Trends in the Japanese Information Security Industry
Japanese Economy Division
Summary
• Japan's information security market growing favorably due to rapidly expanding demand for services and stable demand for products.
• Security-related companies are increasingly shifting from merely selling equipment to developing business models that integrate equipment and services.
• The demand for security products is being developed with new products that integrate varied functions and new marketing methods.
• Tie-ups between domestic and overseas security vendors are accelerating. 1. Market Overview
With networks having thoroughly permeated corporate activities in Japan, the information security industry is capitalizing on security concerns that have sprung up virtually everywhere in corporate Japan. Although many public institutions, major enterprises and other users have implemented security measures, damage still continues to occur due to new types of viruses and methods of illegal access. As a result, network security needs to be maintained with stringent measures that can deal with frequent and diverse security threats, which has created a favorable market for information security products and services.
According to the "Comprehensive Survey of the Network Security Business" by the Fuji Kimera Research Institute, the information security market grew from 72.7 billion yen in 2000 to 222.6 billion yen as of 2003, and is estimated to have quadrupled the 2000 figure in 2004. Security services quintupled from 9.8 billion yen in 2000 to 48.6 billion yen in 2003, while security products tripled from 62.9 billion yen to 174.0 billion yen over the same period (Fig. 1).
According to the Information-Technology Promotion Agency (IPA), there were 24,261 reports of viruses in 2001, 20,352 in 2002 and 17,425 in 2003. In addition, there were 550 reports of illegal access in 2001, 619 in 2002 and 407 in 2003. Ongoing security breaches on this scale have dramatically increased user awareness of the need for countermeasures (Fig. 2). So far, measures have mainly consisted of introducing anti-virus tools for protection against viruses and illegal access, and firewalls and other products to prevent external attacks and intrusions.
In addition to public agencies and major enterprises, the implementation of measures has spread to smaller enterprises and also individuals. Most users have the necessary steps to block external attacks, so information security measures are now aimed at strengthening internal security, such as establishing authentication systems, introducing encryption products and ensuring compliance with the Personal Data Protection Law, which took effect in April 2005.
10 15 26 49 78 63 110 152 174 213 0 50 100 150 200 250 300 350 2000 2001 2002 2003 2004 (estimate) Security products Security services (billion yen)
Fig. 1 Changes in Information Security Market Scale
One major reason for this is a number of incidents occurring between 2003 and 2004, where large amounts of personal data was leaked by major telecommunications operators, mail-order vendors, financial institutions, local governments and other organizations. In response to the shock over these leaks, companies began strengthening authentication systems and establishing internal information security measures, although such efforts were implemented by only a limited number of enterprises. The Communications Usage Trend Survey in 2003 showed that while some enterprises had taken measures such as enhancing employee awareness of the Personal Data Protection Law and related issues, about 40% of the surveyed companies responded that they had taken no particular measure, indicating that inadequate action on the part of many enterprises has been a factor in information leaks.
Damage caused by the recent leaks has been far reaching. The enterprises involved have suffered lost credibility, demands for compensation totaling large sums, self-imposed curtailment of business activities and other damage. The situation has the potential to shake the foundations of corporate Japan. But managers have generally come to recognize that security negligence can lead to serious damage, and this heightened awareness has been a major factor behind the expansion of the information security market in recent years.
