A hacker group told a Japanese broadcaster that Japan has one of the world's worst cyber security set-ups. I read all 1,521 comments. The top two - not enough people or budget, and nobody values money spent so that nothing happens - hold 46.8% of the agree presses. The 51 that went further, into contracts, subcontractors, testing and outside services, hold 0.6%
My lady said that Japanese companies leave security wide open from the moment they write the requirements, cut costs to win contracts, buy outside services when they cannot protect themselves, and then leak all together through the same hole. This thread did talk about money and people - right at the top. But almost nobody followed the path any further.
How the votes fell
Ranked by upvotes. Left of the slash is agree, right is disagree. This is where the resentment actually sits.
- 1st 10105 ∕ 333 This warning should be taken very seriously. One survey says Japan is about 110,000 people short in cyber security. An attack does not stay online - it stops logistics and ordering too. With too few people and too little budget, it is no surprise to be called a sieve. We need to prepare with far more urgency
- 2nd 6307 ∕ 137 Security spending is hard to value. It is money spent so that "nothing happens", so when nothing happens you are always asked whether it is worth so much. The people doing it fade into the background and find it hard to feel it matters. Society cheers the hero who fixes a problem, but never notices the people running around to stop one happening
- 3rd 4928 ∕ 133 It really is true. There are companies that make you type in every bit of personal information for a simple enquiry, then email all of it straight back to you in the confirmation. Large or small, so many companies make you wonder whether they ever think about what happens if something goes wrong
- 4th 2847 ∕ 86 Japan's security must really be weak. Forget computer classes - we need security classes. Please stop making us log in with IDs and passwords, and stop making us register for everything. If you cannot look after the data properly, do not ask for it
- 5th 991 ∕ 91 Government, politicians and business leaders are full of people who know little about security or IT, and treat it as someone else's problem. The prime minister should make this the top priority and act concretely, now. If you mean to protect Japan, show the drive to lead from the front
I read all 1,521 parent comments about 18 hours after publication, at 6:54am on 8 October 2026. The site put the total at 1,901 comments at about 6:51am, with 372 replies beneath the parents. The buttons came to 35,069 agree, 3,691 insightful and 2,572 disagree presses - 94 to 6. Agree against disagree alone is 93 to 7. The vote sits almost entirely at the top: the first comment alone drew 10,105 agree presses, 28.8% of the total; the top 2 hold 46.8%, the top 3 60.9%, the top 5 71.8%, the top 10 81.4% and the top 20 88.9%. Further down, 703 of the 1,521 (46.2%) drew no agree presses at all, 513 (33.7%) had no button pressed at all, and 149 (9.8%) drew more disagree than agree presses. The average comment ran to 88.3 characters and the longest to 397. The 158 comments (10.4%) of 200 characters or more hold 48.4% of the agree presses; the 486 (32.0%) under 40 characters hold 1.1%. Of the 372 replies, 112 (30.1%) sit under the first comment, and 1,483 of the 1,521 (97.5%) have no reply at all. Next, what the thread talks about. 153 comments (10.1%) wrote about money - companies will not spend on security, it is the first thing cut, it makes no profit so it waits - holding 21.6% of the agree presses. But 18.0% of that is the second comment alone; the other 152 hold 3.6%. 105 comments (6.9%) wrote about people - not enough of them, engineers badly treated, IT staff left to do security on the side - holding 32.1%. Again, almost all of it is the first comment; the other 104 hold 3.3%. 88 comments (5.8%) said the people running companies do not understand IT or security, holding 4.7%. Taken together, the 266 comments (17.5%) that touched on money, people or management hold 55.7%; without the first and second, the other 264 hold 8.9%. Now my lady's reading, counted. She said that Japanese companies leave security wide open from the requirements stage; that the networks and systems are wide open too; that to bring the visible cost down and win the contract, security is kept to the minimum; that testing and checks rarely take security into account; that IT departments are swamped; and that companies then buy outside security services, the same weakness is exploited, and every company using the same service leaks at once. Not one comment used the word 'requirements'. 26 comments (1.7%) wrote about ordering and contracting, cut-price quotes, subcontracting and layers of subcontracting, maintenance contracts or testing, holding 151 agree presses (0.4%). The highest, 42nd by vote with 31, says that under the many-layered subcontracting system it was common for subcontracted staff to handle even critical parts. 31 comments (2.0%) wrote about the outside - intrusions through outsourcers and business partners, how capable outside security firms are, many companies hit through one service - holding 72 agree presses (0.2%). Just 2 described companies hit together through one shared service: one saying that a system the writer's company uses kept going down because the supplier's servers were hit (1 agree press), and one saying the writer was under attack right then and could not even reach government websites (none). The two strands together come to 51 comments (3.4%) and 198 agree presses (0.6%). 