The Basics of Incident Response and Cybersecurity Measures: Lessons learned from the Asahi Group Ransomware Attack
The recent ransomware attack on Asahi Group Holdings Ltd (Asahi GHD) sent shockwaves through Japan’s business community. Highlighting just how disruptive and far-reaching modern cyber threats have become, the incident not only caused major operational shutdowns and financial losses for a leading enterprise, but also exposed the growing risks posed by sophisticated cybercrime groups.
In this insight, we draw lessons from the Asahi GHD attack, including:
・Why robust incident response and proactive cybersecurity frameworks are now essential for every organization
・How ransomware tactics are evolving
・The critical steps required for effective incident management, and
・The legal and strategic considerations that must guide a company’s response.
Reach out to our team if you need more information or guidance.
What happened to Asahi GHD? A timeline

Ransomware attacks of this kind pose a significant threat to enterprises. It is an urgent priority for companies to understand the response processes to be followed when cybersecurity incidents (such as ransomware attacks) occur and to establish internal frameworks that provide for robust cybersecurity measures.
How ransomware attacks have evolved: From broad attacks to targeted extortion
‘Ransomware’ refers to a type of malicious software that renders data on endpoints or servers unusable - typically by encrypting it - and then displays a coercive message demanding ransom payment in exchange for restoration.
Historically, ransomware campaigns often lacked a specific target. Attackers would conduct broad-based email campaigns with malicious attachments, seeking to infect as many systems as possible and extract ransom payments from the unlucky victim. If a system became infected and the victim chose to pay, they would receive a decryption key.
Today, in addition to such traditional campaigns, attackers increasingly select specific companies or organisations as targets and engage in ‘double extortion’ before encrypting systems. They exfiltrate data and then threaten not only to withhold decryption keys unless paid, but to also publish the stolen data if payment is not made. This method creates intense business continuity pressure and has resulted in more reliable and larger ransom payments.
In recent years, cyberattacks have also become commoditised. Under ‘Ransomware as a Service’ (RaaS), cybercrime groups provide would-be attackers with ransomware and related infrastructure - such as leak sites for publishing stolen information - in exchange for receiving a share of any ransom collected by the affiliates who carry out the attacks. RaaS lowers the barrier to entry for cybercrime, making such attacks a material and persistent risk for enterprises. The group calling itself ‘Qilin’, which claimed responsibility for the attack on Asahi GHD, is a cybercrime group widely regarded as an RaaS operation.
Beyond data loss, towards operational disruption and reputation damage
The attack on Asahi GHD illustrates that the impact of modern ransomware extends beyond the leakage of confidential information and trade secrets; it also poses a risk to entire business operations that can undermine a business’ reputation in the market.
As a result of the ransomware attack, Asahi GHD was forced not only to address information leakage but also to suspend order and shipping operations at its domestic group companies, as well as call-center operations such as customer service. More than one month has passed since the initial announcement, yet full restoration still seems to be a long way off (as of November 5, 2025). According to media reports, if the disruption continues, Asahi GHD’s losses. These losses also don’t account for the less quantifiable reputational impacts for Asahi GHD, with the significant disruptions across its business potentially eroding trust among its customers and business partners.
Security incident response
As noted above, ransomware attacks can cause severe harm. Each company should have a carefully planned response process that can be initiated swiftly when a security incident (such as a ransomware attack) occurs so that normal operations can be restored as soon as possible. The sections below outline the overall incident-response lifecycle and the key points that companies should consider from a legal perspective.
Overview of the incident-response lifecycle
Incident response can broadly be divided into five phases.
Detection
When an incident is detected, employees must report it to the responsible functions (such as IT and Legal Departments) so that the initial response can begin without delay. However, detection is not easy in practice. When an incident occurs, frontline staff often do not know whom to report to, what to report or how much to report. This results in the delay of detection by organisational personnel who are best placed to initiate the response. As discussed in Section 4 below, companies should establish and thoroughly disseminate internal rules requiring prompt reporting to the responsible functions whenever there is a known or suspected cybersecurity incident.
Initial Response
Since relatively few companies maintain a dedicated Computer Security Incident Response Team (CSIRT), many will be required to engage a specialized cybersecurity firm for technical support. Typical steps to be taken as part of an initial response include:
Isolating infected endpoints from all networks (including Wi-Fi)
Preserving logs and other evidence for the vendor’s forensic investigation
Changing passwords and implementing multi-factor authentication (MFA)
Confirming the existence and scope of backups
Standing up a cross-functional response team
Issuing a company-wide advisory
(e.g., warning employees not to open similar emails)
Reporting and Public Disclosure
In general, notifications need to be made to the following parties:
Customers, business partners, contractors, principals, and affiliated organizations.
Depending on stakeholder relations, it may also be necessary to consider public disclosure to the media. In this matter, Asahi GHD, published a comment by Director, President & Group CEO Mr. Atsushi Katsuki, presumably with the aim of allaying concerns among customers and business partnersFinancial institutions and credit-card companies
Contacting Financial institutions and credit-card companies is necessary to prevent further harm stemming from information leakage and related risksSupervisory authorities; the Information-technology Promotion Agency, Japan (IPA) and the JPCERT Coordination Center (JPCERT/CC)
The Personal Information Protection Commission (PPC)
The police (law enforcement).
