Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Policy Watch

FSA's 11th cyber drill will test 181 financial firms against attacks on core systems

Japan's Financial Services Agency will run Delta Wall 2026 from October 6 to 22 with a planned record 181 institutions, testing responses to attacks on core systems and promising industry-wide feedback.

By Tokyo Brief DeskOct 5, 20262 min read
Abstract network of financial institution nodes protected by a layered wall, with several links broken to suggest a simulated cyberattack.

The Financial Services Agency will run its 11th cross-sector cyber exercise, Delta Wall 2026, from Tuesday October 6 to Thursday October 22, with 181 financial institutions expected to take part. The agency's slide deck calls that the largest turnout to date. Participants will join from their own workplaces or from remote-work setups.

Why the drill, and what the name means

The FSA's announcement of October 5 says cyberattacks around the world have grown more sophisticated and faster. It lists business disruption, theft of sensitive information and financial loss among the harm already seen in Japan, and describes the threat as a risk that could affect financial-system stability. The accompanying deck adds ransomware, supply-chain attacks, information theft and unauthorized transfers, and cites concern that advanced AI, including frontier AI, will speed up and sharpen attacks.

The name combines Delta, for the three perspectives of self-help, mutual help and public help that the FSA calls key to cyber defence, and Wall, for defence.

The scenarios

According to the deck, the scenarios reflect more advanced attacks, and one aim is to improve how effectively firms respond when core systems are hit. The deck sets out these scenarios by sector:

Delta Wall 2026 scenarios by sector
Source: FSA Delta Wall 2026 overview. Blind-format sectors are not disclosed.
SectorScenario
Banks, shinkin, credit cooperatives, labour banks, agricultural-system lendersNot disclosed (blind format)
SecuritiesCyberattack leads to unauthorized access and unauthorized trading
Life and non-life insurersNot disclosed (blind format)
Fund transfer providers, prepaid payment issuersCyberattack leads to customer data leak and unauthorized payments
Crypto-asset exchange providersCyberattack leads to outflow of crypto-assets

Banks, cooperative and agricultural-system lenders, and life and non-life insurers run under a blind format, so their scenarios are not disclosed. The exercise checks initial response, investigation and analysis of the attack, customer handling and recovery, in order to confirm business continuity.

Feedback is the point

The deck says the FSA is putting its emphasis on post-exercise evaluation. It plans to show concrete improvement measures and good practices so participants can run a plan-do-check-act cycle, and to feed the results back to the wider industry, not only to participants.

The 181 figure is a plan, and the drill has not yet produced results. The scenarios are simulations, not evidence of actual breaches or of how resilient any institution is.