Japan faces increased cyberattacks from nation-state actors and cybercriminals, but has fallen behind in managing the cybersecurity of critical government systems, according to reports. While Japan's commercial industries are targeted by ransomware and info-stealers, the government continues to find itself the focus on cyber-espionage attacks and cyber-physical attacks on critical infrastructure. Following Japan's creation of cybersecurity standards, the nation's Board of Audit periodically reviews critical systems responsible for delivering government services. The Board of Audit found that 58 of the 356 critical systems were not maintained according to the cybersecurity standards. The law requires that critical infrastructure operators report cybersecurity incidents to the government and gives the government the ability to intercept foreign Internet traffic.