In addition, the Personal Data Protection Law not only applies to the enterprises that
Fig. 2 Reports of Viruses and Illegal Access <Reports of Viruses>
<Reports of Illegal Access>
Note: 2004 figures show the total for January through June. Source: Information-technology Promotion Agency, Japan (IPA)
2,035 3,645 11,109 24,261 20,352 17,425 21,957 0 5,000 10,000 15,000 20,000 25,000 1998 1999 2000 2001 2002 2003 2004 Reports 46 55 143 550 619 407 325 0 100 200 300 400 500 600 700 1998 1999 2000 2001 2002 2003 2004 Reports
Fig. 3 Personal Information Protection Measures by Corporations
Source: Ministry of Internal Affairs and Communications, Communications Usage Trend Survey in 2003
0% 10% 20% 30% 40% 50% 60% 分からない 特にない その他 外注先の選定要件の強化 プライバシーマーク制度の取得 プライバシーのポリシー策定 個人情報保護管理責任者の設置 必要な個人情報の絞込み システムや体制の再構築 社内教育の充実 平成15年末 平成14年末 平成14年末 平成15年末
Enhance internal education Restructure systems and organizations Reduce required personal information Establish personal information protection
ffi Formulate privacy policies Obtain privacy verification certificate Strengthen selection of outside suppliers Other measures No measures Don't know
2002 year end 2003 year end
directly manage personal data, it also makes them responsible for overseeing affiliates, contractors and other enterprises that may come into contact with the data. For this reason, many enterprises now notify suppliers and affiliates of the need for them to enhance their security measures, which have created further momentum in the information security market.
2. Industry Structure: Increasingly Service Oriented
The information security industry is broadly divided into the following four sectors (Fig. 4):
• Tool and equipment vendors, who provide the software and hardware,
• Service vendors, who use security equipment to provide products and services to end-users,
• Dealers, who focus mainly on product sales, and
• System integrators, who provide comprehensive security services with products and services. Tool and equipment vendors provide products for service vendors and system integrators, supply OEM products, develop solutions that make full use of product features and provide technical support. The information security industry is shifting toward services, which is reflected in companies’ efforts to develop service businesses in cooperation with service vendors and others. This trend is blurring the distinction between tool/equipment vendors and service vendors.
Tool and equipment vendors so far have secured sales routes and concluded agreements with strong sales partners, but recently many of these companies have begun to emphasize after-sales business and approach users in much the same way as service vendors. Increased user awareness and knowledge concerning information security has also caused these vendors to discontinue former sell-and-forget methods. Customers now understand that the introduction of security products does not automatically eliminate all threats, so vendors must help their clients improve their overall security, including through
Fig. 4 Information Security Industry Structure
(Fig. 4) shows the information security industry structure in terms of product and service flows.
System integrators Consulting firms Overseas developers
Advanced security technology and know-how T el eco mmu n ica ti on s c arri er s E nh anc em en t of c li ent know-how Service vendors (Security services and vendors and
eneral electronics vendors)
Policy formulation services Inspection and auditing services Design and construction services Operation and management
services Monitoring services Authentication services Education and training services
Operational tie-ups
OEM, product supply, technical support, etc.
Service cooperation and tie-ups
Product supply
Tie-ups
Tie-ups
Expansion of business opportunities by approaching users proactively and carrying out educational activities that leverage the strengths of each enterprise
End users: Public bodies and municipalities, and companies in manufacturing, finance, retail and services Tool and equipment vendors
Authentication products Filtering software Encryption products
Anti-virus tools Log analysis tools
Firewalls/VPN Security inspection tools Integrated appliance products
Dealers
Differentiation of products and services, solutions service support, specialized security know-how and assimilation of user needs. Overseas vendors
Domestic vendors
after-sales activities. In addition, the increased burden on users has created greater demand, another factor that has encouraged vendors to shift to services.
In the service vendor sector of the market, companies no longer focus simply on the provision of services, but also on the construction of security facilities. Some companies are also transforming themselves into managed security service providers (MSSP) to offer services ranging from equipment upgrades to operations monitoring and damage assessment. Meanwhile, security services are being diversified. For example, services are being tailored to specific customers, such as those who had hesitated to use security services due to high costs.
Management consulting firms are also making significant inroads into the information security market, targeting major enterprises and public agencies. While their overall business volume is low, these firms can serve as prime contractors to offer integrated services for all levels, from upstream to downstream processes.
System integrators that design and construct secure environments have benefited from the recent tendency to view systems as networks. They are enhancing their provision of secure system-integration services to distinguish themselves from other vendors.
The above trends illustrate the brisk efforts companies are making to develop value-added security tools and equipment, and to diversify services. In the future, however, security vendors are expected to increasingly tie up with other companies to leverage mutual strengths in order to respond to increasing security needs in the market.
