On 15, the Financial Services Agency began accepting public comments under the title “Publication of Proposed Partial Amendments to the Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc.” The deadline is August 18 (Monday) at 17:00 (submissions must be received by this time).
In response to the many incidents of unauthorized access and fraudulent transactions (transactions by third parties) on online trading services using customer information such as login IDs and passwords stolen through phishing sites impersonating securities firms’ websites, these amendments are intended to strengthen authentication methods and fraud-prevention measures for online trading.
For readers of this blog, the following section of Appendix 1 may be of particular interest:
Taking into account the “Cybersecurity Guidelines for the Financial Sector”, the Japan Securities Dealers Association’s “Guidelines for Preventing Unauthorized Access and Other Misconduct in Online Trading”, and other relevant guidance, does the firm implement appropriate security measures suited to the services it provides? In doing so, does it take into account the growing sophistication and complexity of criminal techniques (such as “man-in-the-middle attacks” and “man-in-the-browser attacks”)?
(Omitted)
For important operations such as logging in, withdrawing funds, and changing the destination bank account for withdrawals, the implementation and mandatory use of phishing-resistant multi-factor authentication (for example, authentication using passkeys or authentication based on PKI (public key infrastructure)) must be implemented and required (enabled by default).
(Source) Financial Services Agency, “Proposed Partial Amendments to the Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc. (Comparison of Old and New Provisions)”
The mandate for phishing-resistant authentication has finally arrived. For why this matters, please also see “The Threat of Real-Time Phishing That One-Time Passwords Cannot Prevent: What Makes Passkeys Phishing-Resistant”. On the other hand, whether it really needs to be “multi-factor” is open to debate. As I have long argued, it is time to break free from the fixation on multi-factor authentication and focus more closely on which threats an authentication method actually addresses.
The other documents are as follows:
(Appendix 1) “Proposed Partial Amendments to the Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc. (Comparison of Old and New Provisions)”
(Appendix 2) “Proposed Partial Amendments to the Guidelines for Supervision of Credit Rating Agencies (Comparison of Old and New Provisions)”
(Appendix 3) “Proposed Partial Amendments to the Guidelines for Supervision of High-Speed Traders (Comparison of Old and New Provisions)”
(Appendix 4) “Proposed Partial Amendments to the Guidelines for Supervision of Investment Management Business Service Providers (Comparison of Old and New Provisions)”
Meanwhile, Some Reporting Misses the Point: Biometric Authentication Is Not Being Mandated!
Meanwhile, there has also been some reporting that misses the point. A prime example is the Nikkei article “FSA and JSDA to Require Biometric Authentication Under New Guidelines to Prevent Securities Account Takeovers.” Nikkin has likewise published an article titled “FSA to Require Multi-Factor Authentication Using Biometrics and Other Methods in Proposal to Strengthen Measures Against Securities Account Takeovers”.
However, the proposed amendments to the supervisory guidelines above say nothing about “biometric authentication.” Passkeys are mentioned as an example, but passkeys are not biometric authentication. This is precisely the kind of point that should be reported accurately instead of being excused as an attempt to make the story “easier to understand.” What matters this time is the mandatory use of phishing-resistant multi-factor authentication. It is not biometric authentication. Naturally, a mechanism that performs “biometric authentication” locally and then sends a password to the website is not acceptable.
So I sincerely hope that members of the media will take care on this point.
For reference, biometric authentication comes in local and remote forms. Those that use mobile devices have been standardized by ISO as follows. Both are publications of SC27 Information security, cybersecurity and privacy protection, whose corresponding Japanese technical committee I currently chair.
ISO/IEC 27553-1:2022 Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 1: Local modes
ISO/IEC 27553-2:2025 Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 2: Remote modes
I hope this is helpful.
