惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Cybersecurity and Infrastructure Security Agency CISA
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
量子位
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
小众软件
小众软件
T
Tailwind CSS Blog
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Exploit Database - CXSecurity.com
T
Tenable Blog
博客园 - 叶小钗
宝玉的分享
宝玉的分享
P
Privacy International News Feed
T
Tor Project blog
博客园_首页
AWS News Blog
AWS News Blog
雷峰网
雷峰网
C
Cisco Blogs
Help Net Security
Help Net Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
Last Week in AI
Last Week in AI
K
Kaspersky official blog
人人都是产品经理
人人都是产品经理
Recent Commits to openclaw:main
Recent Commits to openclaw:main
S
Schneier on Security
博客园 - Franky
W
WeLiveSecurity
L
LINUX DO - 热门话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Proofpoint News Feed
大猫的无限游戏
大猫的无限游戏
腾讯CDC
L
Lohrmann on Cybersecurity
J
Java Code Geeks
美团技术团队
博客园 - 司徒正美
The Cloudflare Blog
V
V2EX

Human Risk Management Blog

How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
Anna Collard · 2026-06-10 · via Human Risk Management Blog

Anna Collard, SVP Content Strategy & CISO Advisor, KnowBe4 AfricaAs Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental transformation. Driven by escalating geopolitical tensions and the rapid proliferation of agentic AI, the nation is shifting its focus from purely technical defenses to a broader strategy of "Cognitive Security" and national resilience. The emergence of a hybrid workforce - where human employees work alongside autonomous AI agents - has redefined the traditional enterprise perimeter. From Japan’s Cybersecurity Strategy to the official launch of their AI Cybersecurity Task Force, the country is facing exponential threats online, and has initiated a series of national strategies to address the dangers originating from AI-powered attacks.

The Geopolitical and Regulatory Shift

In 2026, Japan will integrate cybersecurity into its core national defense framework. A key consensus from recent global summits in Tokyo is that cybersecurity now encompasses protecting citizens' cognitive resilience against AI-driven disinformation and warfare.

Key National Initiatives

  • Project Yata Shield: A newly updated framework aiming to secure critical infrastructure through proactive, AI-driven diagnostics.
  • J-AISI (Japan AI Safety Institute): This body emphasizes an agile, human-centric approach to evaluating systemic risks posed by advanced AI models.
  • BOJ/FSA Self-Assessments: Regional banks and financial institutions now utilize the Cybersecurity Self-Assessment (CSSA) tool to benchmark their risk-based approaches against peers.

The Proliferation of Agentic AI: A New Attack Surface

The agentic shift is no longer a future prediction but a current reality. According to Gartner, by the end of 2026, it is predicted that 40% of enterprise applications will feature task-specific AI agents. These agents are not just tools; they act as "first-class identities" with the power to execute multi-step actions, access sensitive data, and interact with connected systems.

The Risks of Shadow AI and Invisible Agents

The speed of AI adoption has outpaced governance controls, creating a significant governance gap. In the recently published research report “From Agentic Risk to Human Wins”, several key statistics were highlighted, namely:

  • Shadow AI: 37% of employees report using "unapproved" AI tools when official options are restrictive.
  • Lack of Oversight: While 58% of organizations have AI agents acting autonomously in workflows, 17% report having limited or no human oversight over these actions.
  • Visibility & Storage: Only 48% of organizations describe their AI use as formally governed, leaving the majority of firms with unclear protocols on where AI-processed data is stored or who has access to it.

Emerging AI-Enabled Threats

Threat Type Impact and Prevalence
Deepfakes 86% of employees believe deepfake content is now so realistic it is impossible to know what to trust.
Prompt Injection Attackers manipulate AI agent inputs to hijack goals or reveal sensitive data.
Cognitive Warfare Sophisticated disinformation campaigns designed to bypass traditional technical filters and exploit human judgment.
Model Poisoning Corrupting an agent's long-term learning to trigger "sleeper" attacks weeks after initial infection.

The Human-AI Digital Workforce: Training and Resilience

The focus of cybersecurity training in Japan is moving beyond simple "phishing awareness" toward "Integrated Resilience". In a hybrid environment, the goal is to synchronize human instinct with machine intelligence.

From Awareness to Behavior

Data from 2026 shows that awareness alone is insufficient. 55% of employees admit they might know the safe action to take but still make mistakes under time pressure or distractions. This gap requires a move toward "Integrated and Culture-Embedded" security, an approach currently adopted by only 19% of global organizations.

Training the "Dual Workforce"

Strategic training now must address both halves of the workforce:

  1. Humans: Upskilling from operators to orchestrators of autonomous systems, with a focus on spotting "hallucinations of intent" in digital communications.
  2. AI Agents: Implementing Agent Risk Management to govern agent behaviors and automatically adjust permissions based on real-time human risk scores.

Case Study: Shifting Japan's "Disciplinary Culture"

A landmark 2026 research report highlighted a unique challenge in the Japanese market: a pervasive shame culture at the root of security management. Chambers and Partners provided a report on Cybersecurity Trends and Regulatory Enforcement in Japan in 2025, highlighting some key aspects such as training as a key component to address cyber incidents.

The Challenge:

In early 2026, nearly half of all accidental security errors in Japanese firms resulted in formal disciplinary action. This blame culture often led to employees hiding mistakes rather than reporting them, significantly increasing detection times for breaches.

The Strategic Pivot:

Major Japanese organizations, including entities like SMBC and Toyota, have begun referencing human-centric frameworks to shift the narrative. By framing security as a Japanese organizational culture and HR issue rather than just a technical one, firms saw a rise in engagement.

Results:

  • Shift to Coaching: Organizations that moved toward supportive, coaching-led approaches (e.g., learning-led phishing simulations) reported that 91% of employees felt safer reporting mistakes.
  • Media Resonance: High-quality coverage in publications like Nikkei and Toyo Keizai helped socialize the idea that a culture of learning from mistakes - rather than punishment - is what drives true organizational resilience.

Looking Ahead: 2027 and Beyond

As Japan moves toward 2027, the focus remains on "Human Wins" - transitioning from tracking failures to reinforcing positive defensive actions. The digital workforce of the future will be defined by its ability to act as a single, interconnected layer of defense where human intuition and AI-driven telemetry act as a unified immune system.

Key Action for 2026:

Executives must establish identity and entitlement controls for AI agents that are as rigorous as those for human employees, ensuring that digital workforce security becomes a board-level priority.