Security NEXTSeptember 1, 2026🇯🇵Translated from Japanese

NCA Annual Conference 2026 to Examine CSIRT Roles Amid AI and Supply Chain Shifts

The Japan CSIRT Council (NCA) has announced that its annual gathering, the NCA Annual Conference 2026, will run from December 2 to 4 in Tokyo. The conference serves as a platform for CSIRT professionals and other security practitioners to exchange insights and experiences across organizational and sectoral boundaries, regardless of NCA membership status.

This year’s theme, “Attacking, Defending, There Are People There,” will guide discussions on evolving threats driven by the rapid advancement of generative AI, shifting international dynamics around economic security, and the growing complexity of supply chains. Attendees will explore how these factors are changing the operational landscape and the strategic role of CSIRT teams in both defensive and proactive security postures.

The event will be conducted entirely on-site. The December 2 sessions will be hosted at Internet Initiative, while the December 3 and 4 sessions will take place at Akasaka Intercity Conference. Selected keynote presentations and other portions of the program are scheduled for later video release to reach a wider audience.

Participation is free of charge, although prior registration is mandatory. Full details on the agenda, speakers, and registration process are available on the dedicated NCA Annual Conference 2026 website.

Related articles

HabrPolicy & Regulation

From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively

Anatoly Antipov, head of L1 analysts at a small in-house SOC, explains why traditional time-based metrics like MTTD and MTTR often lead to superficial incident handling and analyst burnout. Drawing on NIST SP 800-61 and the latest SANS SOC Survey, the article shows how speed-focused KPIs encourage analysts to game the system rather than improve security. The team replaced vague verdicts with a five-level matrix including TP.Ext, TP.Int, BP, FP, and FP.SOC to separate real incidents, benign activity, and internal detection debt. Weekly reports were restructured around three blocks covering overall volume, verdict distribution, and confirmed violations with actual effort metrics. Regular quality audits of closed alerts now check verdict accuracy, documentation completeness, and whether FP.SOC items trigger rule improvements. The approach helps small SOC teams focus on genuine risk reduction instead of dashboard optics.

AntiMalwarePolicy & Regulation

Personal Laptops, Corporate Secrets: 70% of Companies Err with BYOD Policies

Up to 90% of employees in Russian organizations use personal smartphones and laptops for work tasks, yet around 70% of companies implement Bring Your Own Device programs incorrectly. This creates serious risks of data leaks and other security incidents. Crosstech experts warn that businesses often fall into one of two extremes: either allowing unrestricted use of personal devices without any rules or turning employee devices into heavily monitored extensions of corporate security systems. Both approaches can backfire, with the first leading to lost or compromised devices and the second driving the creation of uncontrolled shadow IT through unofficial apps and cloud services. The recommended approach is to isolate corporate data using encrypted containers on mobile devices and dedicated remote desktops for home computers, without monitoring personal activities. Architect Egor Norkin emphasizes that companies should focus solely on how their data is handled rather than employee behavior outside work hours.

HabrPolicy & Regulation

Corporate Wi-Fi Passwords Stored in Plain Text on Every Connected Device

Many organizations continue to rely on a single shared password for corporate and guest Wi-Fi networks, creating long-term access risks after employees leave. On Windows systems, the netsh wlan show profile command reveals the password in clear text without requiring administrative rights. Linux distributions using NetworkManager store the PSK in readable files under /etc/NetworkManager/system-connections unless the keyring option is selected. macOS keeps passwords in the Keychain, which prompts for user confirmation before disclosure. The article explains why shared passwords cannot serve as effective access control and recommends WPA2/WPA3-Enterprise authentication or properly isolated guest networks instead. It also provides concrete commands for administrators to audit their own environments and highlights the consequences of infrequent password rotation.

HabrPolicy & Regulation

Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations

A year after stricter Russian personal data protection fines took effect, many entrepreneurs continue to commit violations that could trigger multimillion-ruble penalties from Roskomnadzor. The article details ten common breaches, including the prohibited use of Google Forms for data collection, missing cookie banners, absent or invalid consent forms under forms, and failure to obtain separate consents for publishing reviews. Additional violations cover missing privacy policies, outdated notifications to Roskomnadzor, improper transfer of employee data to third parties without written consent, lack of data processing agreements, and absence of records for paper-based data storage locations. Each violation is explained with direct references to the Law on Personal Data, the Code of Administrative Offenses, and specific government orders, along with exact fine ranges for citizens, individual entrepreneurs, and legal entities. Practical remediation steps are provided, such as replacing foreign services with Yandex Forms, drafting compliant consent texts per Article 9, and submitting updated notifications under Order No. 180. The guidance emphasizes conducting a full site audit and implementing all required documents to avoid penalties throughout 2026.