3. Market Trends
A. Rapid expansion
Japan's information security market was estimated at 222.6 billion yen in 2003. Security services produced sales of 48.6 billion yen and security products 174.0 billion yen, so products accounted for more than 70% of the overall market.
As the dependence on networks rises, so has the burden to ensure information security on the network user side, because it has become increasingly difficult for users to implement and manage security measures on their own. This is why managed security and related services are in greater demand than ever before. The market expanded fivefold between 2000 and 2004 and should account for an increasingly larger portion of the overall information security market in the future.
Looking at specific segments of security services in 2003, security assessment, planning and education produced sales of 17.0 billion yen, illegal-access monitoring 6.8 billion yen, virus monitoring 9.2 billion yen, firewall operation and
Fig. 5 Changes in Information Security Market Scale, by Category
Notes
1. Security inspection, formulation and education services did not include education prior to 2002.
2. Firewall, VPN and integrated equipment products did not include integrated equipment prior to 2002.
Source: Fuji Kimera Research Institute, "Comprehensive Survey of the Network Security Business" (billion yen) Fiscal year 2000 2001 2002 2003 2004 (estimate) 3.8 5.3 6.9 17.0 25.6 1.4 3.0 5.3 6.8 13.0 0.6 2.1 5.0 9.2 14.0 1.0 2.5 4.5 7.2 12.0 3.0 2.0 4.5 8.4 13.0 9.8 14.9 26.2 48.6 77.6 8.9 11.8 17.7 20.3 25.1 2.1 3.1 3.9 7.3 13.9 24.8 51.5 72.7 68.1 74.4 6.4 11.5 14.5 21.1 26.6 18.1 27.7 36.0 47.3 60.0 2.6 4.6 7.4 10.0 12.9 62.9 110.2 152.2 174.0 212.8 72.7 125.1 178.4 222.6 290.4 Service or product
Security inspection, policy formulation and education services
Se cu ri ty s er vices Subtotal Filtering software Tital
Illegal access monitoring services
Authentication products
Encryption products Firewall, VPN and integrated equipment products Virus monitoring services
Firewall operation and management services
Electronic authentication services
Subtotal
Security inspection, monitoring and analysis tools
Anti-virus tools Secur ity pr od uct s
management 7.2 billion yen, and electronic authentication 8.4 billion yen.
Security assessment, planning and education have generated a large amount of business because an increasing number of users are outsourcing this work to service vendors, consulting firms and other such companies. In addition, more users are taking advantage of education services to raise employee awareness of security needs. What’s more, increases in general workload are prompting managers to outsource security services to free up company resources to concentrate on core operations, which has helped to stimulate business throughout the security services market, including firewall and virus-monitoring services.
Yet another factor behind the rise of security services is that manufacturers and vendors are addressing customers needs more carefully than before. For example, they have begun shifting from conventional sell-and-forget models to practices that facilitate the provision of not only products, but also operation and management services.
Going forward, the provision of security assessment, planning and education services is expected to shift from an irregular to regular basis. Other factors that should help to expand the market include the diversification of operation and management services, the establishment of service menus and the reduction of prices as more businesses enter the market.
B. Stable growth expected for security products
Sales in the security product market in 2003 included authentication products worth 20.3 billion yen, encryption products 7.3 billion yen, firewall, VPN and integrated-equipment products 68.1 billion yen, security inspection, monitoring and analysis tools 21.1 billion yen, anti-virus tools 47.3 billion yen and filtering software 10.0 billion yen. Firewall, VPN and integrated-equipment products and anti-virus tools were introduced over an increasingly wide range of companies, from major enterprises to small firms and SOHOs, enabling them to become a driving force in the market. Both segments were expected to realize stable growth from 2004 onward, due to customer demand for new products and version upgrades.
Among firewall and VPN equipment, sales of integrated products that combine anti-virus, IDS/IPS, filtering and other functions have started to become noticeable in the mid to low-end model range. These products offer a variety of security functions in a single package, helping to simplify operations and management. They are especially popular with small and midsize enterprises and other users that do not have security engineers. The division of firewall and VPN products into two distinct segments, one for higher-end models offering high-performance firewall and VPN functions and the other offering mid to low-end models with integrated functions, should continue in the foreseeable future.
