SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Cybersecurity for Self-Employed Individuals: Insights from the IPA '10 Major Threats 2026'

Even when told to 'make sure to implement security measures,' the honest truth for self-employed individuals and small businesses is that it is difficult to see where to start to actually reduce damage.

There is no dedicated IT department, it is common to have a structure where the president also handles accounting and general affairs, and employees are starting to use AI tools as they please. We are entering 2026 with that kind of on-site reality.

In such a situation, a useful reference is the '10 Major Information Security Threats' published annually by the IPA (Information-technology Promotion Agency, Japan). The 2026 edition was announced on January 29, 2026 (Source: IPA 'Press Release: 10 Major Information Security Threats 2026 Decided').

This time, I will re-examine this ranking from the perspective of self-employed and small business owners, as well as those already incorporating AI tools into their operations.

As someone who creates offline OCR apps for professionals, I think daily about 'how to handle paper documents containing personal information.'

'Cyber risks surrounding the use of AI' debut at 3rd place in the 2026 edition

First, let's list the ranking for organizations. The order is based on the content of the IPA's official website and press release (Source: IPA '10 Major Information Security Threats 2026').

  1. Damage from ransomware attacks (11 consecutive years)

  2. Attacks targeting supply chains and contractors (8 consecutive years)

  3. Cyber risks surrounding the use of AI (First selection in 2026)

  4. Attacks exploiting system vulnerabilities

  5. Targeted attacks aiming for confidential information

  6. Cyberattacks stemming from geopolitical risks (including information warfare)

  7. Information leaks due to internal misconduct, etc.

  8. Attacks targeting environments and mechanisms such as remote work

  9. DDoS attacks (Distributed Denial of Service attacks)

  10. Business email compromise

The supplementary information on consecutive years was referenced from an explanatory article for small and medium-sized enterprises (Reference: AsaSimple Co., Ltd. 'Complete Explanation of IPA 10 Major Information Security Threats 2026').

The biggest change in the 2026 edition is that 'Cyber risks surrounding the use of AI' was selected for the first time and immediately entered at 3rd place.

It is thought that cyber risks are increasing as AI reaches a practical level. The IPA press release also clearly states three points as anticipated risks: 'unintended information leaks and rights infringements due to insufficient understanding of AI,' 'problems arising from blindly trusting AI-generated results without verification,' and 'facilitation and sophistication of cyberattacks through the misuse of AI' (Source: IPA Press Release January 29, 2026).

What I want to emphasize here is that there is only one newcomer, and the remaining nine items are continuing regulars.

It is not that attack patterns have surged, but rather that existing methods have become more sophisticated and clever, and an amplifier called AI has been added to them, which feels closer to the reality on the ground.

Are the top priorities for self-employed individuals and small businesses 'Ransomware,' 'Supply Chain,' and 'AI'?

It is difficult to try to address all 10 major threats, but you can significantly reduce your risk just by preventing common patterns.

Ransomware Attacks (1st place): Check 'if the backup really restores' just once

Ransomware attacks have been in 1st place for 11 consecutive years, making them a completely fixed threat. NTT Docomo Business's explanation also organizes that methods are diversifying, such as double extortion which involves data theft in addition to encryption, nowhere ransomware which threatens by public disclosure without encryption, and RaaS which turns attacks into a service (Reference: NTT Docomo Business '[2026 Edition] 10 Major Information Security Threats and Measures Companies Should Take').

There is actually not much that needs to be done at the small business level. (1) Take dual backups on cloud storage and locally, (2) test once a year if the backup can actually be restored, (3) do not turn off automatic updates for business PC OS and browsers is about it.

Just doing this will significantly change the probability of being able to rebuild your business from ransomware damage. My impression was that the most common case in the field of self-employment is stopping at 'I should have taken backups.'

Supply Chain/Contractors (2nd place): Be aware that you can be used as a 'stepping stone'

Supply chain attacks are a threat that small business owners should read as **both 'being a victim' and 'potentially becoming an offender who involves business partners'**.

NTT's explanation organizes that even if the target company's security is solid, if the security of business partners or contractors is weak, that becomes the entry route (Reference: NTT Docomo Business, same article).

At the self-employed/small business level, (1) Review the permissions of the cloud shared with business partners (Google Drive, Dropbox, kintone, etc.) once every six months, (2) do not leave accounts of retired employees or finished contractors, (3) decide just one line on 'where to contact in case of an incident' with consultants and business partners is sufficient granularity.

It doesn't have to be a difficult contract; just having one line written in an email will allow you to act when the time comes.

Cyber Risks Surrounding AI Usage (3rd place): This is currently the most likely to be put on the back burner

And what I want to delve into most in this series is 3rd place. Trend Micro's explanation organizes understanding AI cyber risks by dividing them into **three categories: 'attacks abusing AI,' 'attacks against AI,' and 'operational and legal risks'** (Reference: Trend Micro 'IPA "10 Major Information Security Threats 2026": Understanding AI Cyber Risks by Dividing Them into Three').

For small business owners, **the most realistic one happening every day among these three is the third, 'operational risk.'** Specifically, it was in situations like the following.

  • Pasting customer lists or contract text into a free-plan generative AI to summarize it

  • Employees putting company data into ChatGPT they use with personal accounts

  • Sending misinformation returned by AI to customers as is, requiring corrections later

This is not an accident caused by being attacked, but an accident that occurred as a result of AI permeating the workplace without operational rules.

As the IPA commentary explicitly highlights 'unintended information leakage caused by insufficient understanding of AI' as the top concern, at the micro-business level, you must first eliminate this self-inflicted risk before focusing on external attack countermeasures (Source: IPA Press Release, January 29, 2026).