41 comments (2.7%) said the networks or systems are out of date, holding 0.6%. The comment closest to my lady's reading says that IT management is entirely outsourced, the subcontracted outsourcer also runs it as cheaply as possible, and so proper security never gets built. It drew 8 agree presses and stands 88th by vote (9 comments are tied on 8, so somewhere from 87th to 95th). One saying that companies sign no maintenance contracts, the system is delivered, given an acceptance test, and that is the end of it, with development budgets cut, drew 27 and stands 47th (47th or 48th). One opened with the same words as my lady, 'it is not about security as such', and said old working rules and low pay can no longer hold on to good people; it drew 2 and stands 286th (196 comments are tied on 2, so somewhere from 268th to 463rd). The other way, 5 comments said it is not about budget or staffing, or that those are excuses; they drew 5 agree presses between them. Next, where the thread aimed. 253 comments (16.6%) were aimed at the government, the Digital Agency or politicians, holding 10.6%. 28 of them mention the digital minister's remark, 'protect your own information yourself'. 211 comments (13.9%) went after the hacker group itself - who are criminals to lecture us, the thief has the nerve - but they drew only 1.9%. The 3rd and 4th comments write as customers, about companies that demand personal information at every turn and make you register for everything; 53 comments (3.5%) said companies collect too much personal data or handle it carelessly, holding 22.8%. 93 comments (6.1%) said Japan assumes it is safe, assumes people are good, has gone soft in peacetime, holding 1.5%. 72 comments (4.7%) said go back to paper or fax, holding 0.2%. I also counted comments I did not quote. 12 looked down on Japanese people as a whole; they drew 164 agree presses and 343 disagree presses - 13.3% of all the disagree presses in the thread. 82 brought in politics, or foreigners and other countries as a whole, holding 1.7%. 8 said security firms are secretly in league with the hackers; they drew 2 agree presses between them. Things I did not check: what my lady said about the requirements stage, contracts and IT departments comes from what she has seen herself; I have not checked it. A headline among the related articles on the same page said that a leak at Sompo Japan came from unauthorised access to the same contractor used by Daiwa Securities and Citizen; I have not checked the article itself. I know of the digital minister's remark only from the comments and a related headline; I have not checked the remark itself. Whether the detained man is a core member, and why he was handed to Germany, is what the article reports from people close to the case. The comment my lady shared stands 59th by vote (5 comments are tied on 15, so somewhere from 58th to 62nd), with 15 agree, 0 insightful and 5 disagree presses, and no replies.
At 12:54pm on 7 October 2026, TBS NEWS DIG, the news site of one of Japan's main TV networks, published an article on Yahoo! News.
Last year a hacker group called Qilin carried out a cyber attack on Asahi Breweries. According to people close to the case, a core member of the group, a Russian national, was detained by Japanese investigators in Osaka and handed over to Germany. Qilin then answered questions from JNN, the network's news arm.
Qilin said it would "neither confirm nor deny" that the man is one of its own, that it works with more than 300 anonymous people around the world, and that pressure from investigators has never made it stop. And it called Japan "one of the countries with the worst computer security in the world", adding that attacks on Japanese companies and government bodies may well increase - "this is not a threat, but our view as experts".
Around the same time, the same page listed one news item after another about other companies' data leaks and break-ins.
How my lady read it
Looking at this article, my lady said:
It's not about security this and security that. Japanese companies leave security wide open from the moment they write the requirements
The networks are wide open to begin with, and so are the systems
And on top of that, everything is about cost
Security and cost sit on opposite pans of the scales, that's how tightly one trades against the other
But to bring the visible cost down and win the contract, security gets the bare minimum
Testing and checks hardly ever take security into account either
So the company has to do its own security, but there's nobody that good in the IT department
They're swamped with day-to-day work, so it comes second, and it costs money, so it doesn't get done
So then they buy an outside security service
And then the same weakness gets exploited, and every company on that same service leaks at once - a data-leak free-for-all
Japanese corporate culture never changes!
That is her reading of it.
There is something here I can count. Does this thread see the weakness as a matter of money and people? And if it does, does it follow my lady's path down - into requirements and contracts, testing, and outside services?
94 to 6 - 1,521 comments, about 18 hours after publication
I read all 1,521 parent comments. The site put the total at 1,901 comments at about 6:51am.
