Where Should SMEs Start on Security? — A Walkthrough of IPA's 'Information Security Guidelines for SMEs,' 4th Edition
· Go Komura · Information Security, Security Measures, SME, IPA, SECURITY ACTION, Ransomware, Backup, Business Improvement, B2B
“A client sent us a security checklist, but we don’t know what we’re supposed to do or how far to go.”
“We know security matters, but we can’t afford to put someone in charge of it full-time.”
“They tell us to take measures, but we have no idea what it would cost, so we haven’t touched it.”
Security consultations from small and medium-sized businesses almost always start out this way.
As it happens, there’s an official handbook that answers exactly this “where, and how far” question: IPA’s (the Information-technology Promotion Agency’s) Information Security Guidelines for Small and Medium Enterprises. On March 27, 2026, IPA published its 4.0 edition — the first major revision in roughly three years.
This article draws on the content of the 4.0 edition to lay out, in order, how a company with no dedicated security staffer should proceed with security measures.
1. The Bottom Line First
Here’s the approach the 4.0 edition lays out, up front.
- The first step isn’t buying expensive products — it’s the “Six Articles of Information Security,” the basic measures every company must implement regardless of size, and none of them require a large budget
- Next, use the appendix’s “5-Minute Information Security Self-Assessment” (25 items) to understand your current state, and improve starting from the items you haven’t yet covered
- Once you’ve started, self-declare through IPA’s “SECURITY ACTION” (free of charge) — it gives you something to show clients and is also a requirement for some public support programs
- From there, move step by step into drafting a basic policy, putting internal rules in place, and building an incident-response structure
- Business owners have roles they can’t simply hand off to staff — such as “drive the effort with leadership” and “account for the security of outsourced vendors, too”
In a word, this guideline’s design philosophy is: don’t aim for perfection all at once — go in a set order, step by step, starting with whatever you can.
2. What Is the “Information Security Guidelines for Small and Medium Enterprises”?
This guideline is a document that lays out the thinking and procedures for protecting a small or medium-sized business’s important information from threats such as leaks, tampering, and loss, and for preventing damage to business continuity. First published in November 2016, it has since become the de facto standard for SME-oriented security measures. Sole proprietors and micro-businesses are included as well.
It’s broadly divided into three parts.
| Part | Intended audience | Content |
|---|---|---|
| Part 1: For Business Owners | Business owners | The downsides of neglecting security, the responsibilities business owners bear, three principles to keep in mind, and seven key actions to take |
| Part 2: In Practice | Managers and staff | The step-by-step practical approach, from the Six Articles of Information Security up through full-scale measures |
| Appendices 1-8 | Practitioners | A self-assessment sheet, sample basic policy / regulations / asset ledger, guides to cloud usage and incident response, and more |
The main body runs about 70 pages, but as covered below, there’s no need to read it cover to cover from the start. It’s built so you can start using it wherever fits your company’s current stage.
What changed in the 4.0 edition
The revision to the 4.0 edition cites three environmental changes since the 3.1 edition (April 2023):
- Ransomware damage has spread beyond information leaks to full business-activity shutdowns
- Supply-chain-mediated damage has spread both domestically and abroad, raising the need for measures across the entire trading network
- There is a marked shortage of people inside SMEs who can drive security measures forward
In response, the guideline expanded the “Five Articles of Information Security” into six by adding “take backups,” reorganized its organizational and technical countermeasures in light of the SCS evaluation system (a security assessment system for supply chain reinforcement) being developed by the Ministry of Economy, Trade and Industry and the Cabinet Secretariat’s National Center of Incident Readiness and Strategy for Cybersecurity, and added a practical guidebook (Appendix 1) to support securing and developing security personnel.
The two pillars of this revision — “backups” and “supply chain” — mirror exactly the threats SMEs face today. Ransomware and attacks routed through business partners have each ranked near the top of IPA’s annual “10 Major Threats in Information Security” (organizational edition) for 11 and 8 consecutive years, respectively. (See our article on the 10 Major Threats 2026 for details.)