C. Further growth expected for internal security products
Public agencies and major enterprises have for the most part augmented measures against external threats such as firewalls, anti-virus measures and prevention of illegal access, and efforts since 2003 have
Fig. 6 Security Service and Product Weightings
Security services, worth 48.6 billion yen in 2003
Security products, worth 174.0 billion yen in 2003
Source: Fuji Kimera Research Institute Electronic authentication services 17% Firewall operation and management services 15% Virus monitoring services 19% Illegal access monitoring services 14% Security inspection, formulation and education services 35% Authentication related products 12%
Encry ption products 4% Firewall, VPN and integrated appliance related products 39% Security inspection, monitoring and analy sis tools
12% Anti-virus tools
27%
Filtering software 6%
focused on strengthening internal security measures. The market for internal security products, especially authentication and encryption products, has shown remarkable growth since 2004, in large part due to the Personal Data Protection Law that took full effect in April 2005, and also heightened awareness in the wake of the much-publicized information leaks.
Among authentication products, demand is expanding for biometrics and IC cards used for applications such as entry and exit control. In addition, demand for single sign-on products used in access control to prevent information leaks is also bolstering the market. The market for encryption products is growing in fields of information leak prevention and system administration applications to manage information output, prevent information smuggling and monitor for unauthorized terminals.
Filtering software was originally introduced as a tool for restricting access to harmful websites with computers at locations such as elementary and junior high schools. Enterprises also use filtering software to prevent employees from using their office computers for personal matters, as well as to improve the operational efficiency and to regulate traffic. More recently, the market has been further expanded with the introduction of leak-prevention tools to reinforce client PC management functions and block illegal applications and improper usage of networks.
Needs are increasing for defenses against new security threats and strengthened internal security systems. In addition, manufacturers and vendors are actively developing both hardware that integrates various security functions and software for security tools. As a result, the introduction of security products across a wide range of user sectors, from major enterprises to small companies and SOHOs will continue to expand the security product market.
4. Domestic vs. Foreign Firms in Individual Markets
Japan's security services market is served mostly by domestic firms, except for certain foreign-affiliated services such as ISS's intrusion detection/defense service and VeriSign Japan's authentication service. Domestic vendors have an advantage over foreign rivals due to their greater familiarity with the business practices and network characteristics of specific industries. But the security products, tools and other items used for these services are not limited to those of domestic manufacturers, and in many cases foreign products that have set the de facto global standards are used. For example, firewall services are provided with products of globally respected brands, such as NetScreen (Juniper Networks) and FIREWALL-1 (NOKIA), which has helped these services acquire users. Service vendors are attempting to distinguish themselves by using security products with high name recognition, which has led to collaborative relationships with well-known security vendors overseas.
Overseas manufacturers and vendors' products have been widely introduced throughout Japan and are thought to have accounted for roughly half of the domestic market in 2003, according to Fuji Kimera Research Institute. Overseas products accounted for high shares of the markets for one-time password and single sign-on products, firewall and VPN devices, inspection and monitoring tools, log analysis tools and so on.
Many users specify products based on perceptions of trust and reliability associated with products that are globally well known name and have proven records. As a result, foreign manufacturers account for 80% or more of the Japanese marketing in the five categories noted in the table above.
Fig. 7 Japanese Market Share of Selected Overseas Manufacturers (FY 2003 estimates)
Source: Fuji Kimera Research Institute, "Comprehensive Survey of the Network Security Business"
Approx. 90% 2.5 bil. yen
Approx. 90% 4.0 bil. yen Approx. 88% 32.6 bil. yen
Approx. 90% 10.9 bil. yen
Approx. 95% 2.4 bil. yen
Manufacturer / vendor RSA Security, Secure Computing, etc. One-time passwords
Product Share and sales
Entrust, IBM, HP, RSA Security, etc. Juniper Networks, NOKIA, Cisco Systems, etc.