Create a 'one-page AI usage policy' within this month.

As I have written several times in this series, the outcome of AI-related risks depends heavily on whether or not you establish a single-page policy from the start. The structure is exactly the same as the 'decide what data not to give to AI' advice I wrote about in my article on AI usage for labor and social security attorneys.

For micro-businesses, if you cover the bare minimum on a single sheet of paper, that is sufficient.

  • Draw a line between data you can input and data you cannot: Raw data such as names, salaries, My Number, client names, and amounts are off-limits. Anonymize or categorize them before pasting.

  • Limit the AI services you are allowed to use: Narrow it down to one or two business plans where 'training off' is the default. Do not use free plans for company business.

  • Treat AI responses as 'drafts': Always have a human review documents, contracts, and estimates intended for clients before sending them.

  • Decide on a point of contact for when you are stuck or unsure: Establish a workflow where you can ask the business owner or a specific person in charge, 'Is it okay to input this?' within one minute.

The Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry's AI Business Guidelines also emphasize transparency, risk management, and human involvement when using AI. While the phrasing is formal, I interpret the essence of what needs to be done at the micro-business level as being the same as the four lines above.

The remaining threats can be mostly covered by 'incidental countermeasures'

From the 4th rank onwards in the 10 major threats, the countermeasures for micro-businesses overlap significantly.

  • 4th place: Attacks exploiting vulnerabilities can be largely mitigated by simply not turning off automatic updates for OS, browsers, and business applications.

  • 8th place: Attacks targeting remote work environments can have their damage probability significantly reduced by simply enforcing multi-factor authentication (MFA) and screen locks on all company PCs and smartphones.

  • 10th place: Business Email Compromise (BEC) can have most micro-business damage scenarios eliminated with just one rule: 'Always confirm requests to change bank account details via phone.'

  • 7th place: Internal fraud can be covered by a policy of deactivating departing employees' accounts on the same day and reviewing shared folder permissions.

Most risks can be prevented through 'thorough operational management' rather than special investments. Conversely, buying high-performance EDR or SIEM tools without established operations often leads to waste at the micro-business level because they cannot be managed effectively.

Thinking about this in relation to my own app development

Since I am building an offline OCR app for people who handle various documents, such as professionals and consultants, I decided on an offline-only approach after worrying about 'when, where, and in what form customer data is transferred.' The world of security is one of cutting losses and requires advanced technology, experience, and intuition; by managing things as simply as possible, you can reduce opportunities for attacks.

While it is true that this is difficult unless you are an operating company with capital, I believe the direction of handling things offline where possible while maintaining convenience is correct.

In this way, while AI utilization and security measures may seem like separate topics, it can be said that it all comes down to the difference between 'consciously designing the flow of data or letting it flow aimlessly.'

The reason I am committed to making it work offline is that I wanted to make the 'option not to hand over data to AI'—which is currently the most sought-after requirement in small-scale operations—the default, so that document images do not have to leave the premises.the option not to hand over data to AI, which is currently the most sought-after requirement in small-scale operations.

Having re-read the 10 Major Threats 2026, I am convinced once again that this direction was the right one.

From a business owner's perspective, the criteria for choosing AI tools should not just be 'convenience'; simply taking a moment to consider 'where the data goes' serves as preparation against the third-ranked threat. There is no need to memorize difficult terminology; spending one minute reading the data handling section of the contract screen is enough to make a real difference.

The risks behind the popularity of Google Workspace

I would like to talk about Google's SaaS in terms of data flow design. Google Workspace, which claims not to use client data for training, has become a common choice in business settings. There are multiple AI products available, and since AI can be used safely (if you trust Google completely), it has gained a certain level of adoption.

On the other hand, while not triggered by Google Workspace itself, there is a risk that your account could become unusable at any time due to unexpected circumstances.

In this case, the account was likely frozen after receiving a violation judgment automatically via an algorithm, such as an AI, on Google Drive. While the ambiguity of the judgment criteria is questionable, the real problem here is that a violation on Google Drive results in the inability to use all Google services.

While the handling might differ between personal and corporate accounts, if a company's products are related to adult content, medical fields, or criminal investigations, there is a possibility of automatic suspension, and no matter how much attention you pay to cybersecurity, this cannot be prevented.

With a typical SaaS provider, you might get individual support due to potential lawsuits or social reputation, but with a capital-intensive giant like Google, it is conceivable that your account could be mechanically frozen, leaving you with no recourse.

Large services carry the risk that you could suddenly be unable to use them due to automatic judgment if you are unintentionally handling sensitive information.

Regardless of whether you use them or not, it is almost always the right choice to keep data that would be problematic if it disappeared on your own local storage.

Summary

The 10 major information security threats for 2026 have only one newcomer: 'Cyber risks surrounding the use of AI', and the rest are the usual suspects. That is precisely why you can narrow down your focus at the self-employed or small-business level.

  • For the #1 threat, ransomware, try once to see if your backups actually restore

  • For the #2 threat, supply chain attacks, audit shared cloud permissions and accounts of former employees

  • For the #3 threat, AI cyber risks, define AI usage rules on a single sheet of paper

  • The remaining threats can be almost entirely covered by automatic updates, MFA, and confirming payment changes via phone

  • At the small-business level, writing down operational rules is more effective than investing in tools

There is only one thing I want you to try by next month: write down on a single sheet of A4 paper who is using AI, in what situations, and with what data within your company (including family members and outsourced partners). The moment you write it down, you will definitely notice at least one thing you shouldn't have been putting into the AI. That is the starting point for your company's security measures in 2026.

Reference Materials:

いいなと思ったら応援しよう!