Although the key points are explained below in (2) ②, since these steps typically must proceed in parallel with the initial response, it would be advisable to obtain guidance from specialists such as a legal counsel.
Review of Findings and Restoration
Based on the forensic report prepared by cybersecurity specialists, confirmation that containment and eradication of the malware has been achieved is necessary for assessing whether restoration is appropriate. In the process of restoration, best practice is said to be reset and restore of endpoints suspected to be affected, installation of Endpoint Detection and Response (EDR), and restoration of systems to service only after confirming that no anomalies are detected.
Recurrence Prevention
Given the prevalence of RaaS, the possibility of repeated incidents cannot be excluded, making recurrence-prevention measures essential. In addition, as noted at ‘Reports and disclosures’ below, whenever notification to the PPC is required, the PPC will also require reports on the implementation status of recurrence-prevention measures proposed in the forensic report. It is therefore advisable to obtain guidance from specialists such as a legal counsel to ensure that the contents of the report meet this requirement.
Key legal considerations and strategic decisions
Whether to pay a ransom
With respect to ransom payments, the Ministry of Economy, Trade and Industry (METI), identifies the following three points and states that companies should strictly refrain from making monetary payments so as not to encourage ransomware attacks. Specifically, METI notes (in its advisory dated December 18, 2020 titled ‘最近のサイバー攻撃の状況を踏まえた経営者への注意喚起’ (001_07_00.pdf (in Japanese)):
Paying a ransom is tantamount to supporting criminal organizations.
There is no guarantee that payment will halt the publication of data or enable decryption.
In some jurisdictions, payment may be deemed financing of terrorist or other criminal organizations, exposing the paying company to sanctions.
Further, JPCERT/CC, in Q3-2-1 of its ‘FAQ to Read When Subjected to A Human-Operated Ransomware Attack’ (in Japanese), last updated December 12, 2024), adds the following two points in illustrating why ransoms should not be paid:
Even if a ransom is paid, the root causes and other harm caused from the intrusion will remain unresolved
After payment, there is a risk of subsequent attacks or additional payment demands
Reports and Disclosures required by law
The following reports and disclosures are required by law.
‘Preliminary’ and ‘Definitive’ reports to the PPC
A Business Operator Handling Personal Information (BOHPI) must report to the PPC when a leak, loss, or damage of personal data has occurred (or is likely to have occurred) due to an act against the BOHPI conducted with wrongful intent (Act on the protection of Personal Information (APPI) Art. 26(1); Enforcement Rules Art. 7). For these purposes, the obligation also covers scenarios where personal data is handled by entrustees or third-party service providers used by the BOHPI (Guidelines (General Rules) 3-5-3-1).
There are two report types: a Preliminary Report (速報) to be filed roughly within 3–5 days of detection, and a Definitive Report (確報) generally within 60 days of detection (for cyberattacks such as ransomware).
The items to be reported are:
・Overview of the incident
・Categories of personal data leaked or at risk
・Number of individuals whose personal data were leaked or at risk
・Cause
・Existence and details of secondary harm or risk thereof
・Status of actions for affected individuals
・Status of public disclosure
・Recurrence-prevention measures
・Other relevant matters
The Preliminary Report covers what is known at the time of filing; the Definitive Report, however, must address all of the above items.Notice to affected individuals
Where a report to the PPC is required, the BOHPI must also promptly notify affected individuals, as appropriate to the circumstances (APPI Art. 26(2); Enforcement Rules Art. 10).
The notice should include:
・Overview of the incident
・Categories of personal data leaked or at risk
・Cause
・Existence and details of secondary harm or risk thereof
・Other matters that are relevant in the circumstances
Although notice should be given without delay, sending it when facts are still largely unknown may cause confusion. In practice, it is advisable to notify the affected individual by letter or email in step with investigative progress and with due regard to client relationships (Guidelines (General Rules) 3-5-4-2, 3-5-4-4). If individual notification is difficult—for example, because ransomware encryption prevents access to contact information—alternative measures are permitted, such as public announcement of the incident together with the designation and publication of an inquiry desk/contact point.Timely disclosure (for listed companies)
For listed issuers, it may be necessary to consider Timely Disclosure where the incident constitutes a “important matters related to operation, business or assets of such listed company or such listed stock, etc. which have a significant impact on investors’ investment decisions” (Securities Listing Regulations Art. 402). Accordingly, upon an incident, the company should promptly consult with their Corporate Affairs / Investor Relations function to take measures to coordinate with the relevant stock exchange (such as Tokyo Stock Exchange) and assess the necessity of Timely Disclosure.
On October 14, 2025, Asahi GHD announced the possibility that personal information had been leaked in connection with the ransomware attack. As a result, Asahi GHD would, at minimum, be expected to fall within the case where ‘a leakage … is likely to have occurred,’ necessitating a report to the PPC and—if affected individuals can be identified—notices to those individuals.