3. For Business Owners — Security Isn’t “The Staff’s Job”
Part 1, for business owners, barely touches on technology. What it covers instead is what you stand to lose by neglecting security (business disruption, loss of trust, damages), what legal responsibilities a business owner bears (safety-management measures under the Act on the Protection of Personal Information, the duty of loyalty under the Companies Act, and so on), and what business owners themselves should be doing.
The three principles business owners are told to keep in mind are:
- Drive information security measures forward with the business owner’s own leadership
- Account for the information security measures of outsourced vendors as well
- Maintain constant communication about information security with everyone involved
Building on that, the guideline lays out “seven key actions” business owners should take: setting an organization-wide response policy, securing budget and personnel, having necessary measures examined and instructing that they be carried out, instructing periodic review of those measures, building a structure for emergency response and recovery, clarifying security responsibilities when outsourcing or using external services, and staying current on the latest trends.
From the front line, security measures tend to look like an inconvenient hassle that reduces convenience. That’s exactly why “the business owner judges, decides, and leads” is placed as the very first principle. This guideline’s consistent stance is that simply telling a staffer to “handle it somehow” doesn’t work.
4. The Practical Section — Proceeding in Three Stages
Part 2, the practical section, is structured in stages: “start with what you can” → “begin organizational efforts” → “take it on in earnest.”
Stage 1: Start with what you can
Implement the Six Articles of Information Security
↓
Stage 2: Begin organizational efforts
Draft an information security basic policy and communicate it
Assess your current state with the "5-Minute Self-Assessment" (25 items)
Decide which measures aren't yet in place and communicate that
↓
Stage 3: Take it on in earnest
Draft regulations, manage assets, defend against and detect attacks,
inspect and improve, build incident-response structure, manage business partners
↓
Further: Measures to strengthen things even more
Risk analysis, measures for websites, cloud, and telework
What matters is that Stages 1 and 2 require almost no special knowledge and almost no budget. Rather than “we can’t do anything without budget,” it’s designed so that “even without a budget, you can start this much today.”
5. The Six Articles of Information Security — What the First Step Actually Involves
Stage 1’s “Six Articles of Information Security” are the basic measures every company must implement regardless of its size.
| Article | What to do | |
|---|---|---|
| 1 | Keep the OS and software always up to date! | Apply patches, or use the latest version. Leaving things outdated invites attacks on already-fixed weaknesses |
| 2 | Install antivirus software! | Install it, and keep the virus definition files always up to date |
| 3 | Strengthen your passwords! | “Long,” “complex,” “never reused.” Prevents unauthorized logins from misuse of leaked IDs and passwords |
| 4 | Review your sharing settings! | Check the settings of cloud services and networked multifunction printers, and eliminate any state where unrelated people can view them |
| 5 | Take backups! | Make sure the business can continue even if data is lost or encrypted due to failure, operator error, or virus infection |
| 6 | Know the threats and attack techniques! | Attack techniques change every year. Stay informed through the latest updates from IPA and others, and prepare so you don’t get fooled |
For the fifth item, “backups,” added in the 4.0 edition, the guideline specifies operating it as a set of three: acquisition (decide the scope and interval), storage (decide the location, generation management, and retention period), and recovery (build a plan and confirm you can actually restore correctly). It only counts as a real measure once you also keep the backup disconnected from the production environment, so it isn’t encrypted along with the original data by ransomware, and confirm recovery so you avoid the trap of “we thought we had a backup, but it turns out we can’t restore from it.”
Every one of these items looks obvious once it’s written down. But most real-world damage happens precisely where this obvious stuff wasn’t followed through. Thoroughly enforcing these six items company-wide, under the business owner’s top-down leadership, is the starting point.
6. The 5-Minute Self-Assessment, and Organizational Efforts from Stage Two Onward
The centerpiece of Stage 2 is Appendix 3, the “5-Minute Information Security Self-Assessment.” Just answering 25 questions with “in place / partially in place / not in place / don’t know” makes your company’s current state and weak points visible.
The 4.0 edition revised the example countermeasures in the assessment, adding items reflecting recent intrusion routes, such as “block unnecessary communication from outside into the internal network” and “operate your website securely.” Intrusions exploiting weaknesses in VPN equipment, and tampering with neglected websites, are routes through which SMEs have continued to suffer real damage. (Website-side measures are covered in detail in a separate article, “How to Use IPA’s ‘How to Secure Your Website’”.)