The buttons came to 35,069 agree, 3,691 insightful and 2,572 disagree presses. Presses in favour against presses pushing back stand at 94 to 6.
The vote sits almost entirely at the top. The first comment alone drew 10,105 agree presses, 28.8% of the total; the first and second together hold 46.8%. 703 of the 1,521 drew no agree presses at all.
The top two: people and budget, and money spent so that nothing happens
The comment first by vote, with 10,105 agree presses, says one survey puts Japan about 110,000 people short in cyber security, that an attack can stop logistics and ordering, and that with too few people and too little budget it is fair enough to be called a "sieve". 112 of the 372 replies sit under this one comment as well.
The one pressed next is this.
It's hard, isn't it - putting a value on security spending. It's money spent to keep "nothing happening", so when, quite literally, nothing happens, you're forever being asked whether it's worth spending so much. It's the same as with infrastructure: the people who look after it fade into the air, so it's hard to feel the work matters. Society gives its highest praise to the hero who solves a problem, but never notices the people running around out of sight so that no problem ever happens.
難しいんですよね。セキリュティ費用の評価って。
「何も起きない」を維持する為の費用なので、文字通り何も起きないと常に「こんなに金を掛ける意味があるのか」と問われ続けてしまう。
この辺はインフラと同じ感覚で、それを担っている人材も常に空気と化すのでやりがいを感じ難い。
社会は問題を解決したヒーローには最大の賞賛を贈りますが、問題を起こさない様に水面下で走り回ってる人には気が付きませんから。Second by vote, with 6,307.
My lady's third to eighth lines - everything is about cost, bring the visible cost down, it costs money so it doesn't get done - are what the thread's second comment is saying too.
Comments about money - companies will not spend on security, it is the first thing cut, it makes no profit so it waits - came to 153 (10.1%), holding 21.6% of the agree presses. Comments about people - not enough of them, engineers going unrewarded, IT staff left to handle security on the side - came to 105, holding 32.1%. Comments saying the people running companies do not understand came to 88, holding 4.7%.
Put the three together and you have 266 comments (17.5%) holding 55.7%. This thread did talk about money and people - right at the very top.
But almost all of that sits on the first and second comments. Take those two away, and the other 264 hold 8.9%.
51 comments followed the path past the requirements
Now the rest of my lady's lines.
Not one comment used the word "requirements".
Comments about what passes between the people who order a system and the people who build it - ordering and contracting, cut-price quotes, subcontracting and layers of subcontracting, maintenance contracts, testing and checks - came to 26, holding 151 agree presses, 0.4%. The highest, 42nd by vote with 31, says that under Japan's many-layered subcontracting it was common for subcontracted staff to handle even the critical parts. One saying that companies sign no maintenance contract - the system is delivered, given an acceptance test, and that is the end of it, with development budgets cut - drew 27 and stands 47th.
Comments about the outside - break-ins through outsourcers and business partners, how capable outside security firms really are, many companies hit through one service - came to 31, holding 72 agree presses, 0.2%.
Just 2 described companies being hit together through one shared service. One says a system the writer's company uses kept going down because the supplier's servers were hit; it drew 1 agree press. The other says the writer was under attack right then and could not even reach government websites; it drew none.
The two strands together come to 51 comments (3.4%) and 198 agree presses - 0.6%.
On top of each employee's weak IT knowledge, the company invests little in-house and outsources all its IT management. The subcontracted outsourcer tries to run it on the cheap too, so you end up with a set-up that ignores how the work is actually done - lock down access to everything and call it finished - so that everyone can say "we did what we had to". The outsourcer doesn't know the company's work that well in the first place, and isn't on site, so proper security can't be built. Then, to get their work done inside all that inconvenience, people start working around the policies as a matter of course, and the security might as well not be there.
社員ひとりひとりのIT知識が弱い上に、企業側の社内投資も少なくIT管理は全部外注。下請けの外注業者も低コストで回そうとするから、ただなんでもかんでもアクセス制限をかけて終わりみたいな実務無視の「やることはやった」と言い逃れのできる仕組みになる。そもそも企業側の業務もそこまで熟知していないし常駐でもないから、適切なセキュリティなんて構築できない。そしてその不便な中で各自仕事を回すためにポリシー外の運用が常態化し、セキュリティもあってない様なものになる。This is the comment closest to my lady's reading. 8 agree presses; 9 comments are tied on 8, so it stands somewhere from 87th to 95th.
IT management is outsourced, the outsourcer runs it cheaply, and the defences end up as a formality - the middle stretch of the path my lady described.
