News
- Press Release
Cybersecurity Cloud announces its policy to support vulnerability management and multi-layered defense in the Frontier AI era – focusing on virtual patching with Cloud-based WAF to support the rapidly increasing number of vulnerabilities.
Cyber Security Cloud, Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Toshihiro Koike; hereinafter referred to as "the Company"), a global security manufacturer, has announced that, in response to the "Request Regarding Short-Term Responses by Financial Institutions, etc., in Light of Threat Changes Caused by Frontier AI" (*1) published by the Financial Services Agency and the Bank of Japan on May 22, 2026, the structural challenges indicated in this request are not limited to financial institutions but are common to businesses in all industries. Recognizing this, the Company and its group companies will fully support customers in their short-term responses, regardless of industry, through vulnerability management services, technical resources, and WAF (Web Application Firewall) product suites provided by the Company and its group companies.

■ Summary of requests from the Financial Services Agency and the Bank of Japan
The Financial Services Agency and the Bank of Japan have pointed out that with the development of advanced, cutting-edge general-purpose AI models with high capabilities, so-called "frontier AI," the time from vulnerability discovery to attack will be significantly shortened, and a large number of vulnerabilities and patches may be provided in a short period of time. In response, financial institutions and other organizations have been requested to establish systems that enable them to respond quickly and appropriately to asset management, vulnerability management, patch application, monitoring, and resilience, with the direct involvement of top management and other senior executives.
Of the short-term responses outlined in the request, the following areas form the core of the technical response:
- Identifying services/IT systems that require priority attention and resolving technical debt (Requests ② and ③)
- Additional human resources for patch application (Request ④)
- Risk-based approach to the patch application process (Request ⑥)
- Strengthening multi-layered defense using virtual patches (WAF) etc. when patch application is difficult (Request 7)
■ The same structural challenges common to industries other than financial institutions
While this request is addressed to financial institutions and similar organizations, the underlying issue of "the proliferation of vulnerabilities and the acceleration of attacks due to Frontier AI" is affecting all businesses operating web systems, regardless of industry.
In fact, in the attack traffic we observe daily in our customers' environments, the lead time to the exploitation of new vulnerabilities is continuously shortening across all industries.
The requests from the Financial Services Agency and the Bank of Japan can be seen as a pioneering example of how these "cross-industry structural challenges" have been promptly articulated as a regulatory message to the financial sector. For businesses in other industries as well, the four technical response areas outlined in these requests (asset identification, human resources, risk-based management, and virtual patching) can serve as a checklist for their own short-term response plans.
■ A practical solution for "buying time" using virtual patching (WAF)
Regardless of the industry, the biggest constraint on the ground during short-term response periods is the time required to fundamentally resolve vulnerabilities. Asset inventory, impact assessment, patch application testing in a verification environment, and maintenance adjustments for deployment to production all involve structural lead times that cannot be shortened by the efforts of on-site personnel alone.
On the other hand, advancements in AI are continuously shortening the time between vulnerability disclosure and the occurrence of attacks. Attacks continue to reach targets even while a fundamental fix is being sought.
The reason why the Financial Services Agency and the Bank of Japan's request (⑦) specifically mentions virtual patching is that, at present, there is no other realistic means to bridge this structural gap than multi-layered defense using virtual patching. Cloud-based WAF play the role of "buying time" by blocking attacks before the root cause of the vulnerability can be resolved, allowing the field staff to calmly proceed with the fundamental response.
Our company has established a system that enables the provision of virtual patches to both on-premises and cloud environments using Shadankun and WafCharm.
■ Our Group's Response Policy
As a cybersecurity specialist manufacturer with a wealth of experience, including our Cloud-based WAF "Shadankun" which holds the No. 1 market share in Japan (*2), we will fully support the areas indicated in this request with our group's product and service suite, regardless of industry or environment.
Specifically, we leverage our ability to provide end-to-end solutions for "vulnerability management," "additional human resources," and "virtual patching (WAF)" in both on-premises and cloud environments, enabling us to support a wide range of customers, including financial institutions and those in other industries, with their short-term response needs.
■ Coverage provided by group products and services
In response to requests from the Financial Services Agency and the Bank of Japan regarding "vulnerability management," "securing human resources," and "multi-layered defense through virtual patching," our group provides the following product and service suites in both on-premises and cloud environments.
