Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with
Incident Readiness
Characteristics of Cyberattack Risks (v)
Possibility for the occurrence of simultaneous and multiple attacks
In the case of cyberattacks, regardless of the physical distance, attacks can be carried out
simultaneously on targets spreading out across a wide area. Some possible cases include cases
where attacks are carried out simultaneously on multiple business locations of an
organization, cases where attacks are carried out simultaneously on the organization’s system
and supplier’s systems, and cases where attacks are carried out simultaneously on main
systems and emergency systems.
Matters to Be Considered with Regard to Response and Countermeasures
[Basic point of view]
Response to simultaneous and multiple attacks, based on the premise of cooperation with
stakeholders
[Matters to be considered in the formulation and revision of CP and BCP]
In the event where multiple incidents occur simultaneously, it is necessary to assess the
need and order of priority for response based on factors such as the impact on business,
risk tolerance, and resources necessary for response. Hence, clarify the assessment
criteria when formulating the plans.
In preparation for a cyberattack on suppliers or external contractors who is involved in
the provision of CISs, verify the status of preparation of CP and BCP by suppliers and
external contractors, as well as the contents of cooperation with the organization during
response.
Consider the possibility for the occurrence of the same cyberattack on multiple CI
operators. Through the industry organizations, CEPTOAR, and information security
related agencies of each sector, actively share information that contributes to the
prevention of damage in other organizations, such as the means by which one’s own
organization came under a cyberattack, the source of attack, and any characteristic
indicators, and strive to prevent the further occurrence of damage across the entire
sector.
(Countermeasures during normal times, in preparation for the activation of CP and BCP)
Consider measures to reduce the possibility of the main system and emergency system
becoming unavailable at the same time. Examples of such measures include blocking
off communications other than those necessary for the business (such as data copies and
back-ups between the main system and emergency system), and segregation of the
networks of the main system and emergency system.
Based on the assumption of situations in which it becomes difficult to maintain CISs
41