or cybersecurity incidents into a common format based on agreements among relevant ministries. This applies to 17 areas, including administrative guidelines for cryptocurrency exchange operators.
The background for the amendment is the revision of the "Agreement on Reporting Procedures in the Event of Damage from Cyber Attacks" (Agreement among relevant ministries on May 28, 2025). Previously, only DDoS attack incidents and ransomware incidents could be reported using a common format, but a new format is expected to be established for other types of incidents as well.
Organization of Reporting Formats into Three Categories
The amendment proposal organizes the reporting categories from businesses into three types. DDoS attack incidents will be reported using the DDoS Attack Incident Common Format, while ransomware incidents will be reported using the Ransomware Incident Common Format. Incidents that do not fall into either category will be reported using the newly established "Common Format for Other Cyber Attacks and Incidents."
In the administrative guidelines related to cryptocurrency exchange operators, the reporting procedures for incidents such as system failures will be rewritten according to these three categories. The practice of the financial bureau contacting the relevant department of the FSA immediately upon receiving reports from cryptocurrency exchange operators will remain unchanged.
Transitional Measures and Public Comment Period
Transitional measures have also been established. Until the end of March 2027, businesses designated as specific social infrastructure operators under the Economic Security Promotion Act will be allowed to report using the old "Incident Report" format, except for those designated operators. Designated operators are expected to adapt to the new common format after the amendment.
The public comment period will be open until September 7, 2026, at 17:00. After the public comment period ends, the necessary procedures will be followed, and the amendments to the supervisory guidelines are expected to be applied. Target businesses, including cryptocurrency exchange operators, will need to prepare for practical responses based on the forthcoming official decisions.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Fed's Hawkish Signals Strengthen, September CPI Becomes Key for Rate Hike

Xinxing Electronics Under Investigation for Mislabeling Chinese Parts

Kalshi Becomes Official Prediction Market Platform for the US Open

Interest Rate Raised to 3.00%, Driven by Semiconductor Boom

On-chain Insurance Decreases by 20.2%, Hacking Losses Increase by $3.63 Billion

Changxin LPDDR6 Mass Production, Peak Rate 12800Mbps, Maximum Capacity 16GB

Federal Reserve Sets Target Range of 3.50-3.75% for 2025 After Three Rate Cuts

July PCE at 3.7%, Exceeding Fed's Target for 65 Months

Lido Expands Ethereum Staking Credibility with Web3SOC Certification

President of the Polish Olympic Committee Arrested in Zondacrypto Case, Faces Charges

Brave Launches Brave Accounts with OPAQUE Protocol for Password Security

Ukraine and Romania Agree on Measures to Accelerate Shipping through the Sulina Canal

The Audit Chamber Reveals UAH 350 Billion Discrepancies in Defense Procurement

Sayful App for macOS with AI Dictation and Automatic Layout Switching

KNDS Relaunches Its IPO for September

Resident Foreign Currency Deposits Reach Record High of $128.34 Billion in July

Ethereum Account Abstraction Proposal EIP-8141 Included in Hegotá Upgrade

Dunamu Partners with Visa for Stablecoin Payment Collaboration

NVIDIA AI Chip Demand Accelerates, Customer Profitability Becomes Key

Every Second Russian Bank Recorded Outflow of Deposits

Bank of Korea Raises Core Inflation Forecast to 2.5%

Pyth Network API overhaul risks freezing 300 DeFi protocols

CLAN Market Cap on Robinhood Exceeds $3.52 Million

World ID Integrates Human Verification Technology with PeakOS

Bitcoin: US GDP Revives Hopes for Fed Rate Cuts

eToro Launches Happening to Summarize Company Results

State Tax Service Introduces Updated Concept of Electronic Cabinet for Individual Entrepreneurs

Citi Projects Record Global Equity and Debt Financing for South Korean Companies by 2026

B.AI API Compatible with Codex Supports Calling GPT Series Models