- Vulnerability management (corresponding to requests ②, ③, and ⑥)
[On-Premise Environment] SIDfm (https://sid-fm.com/)
[Cloud Environment] CloudFastener (https://cloud-fastener.com/) - Additional human resources (corresponding to request ④)
[On-Premise Environment] Generative Technology Co., Ltd. (https://gen-tech.co.jp/)
[Cloud Environment] CloudFastener (https://cloud-fastener.com/) - Virtual patch/WAF (corresponding to request ⑦)
[On-Premise Environment] Shadankun (https://www.shadan-kun.com/)
[Cloud Environment] WafCharm (https://www.wafcharm.com/jp/)
◇ Vulnerability Management Solution
Vulnerability information collection and management tool "SIDfm "
SIDfm, a vulnerability information collection and management tool, streamlines vulnerability response operations. It automatically collects and stores vulnerability information for operating systems, applications, and network products from around the world. Its ability to quickly identify only the information necessary for your company allows you to see at a glance which vulnerabilities need to be addressed and what countermeasures are required. Furthermore, it allows you to record and manage the progress of vulnerability remediation.
CloudFastener
CloudFastener, a fully managed security service compatible with AWS, Azure, and Google Cloud, leverages cloud-native security services to provide comprehensive management of your cloud environment resources and alerts, along with customized support from security experts. CloudFastener flexibly provides support for threat detection, vulnerability management, data protection, audit trails, and compliance, tailored to your environment configuration and organizational structure. It offers comprehensive, one-stop support for the entire cloud security operation, from governance policy development to recovery and remediation. Furthermore, CloudFastener employs a model where a team of highly specialized knowledge and experience provides in-house support. This allows companies and organizations without a dedicated security team to quickly and effectively implement security measures in their cloud environment.
◇ Human Resource Addition Solution
Generative Technology Co., Ltd. (Our group company)
We are a group company that provides technical staffing and contract development services in the IT infrastructure and security fields. In the face of the increasing number of vulnerabilities caused by Frontier AI, we will flexibly assign technical staff to complement our customers' existing operational systems. We provide human support across the group that is directly related to on-site operations, from building verification environments and applying patches to confirming operation after application.
◇ Virtual Patching/WAF Solution
Cloud-based WAF "Shadankun "
Cloud-based WAF "Shadankun" is a cloud-based web security service that protects web servers and websites by detecting and blocking external cyberattacks that could cause information leaks or service disruptions. Based on the analysis of trillions of records of big data, its unique high-precision detection rules prevent a wide variety of cyberattacks in real time. Furthermore, its security engineers quickly update defense signatures to address the latest vulnerabilities, and in the unlikely event of a false positive, technical support provides flexible assistance to support safe and stable site operation.
WAF automated operation service "WafCharm "
WafCharm is an automated WAF (Web Application Firewall) management service that allows you to automatically manage WAFs provided on public clouds. It supports AWS, Azure, and Google Cloud. The biggest advantage of WafCharm is that it automates complex and important WAF management tasks. With a wealth of features such as automatic rule application and automatic addition of IP block lists, you can leave tasks such as creating and updating WAF rules and adding IP block lists to WafCharm, eliminating the need for manual work.
■On-site support under the involvement of management
This request emphasizes the essential role of direct involvement from management, including CIOs and CISOs, but this is not limited to financial institutions. In an era where cyber risk is a direct business matter, collaboration between frontline staff and management is an urgent issue across all industries.
Our company supports both on-site operations and management decision-making by providing explanatory materials for management, prioritizing responses in emergencies, and offering 24/7 Japanese language support, enabling on-site personnel to smoothly report to and get approvals from management.
*1: Regarding the request for "Short-term responses by financial institutions, etc., in light of the changing threats posed by Frontier AI"
*2: Source: Deloitte Tohmatsu MIC Research Institute, "Current Status and Future Outlook of the External Threat Countermeasure Solutions Market, FY2025"
Cyber Security Cloud, Inc. (https://www.cscloud.co.jp)
Address: JR Tokyu Meguro Building 13th Floor, 3-1-1 Kami-Osaki, Shinagawa-ku, Tokyo 141-0021
Representative: Toshihiro Koike Representative Director, President and CEO
Established: August 2010
With the mission of "creating a safe and secure cyberspace for people all over the world," we are a Japanese security manufacturer that provides web application security services utilizing world-leading cyber threat intelligence, as well as vulnerability information collection and management tools and fully managed security services for cloud environments. As one of the global companies in cybersecurity, we will contribute to solving social issues related to cybersecurity and providing added value to society.