ISS, Symantec, Cisco Systems, etc.
NetIQ, etc. Single sign-on products
Firewall and VPN equipment
Inspection and monitoring tools
5. Corporate Tie-ups among Major Enterprises
Examples of corporate tie-ups between major domestic and overseas vendors are shown below.
Internet Security Systems, Inc.
Pr of es si onal s er vi ves Product supply Product supply Product supply 100% capitalized 100% capitalized 100% capitalized Internet Security Systems, Inc.
TriSecurity Holdings Pte Ltd. (Singapore) Internet Security Systems, Inc. (Delaware, U.S.)
ISS Investment Holdings, Inc. (Georgia, U.S.)
Internet Security Systems Pte Ltd. (Singapore)
Internet Security Systems BTY Limited (Queensland, Australia)
Master distributors
Resellers
Asia-Pacific region users
End users 100% capitalized 100% capitalized 87.7% capitalized Product supply Itochu TechnoScience NTT Communications NBS OGIS-RI Sakura Kcs SOFTBANK BB Daiko Denshi Tsushin TIS TechMatrix Toshiba Solutions NEC Hitachi Yokogawa Denki LAC
Trinity Security Systems IBM Applications Japan NEC System Integration & Construction
Master distributors
IT4
Daiko Denshi Tsushin NEC Nokia Japan Yokogawa Denki Alliance partners ip.net Itochu TechnoScience NTT Communications NEC Fielding Hitachi Electronics Services C & W IDC Japan Telecom NEC System Integration & Construction
MSS partners
Resellers and partners ISS Inc. (Georgia, U.S.)
Trend Micro Tre nd M icr o In di vi du al us er s C or por at e us er s
Check Point Software Technologies Syscon Systems
Citrix Fujitsu Hitachi
Internet Security Systems Microsoft HP IBM Japan NEC Oracle Sun Microsystems Lucent Technologies Turbolinux Nokia Twin Sun Global
16 companies including: Itochu TechnoScience 10art-ni SOFTBANK BB
InterScan master resellers
CIC Fujitsu Marubeni Solutions <erverProtectforNetApp master resellers 9 companies including: SECOM Trust.net CSK Network Systems HP Japan Nippon Jimuki
Premium security partners
SOFTBANK BB Catena Computer Wave Networld Distributors Business partner SI Otsuka Shokai SOFTBANK BB SECOM Trust.net PFU SLMD
More than 20 companies including: NTT Communications Nifty IIJ hi-ho SSP Volume retailers, t Technical alliances NetStar
URL filtering technology and database OEM supply
eDoctor service InterScan VirusWall ServerProtect for NetApp Client/server products
Local ISP and cable TV operators
Local municipalities, etc.
Fujitsu Social Science Laboratories
Fujitsu Security Solutions NPO 日本ネットワークセキュリティ協会( JNSA) NPO 日本セキュリティ 監査協会(JASA) 富士通 SSL PoweredSolution Powered OpenNetwork Security Solutions Technical tie-ups Products and services
Products Fujitsu Fujitsu Group corporations Fujitsu 加盟団体 営業本部 ネットワークシステム事業部 Fujitsu SSL End users Membership activities
Fujitsu Group corporations Outsourcing Division Security Service and Support Division Affiliated organizations Sales Division Network Systems Division Solutions partners
• Check Point Software Technologies • Juniper Networks • Clestix • Nokia • Cisco Systems • F5 Networks Firewall/VPN
NPO Japan Network Security Association (JNSA) NPO Japan Information Security Audit Association
(JASA) Security vendors ・ Trend Micro ・ TopLayer ネットエージェント KaVaDo
Inspection and monitoring • ISS
• NetAgent • KaVaDo
DoS/DDoS measures • TopLayer
Virus and spam measures • Trend Micro • Sendmail TopLayer ネットエージェント KaVaDo Authentication products • RSA Security • Aladdin • CSE Encryption Filtering • Websense
• Canon System Solutions • RSA Security
• Control Break international
Partners
Macnica Networks Tokyo Electron Axent
Hitachi Limited NTT Communications ・ ・ End us er s Consulting services Information sharing Product procurement • Verisign • Check Poinr • RSA Security • Symantec • Trend Micro, etc.