The assessment’s result isn’t meant to be a score you compete on. Use it as material for prioritization: among the items not yet in place, fix the ones that carry the greatest risk for your own business first.
7. SECURITY ACTION — A Free Program for Making Your Efforts Visible
Once you’ve started, it’s worth also using SECURITY ACTION alongside it. It’s a program where SMEs self-declare that they’re working on information security measures, letting them use “one-star” or “two-star” logo marks free of charge according to how far along they are.
| What the declaration means | |
|---|---|
| ★ One star | Declares that the company is working on the Six Articles of Information Security |
| ★★ Two stars | Declares that, after assessing the company’s own situation with the “5-Minute Self-Assessment,” it has established and publicly posted an information security basic policy (a sample is in Appendix 2), and is working on measures |
Since it’s a self-declaration, there’s no review process — which also means you can start right away. Displaying the logo on business cards or your website gives you something to show clients, and the declaration is sometimes required to apply for public support programs such as the IT Introduction Subsidy.
For a company that’s just received a security checklist from a client and isn’t sure what to do, being able to say “we’re working from the guideline’s six articles and self-assessment, and we’ve declared SECURITY ACTION” is a realistic and honest first step.
8. The Appendices Double as a “Template Library”
It’s fair to say much of this guideline’s practical value lies in its appendices. The 4.0 edition comes with the following eight, all downloadable free of charge from IPA’s page.
- Appendix 1: Practical Guidebook for Securing and Developing SME Security Personnel (newly added in the 4.0 edition)
- Appendix 2: Information Security Basic Policy (sample)
- Appendix 3: 5-Minute Information Security Self-Assessment
- Appendix 4: Information Security Handbook (template)
- Appendix 5: Information Security-Related Regulations (sample)
- Appendix 6: Asset Management Ledger (sample)
- Appendix 7: Guide to Safe Use of Cloud Services for SMEs
- Appendix 8: Guide to Security Incident Response for SMEs
You don’t need to write the basic policy, the regulations, or the asset ledger from scratch — the design assumes you’ll adapt the samples to your own company. If your company is stuck on getting internal rules in place, starting with Appendix 2 and Appendix 5 will move things along faster.
Closer to day-to-day operations, individual topics such as reviewing password-protected ZIP files sent by email — so-called PPAP (“Why PPAP Is a Bad Idea”) — and preventing information leaks from PCs being disposed of (“A Checklist Before Disposing of a Windows PC”) are continuous with the thinking behind this guideline.
Summary
Here are the key points of IPA’s “Information Security Guidelines for Small and Medium Enterprises,” 4.0 edition.
- Published March 27, 2026. A revision reflecting environmental changes: business disruption from ransomware, supply-chain-mediated damage, and a shortage of personnel
- The approach is staged: start with the Six Articles of Information Security, then the 25-item self-assessment, then build out policy, regulations, and structure
- The six articles now include “take backups!” — a real backup covers acquisition, storage, and confirmed recovery
- Business owners have three principles and seven key actions of their own, so the effort isn’t left entirely to staff
- Self-declaring through SECURITY ACTION (free) makes your efforts visible and is also a requirement for some public support programs
- The eight appendices work as a ready-to-use template library for daily practice
The biggest obstacle to security measures is not knowing what to do — and that part is exactly what an official guideline has already answered for you. What’s left is applying it to your own environment and actually carrying it out.
For Those Struggling to Apply This to Their Own Environment
Plenty of companies, when they try to carry out the six articles’ “keep the OS and software up to date,” run straight into the wall of “our old business application can’t be updated because it won’t run on a newer OS.” Likewise, the order in which to fix issues found in the self-assessment depends on the configuration of your business systems.
Drawing on our experience developing and maintaining Windows business applications and web systems, Komura Software LLC takes on consultations about modifying existing software that’s blocking an update, and about prioritizing countermeasures. Even at the stage of “we ran the assessment, but from here it turns into a technical conversation we can’t move forward on,” we welcome a consultation starting from confirming your current state.