Cybersecurity
Cybersecurity Management Guidelines (Ver. 3.0)
On March 24, 2023, METI published the Cybersecurity Management Guidelines (Ver. 3.0). The Guidelines set out the following three principles that corporate executives should recognise:
Corporate executives need to recognise that cybersecurity risk is an important issue in their company's risk management and take measures at their level to address this.
In order to fulfill the responsibility of ensuring cybersecurity, it is necessary to pay attention to cybersecurity measures not only for the company itself but also for the entire supply chain, including domestic and overseas bases, business partners and outsourcing organizations
Active communication with relevant parties is necessary to implement effective cybersecurity measures during both normal operations and emergencies
The Guidelines also set out the following ten priority items that management should instruct the responsible officers and departments to implement when carrying out cybersecurity measures:
Recognize cybersecurity risks and develop an organization-wide policy
Build a management system for cybersecurity risk
Secure resources (budget, workforce, etc.) for cybersecurity measures
Identify cybersecurity risks and develop plans to address them
Establish systems to effectively address cybersecurity risks
Continuously improve cybersecurity measures through a PDCA cycle
Develop a cybersecurity incident response team and relevant procedures
Develop a business continuity and recovery team and relevant procedures in preparation for damage due to cyber incidents
Understand the status of and implement measures considering the entire supply chain, including business partners and outsourcing organizations
Facilitate the gathering, sharing and disclosure of information on cybersecurity.
Establishing internal frameworks
Each company should develop internal rules using the Cybersecurity Management Guidelines (Ver. 3.0) as the baseline and keep in mind the five key points outlined below. Companies should recognize, however, that the development of these rules however is merely the starting point and it is of paramount importance for companies to build the requisite capabilities and culture in order to implement and conduct their activities in adherence with those rules.
1. Clarify roles and responsibilities
If internal governance is unclear, reporting lines and chains of command will be ambiguous when an incident occurs, delaying the response. Accordingly, the company should appoint a Chief Information Security Officer (CISO) and cybersecurity leaders for each department and clearly define their respective roles and responsibilities.
2. Build three-way coordination among IT, legal, and senior management that links normal operations to emergencies
As noted at 3(1)①, the company should establish and disseminate internal rules requiring prompt reporting to the responsible functions whenever there is a known or suspected cybersecurity incident. In identifying risks, the scope must cover the entire supply chain (see Guidelines (General Rules) 3-5-3-1 under the APPI). It is advisable to document the risk-response plan and communicate it company-wide.
3. Integrate policies with training and response capabilities
Risk-response plans should specify, in clear terms, who does what, when, and how, and should be supported by manuals, internal FAQs, drills/exercises, and initial-response workflows. Companies should also develop cybersecurity talent and keep internal knowledge up-to-date with input from experts such as a legal counsel and cybersecurity specialists.
4. Operate PDCA as a continuously running organization
It would be advisable to hold regular review meetings to examine internal rules and systems. To enable swift responses when incidents occur, it is important to instill the idea of the plan–do–check–act (PDCA) cycle across the whole supply chain and to implement into day to day operations so it becomes engrained within the organization’s culture and routine. As a means of assuring cybersecurity measures within the supply chain, consider using independent third-party assessments, as discussed in (3) below.
5. Establish an evidence-preservation posture
When a cyberattack occurs, the organization must be able to promptly preserve logs and secure/quarantine infected endpoints and other evidence. It is important to extend this record-keeping culture to the entire supply chain.
Security measures evaluation scheme to strengthen supply chains
As companies advance their cybersecurity programs, suppliers increasingly face divergent security requirements from different customers and industry groups, while ordering companies (customers) find it difficult to assess, objectively and consistently, the status of each supplier’s measures. In response - recognising the importance of supply chains - METI is developing a unified framework that specifies the measures companies should meet and visualizes each company’s implementation status: the Security Measures Evaluation Scheme to Strengthen Supply Chains (Interim Report Released on Discussions to Establish a Cybersecurity Measures Evaluation System for Strengthening Supply Chains)
According to the interim summary (in Japanese)), the scheme will evaluate required measures by multiple tiers (★3–★5), calibrated to each company’s criticality and potential impact within the supply chain. Of these, ★3 (aimed at a level capable of addressing common cyber threats) and ★4 (aimed at coping with attacks on companies whose business disruption would significantly impact a particular supply chain, or whose leakage of confidential information would be highly consequential) are expected to begin operation around fall of FY2026.
Conclusion
The ransomware attack on Asahi GHD has once again underscored the seriousness of cyber threats - even for Japan’s leading enterprises. With the rise of RaaS, attacks continue to increase, and the resulting harm can be devastating, affecting numerous customers and supply chains. Each company should treat cyberattacks as a management-level risk and, drawing on the support of specialists such as legal counsel and cybersecurity experts, accelerate the build-out of internal frameworks in line with the points discussed above.