Security vendors SECOM SECOM Trust.net Product procurement Cooperation Comprehensive tie-up Hitachi Limited S ys te m i ntegrat io n an d sales fo r sp ec if ic i nd us trie s
System integration and system development
System integration Cooperation Se co nda ry sh ops
Syscon Systems Cooperation
Se cu ri ty S ol ut ion Pr om ot ion D ivi si on H itac hi G ro up N T T Co mmu nic ation s • Computer Associates • ISS • Trend Micro • Baltimore Technologies Japan • Yokogawa Denki Security vendors E nd us er s
Product supply and technology sharing • SECOM Trust.net. Tie-up in IC card solutions field • NEC • TIS
• Seiko Instruments authentication businessTie-up in electronic
Security Operation Centers
Customer Service Centers
Customer Network Service Center
Cooperation
Solution Business Division IP Integration Division IT Management Services Division Broadband IP Services Division Advanced IP Architecture Center Other divisions
• NTT Group
R&D, personnel exchange
SIer
Cooperation
• Cisco Systems
Provision of technology and product information
6. Current Topics
• Increased demand due to Personal Data Protection Law
New compliance requirements under the Personal Data Protection Law have stimulated demand for information security business since the second half of fiscal 2003, when users began preparing for the law’s complete implementation in April 2005. The demand for acquisition of the Privacy Mark and ISMS/BS7799 certification has increased rapidly in response to the law. Privacy Mark acquisition or ISMS/BS7799 certification is becoming an prerequisite for enterprises that handle personal data. While major enterprises have taken the lead, an increasing number of smaller firms are also aiming to acquire certification. The demand for acquisition/certification services should increase. In addition, enterprises that acquire certification should create demand for new services, such as reinforced security education.
• Consortium for leak-prevention solutions
The increasing complexity and diversity of information security needs has made it difficult for individual companies to offer business models that can satisfy all user needs. In response, the nine companies of Hitachi Software Engineering, RSA Security, Motex, Otsuka Shokai, Quality Corporation, Sompo Japan Insurance, Citrix Systems Japan, Trend Micro and Microsoft formed a consortium to meet the demands for concrete measures offering optimum products and integrated solutions. Through the consortium, the participants will combine products and services for comprehensive solutions that meet diverse needs. International alliances such as these are expected to accelerate as security needs further diversify, offering users more flexibility and thereby creating additional new demand.
Security terminology
Firewall/VPN devices: Dedicated hardware equipped with firewall and VPN functions.
VPN: Virtual private networks enable highly secure communication by establishing connections similar
to dedicated lines, but via the Internet.
Authentication: The process of confirming the access rights and identity of a computer user.
Single sign-on product: A system that allows a user to access all permitted functions and servers after a single act of authentication, i.e., a password.
Access control: Measures and policies for determining a user’s information access rights and controlling the information and applications they access.
Biometrics: Authentication system for confirming identity using fingerprints, veins, retinal and other unique biological characteristics instead of passwords, etc.
IDS/IPS: Intrusion detection systems detect and announce illegal intrusions into computers or networks, while intrusion protection systems not only detect intrusions but attempt to block them.
Filtering: Forwarding only that data which meets specific conditions or does not clash with restrictions, such as web filtering to prohibit access to specific websites and e-mail filtering to automatically sort, forward or block specific types of e-mail.
Personal Data Protection Law: A Japanese law fully implemented in April 2005 to establish the fundamental ideas and principles of personal data protection in the public and private sectors and also to stipulate the responsibilities for preventing personal data leaks and handling data by constructing reliable information-protection systems. The law applies to private enterprises and other entities that handle retrievable personal data on 5,000 or more customers, etc.
Note: This report was prepared by the Japan External Trade Organization (JETRO) based on a survey commissioned to the Fuji Kimera Research Institute.