Related Articles
Recent articles sharing the same tags. Deepen your understanding with closely related topics.
Information Security 10 Major Threats 2026 — How to Read the Ranking, and What SMEs Should Actually Guard Against
In IPA's 'Information Security 10 Major Threats 2026,' ransomware attacks took first place for the 11th year running, supply chain attack...
What Website Clients Should Know Too — Using IPA's 'How to Secure Your Website' as a Checklist
What standard should you use to check your company website's security against? This article explains the 11 vulnerabilities and counterme...
Don't Forget to Decide 'How Many Seconds Is Fast Enough' — Organizing Non-Functional Requirements With IPA's Non-Functional Requirements Grade
Disputes like 'it's too slow' or 'we didn't expect that failure response' usually trace back to non-functional requirements nobody decide...
How Should You Structure a Contract Development or Operations & Maintenance Contract? — Learning the Quasi-Mandate vs. Contract-for-Work Distinction from IPA's 'Model Contract'
When you outsource system development, how should the contract be structured? Drawing on the 'Information System Model Transaction and Co...
Website Development Costs for SMEs — A Quick-Reference Price Guide and How to Read a Quote
What SMEs should know before requesting a website development quote: price guides broken down by purpose and scale, how to read the line ...
Related Topics
These topic pages place the article in a broader service and decision context.
Windows Technical Topics
Topic hub for KomuraSoft LLC's Windows development, investigation, and legacy-asset articles.
Where This Topic Connects
This article connects naturally to the following service pages.
Technical Consulting & Design Review
Deciding what order to fix issues found in the self-assessment, and identifying where the risk actually sits in your business systems or network configuration, falls squarely within technical consulting that includes design review.
Windows Software Maintenance & Modernization
Actually carrying out 'keep the OS and software up to date' often requires modifying and maintaining the business application that's the reason an old Windows machine or piece of software can't be updated in the first place.
Frequently Asked Questions
Common questions about the topic of this article.
- What are the Six Articles of Information Security?
- These are the basic measures that IPA's 'Information Security Guidelines for Small and Medium Enterprises,' 4th edition, says every company must implement regardless of size. They are: (1) always keep the OS and software up to date, (2) install antivirus software, (3) strengthen passwords, (4) review sharing settings, (5) take backups, and (6) know the threats and attack techniques in use. Through the 3.1 edition this was five articles; the sixth, 'take backups,' was added in light of the growing damage from ransomware.
- What's the difference between SECURITY ACTION's one star and two stars?
- One star is a self-declaration that the company is working on the Six Articles of Information Security, and any company just starting out on security can declare it right away. Two stars means the company has assessed its own situation using the guideline's appendix, the '5-Minute Information Security Self-Assessment,' and has established and publicly posted an 'Information Security Basic Policy,' declaring that it is working on countermeasures. Both are self-declarations to IPA and cost nothing.
- A company with no dedicated IT staff — where should it start?
- The guideline's practical section is structured around 'start with what you can.' It lays out the order as: first, implement the Six Articles of Information Security under the business owner's top-down leadership; next, use the 25 items in Appendix 3, the '5-Minute Information Security Self-Assessment,' to understand the current state; and then improve starting from the items that aren't yet in place. Neither the six articles nor the self-assessment requires specialized knowledge or a large budget.
- What changed between the 3.1 edition and the 4.0 edition?
- The 4.0 edition, published on March 27, 2026, reflects a set of environmental changes: business disruption caused by ransomware damage, the spreading impact of supply-chain-mediated attacks, and a shortage of security personnel. Specifically, it expands the 'Five Articles of Information Security' into six by adding 'take backups,' reorganizes countermeasures in light of the SCS evaluation system (a security assessment system for supply chain reinforcement) being developed by the Ministry of Economy, Trade and Industry and others, and adds a practical guidebook appendix to support securing and developing security personnel.
Author Profile
Profile page for the article author.
Go Komura
Representative of KomuraSoft LLC
Focused on Windows software development, technical consulting, and investigations into failures that are difficult to reproduce.
Public links