S&P and IBM: 22.4% of global cyberattacks in 2024 hit Japan, the most targeted country, as it tries to improve its legacy IT systems against AI-powered threats
Masayoshi Son isn't known for understatement. So when the SoftBank Group Corp. founder gathered business leaders in Tokyo to warn of the …
Context & Ripple Effects
Japan’s cyber-risk problem has been building in the related coverage: ransomware was already flagged as a potential source of supply-chain disruption, and the 2022 Fujitsu cloud breach exposed how a single provider failure could spread across companies and government agencies.
The response is now becoming infrastructure-led. SoftBank has announced an OpenAI-powered patching service for major infrastructure operators, while Microsoft, SoftBank and Sakura Internet have tied data-center buildout to cybersecurity investment and AI-skills training.
First-order effects
- Japanese companies and operators of critical infrastructure face more urgent pressure to replace or harden legacy systems, patch vulnerabilities faster, and improve incident preparedness against AI-enabled attacks.
- Cybersecurity providers and domestic cloud/data-center partners gain a clearer near-term opening to sell managed protection, patching and modernization services into Japan’s large enterprises.
Second-order effects
- Customers and suppliers connected to Japanese manufacturers may demand stronger security assurances, since disruptions at Japanese technology or cloud providers can propagate through international supply chains.
- The concentration of attacks raises the value of locally available cloud, security operations and skilled practitioners, reinforcing the commercial case for the SoftBank- and Microsoft-linked investment programs.
Third-order effects
- If attacks continue to exploit aging enterprise systems, Japan’s digital modernization will increasingly be governed by cyber resilience rather than by cost or productivity alone, making security a prerequisite for cloud and AI adoption.
- The pattern could deepen reliance on a smaller group of large cloud, telecommunications and managed-security providers; the Fujitsu episode suggests that concentration also makes provider resilience and oversight a systemic concern.
The trend: Japan is moving from reactive remediation of legacy-system breaches toward security-led modernization of the infrastructure underpinning AI and cloud deployment.