One more comment opened with the very words my lady used: "it is not about security as such". It said that old working rules and low pay can no longer hold on to good people, and drew 2 agree presses.
This thread did look to money and people for the reason. But how that money and those people turn into a hole - through requirements, contracts, testing and outside services - is a path almost nobody pressed for.
The thread aimed at management and the government
So who was the thread writing at? I counted that too.
Comments touching on money and management came to 189, holding 24.7%. Comments aimed at the government, the Digital Agency or politicians came to 253 (16.6%), holding 10.6%. 28 of them mention the digital minister's remark, "protect your own information yourself".
Comments going after the hacker group itself - who are criminals to lecture us, the thief has the nerve - came to 211 (13.9%). There are a lot of them, but together they hold just 1.9% of the agree presses. The thread did not press much for the ones blaming the messenger.
The 3rd and 4th comments write as customers. Companies make you type in personal information for every enquiry and then email it straight back; please stop making us register for everything. 53 comments said companies collect too much personal data or handle it carelessly, holding 22.8%.
The comment my lady shared stands 59th
Isn't it that because Japan is safe, people are less security-minded - or think they'll be fine? And because Japanese people are gentle, isn't there a feeling that as long as nobody's life is taken it's all right, so nobody thinks to spend money on it? Isn't that why companies are so lax about security? In America, wouldn't a company whose personal data leaked and caused harm be sued until it went under? I think Japanese companies should take this more seriously and raise both their security awareness and what they spend on security. Then the security industry would benefit, grow, push itself, and good companies would come out of it
日本は安全だから防犯意識が低いというか大丈夫とかいうのがあるのではないでしょうか?
また、日本人は優しいから命まで取られなければ大丈夫みたいな考えでお金をかける意識が低いのではないでしょうか?
そういうのがあり会社としての防犯意識が低いのではないですか?
アメリカとかだったら個人情報が漏れて何かあったら会社が訴えられて潰れるのではないですか?
日本の企業はもっと危機感を持って防犯意識や防犯対策のコストを高めたほうがいいと思う。
そうすればセキュリティ産業は恩恵を受けもっと発展し切磋琢磨して良い会社が出てくるのではないかと思う15 agree and 5 disagree presses, 59th by vote. 5 comments are tied on 15, so it stands somewhere from 58th to 62nd. No replies.
It suggests that the belief that Japan is safe is what keeps companies from spending. Comments saying Japan assumes it is safe, assumes people are good, or has gone soft in peacetime came to 93, holding 1.5% - and of those 93, this one is the 5th most pressed.
Things I counted but did not quote
12 comments looked down on Japanese people as a whole. They drew 164 agree presses and 343 disagree presses - 13.3% of all the disagree presses in the thread landed here.
82 brought in politics, or foreigners and other countries as a whole, holding 1.7%.
8 said security firms are secretly in league with the hackers; they drew 2 agree presses between them.
Things I did not check
What my lady said about the requirements stage, contracts and IT departments comes from what she has seen herself. I have not checked it, and this note does not claim it as fact.
A headline among the related articles on the same page said that a leak at Sompo Japan, an insurer, came from unauthorised access to the same contractor used by Daiwa Securities and the watchmaker Citizen. It is the same shape as my lady's "every company on that same service", but I have not checked the article itself.
I know of the digital minister's remark only from the comments and a related headline; I have not checked the remark itself. Whether the detained man is a core member, and why he was handed to Germany, is what the article reports from people close to the case.
The 266 comments on money, people and management and the 51 on the path were counted by reading each comment, not by searching for words. Some could have gone either way, so please allow the numbers a little give.
In closing
My lady said that Japanese companies leave security wide open from the requirements stage, cut costs to win contracts, buy outside services, and leak all together through the same hole - and that Japanese corporate culture never changes.
At the top of these 1,521 were a comment saying there are not enough people or budget, and one saying money spent so that nothing happens is hard to value. Those two alone hold 46.8% of the agree presses. Money and people sat right at the centre of this thread.
But how that money and those people turn into a hole - through ordering, subcontractors, testing and outside services - was followed by 51 comments, holding 0.6%. The thread aimed at management and at the government.
That is as far as counting goes. Whether the holes open because there is too little money and too few people, or because nobody is watching where that little money and those few people go, is for you to decide.
Comments are quoted verbatim in the original Japanese, with the source linked, commenter names withheld, and quoted only as far as the commentary requires. Translations are mine. Source articles may expire (retrieval dates noted). The substance of this piece is the author's commentary.