Redesigning security through white-hat hacking
Unlocking cyber resilience for sustainable growth
Article| 2025-12-17
12 minute read
“If you think you haven’t been hit by a cyberattack yet, chances are you just haven’t noticed.”
As data and AI become core sources of competitive advantage, cybersecurity has now emerged as a central management priority. Cyberattacks are evolving at a speed and level of sophistication that exceed our imagination, and the misuse of AI continues to generate new types of threats. Under such conditions, relying on conventional, incremental approaches makes it extremely difficult to fully protect corporate assets, trust, and long-term growth.
So how should these companies redesign their security? Much like a medical health check, gaining an objective, outside-in assessment to understand where they stand today and chart a realistic path toward where they need to be tomorrow can benefit any organization. The purpose of redesigning security is not simply to shield systems from attacks, but to strengthen “cyber resilience”: the ability to maintain business continuity and recover quickly, on the assumption that intrusions will occur.
This article is based on insights gained through experience conducting white-hat hacking engagements for more than 200 Japanese companies before joining Uvance Wayfinders. These experiences inform an overview of the current state of Japanese enterprises, countermeasures for each phase of a cyberattack, approaches to effective security investment, and security governance for global operations. I hope this will provide insights that help organizations protect their future and open the door to sustainable growth.
Section 1: Closing critical security gaps
The more businesses harness data and AI, the more they face a paradox: innovation amplifies exposure to cyber risk. As system integration expands across business units and external partners, not only does the likelihood of attack grow, but the potential damage also becomes more severe. Given the new challenges of the AI era, companies must look beyond traditional protection and build organizations capable of withstanding and recovering from disruption.
What it comes down to is this: attackers routinely use AI, so defenders must also fight back with AI. Malicious AI-driven attacks such as phishing, malware creation and manipulation, and internal data harvesting, are becoming broader, more precise, and more sophisticated. Once inside, AI can instantly search millions of files and locate passwords with ease.
To counter these evolving threats, AI for security monitoring, detection, incident response, and threat hunting is becoming increasingly important. At the same time, organizations must reinforce their systems and training on the assumption that intrusions will occur.
Specifically, there are several foundational measures to take, which include implementing a CSF (Cybersecurity Framework), deploying solutions like EDR (Endpoint Detection and Response), conducting vulnerability assessments, and establishing SOC (Security Operations Center) and CSIRT (Computer Security Incident Response Team) for 24/7 monitoring. On top of these, organizations must layer AI-driven defenses through holistic redesign to keep pace with adversaries who are already automating their attacks (See Figure 1).

Source: Fujitsu





