JFSA publishes IT Resilience Report amid rising cyber and third-party risks
JFSA published its Analytical Report on IT Resilience in the Financial Sector, addressing geopolitical, cyber, and third-party risks.
The JFSA's updated resilience report signals heightened supervisory focus on operational continuity, cyber defences, and third-party dependencies. Financial institutions operating in Japan should expect increased scrutiny of system failure root causes and remediation practices.
Signals JFSA's continued elevation of operational resilience as a supervisory priority, aligning Japan with global trends.
Action Required
Benchmark IT resilience frameworks against JFSA findings and reassess third-party and cyber risk controls.
IT resilience is a systemic priority; JFSA reports typically inform supervisory expectations and inspection focus areas.
Operational resilience risk elevated. Review IT failure incident history, third-party concentration, and cyber controls against JFSA's 2026 findings; update RCSA controls and remediation plans.
“Since 2019, the Financial Services Agency (FSA) has continuously published analytical reports on system failures occurring at financial institutions. In June 2025, the FSA reorganized the report as the Analytical Report on IT Resilience in the Financial Sector, taking into account growing geopolitical, cyber, and third-party risks.”