Where Should SMEs Start on Security? — A Walkthrough of IPA's 'Information Security Guidelines for SMEs,' 4th Edition

· · Information Security, Security Measures, SME, IPA, SECURITY ACTION, Ransomware, Backup, Business Improvement, B2B

“A client sent us a security checklist, but we don’t know what we’re supposed to do or how far to go.”

“We know security matters, but we can’t afford to put someone in charge of it full-time.”

“They tell us to take measures, but we have no idea what it would cost, so we haven’t touched it.”

Security consultations from small and medium-sized businesses almost always start out this way.

As it happens, there’s an official handbook that answers exactly this “where, and how far” question: IPA’s (the Information-technology Promotion Agency’s) Information Security Guidelines for Small and Medium Enterprises. On March 27, 2026, IPA published its 4.0 edition — the first major revision in roughly three years.

This article draws on the content of the 4.0 edition to lay out, in order, how a company with no dedicated security staffer should proceed with security measures.

1. The Bottom Line First

Here’s the approach the 4.0 edition lays out, up front.

  • The first step isn’t buying expensive products — it’s the “Six Articles of Information Security,” the basic measures every company must implement regardless of size, and none of them require a large budget
  • Next, use the appendix’s “5-Minute Information Security Self-Assessment” (25 items) to understand your current state, and improve starting from the items you haven’t yet covered
  • Once you’ve started, self-declare through IPA’s “SECURITY ACTION” (free of charge) — it gives you something to show clients and is also a requirement for some public support programs
  • From there, move step by step into drafting a basic policy, putting internal rules in place, and building an incident-response structure
  • Business owners have roles they can’t simply hand off to staff — such as “drive the effort with leadership” and “account for the security of outsourced vendors, too”

In a word, this guideline’s design philosophy is: don’t aim for perfection all at once — go in a set order, step by step, starting with whatever you can.

2. What Is the “Information Security Guidelines for Small and Medium Enterprises”?

This guideline is a document that lays out the thinking and procedures for protecting a small or medium-sized business’s important information from threats such as leaks, tampering, and loss, and for preventing damage to business continuity. First published in November 2016, it has since become the de facto standard for SME-oriented security measures. Sole proprietors and micro-businesses are included as well.

It’s broadly divided into three parts.

Part Intended audience Content
Part 1: For Business Owners Business owners The downsides of neglecting security, the responsibilities business owners bear, three principles to keep in mind, and seven key actions to take
Part 2: In Practice Managers and staff The step-by-step practical approach, from the Six Articles of Information Security up through full-scale measures
Appendices 1-8 Practitioners A self-assessment sheet, sample basic policy / regulations / asset ledger, guides to cloud usage and incident response, and more

The main body runs about 70 pages, but as covered below, there’s no need to read it cover to cover from the start. It’s built so you can start using it wherever fits your company’s current stage.

What changed in the 4.0 edition

The revision to the 4.0 edition cites three environmental changes since the 3.1 edition (April 2023):

  • Ransomware damage has spread beyond information leaks to full business-activity shutdowns
  • Supply-chain-mediated damage has spread both domestically and abroad, raising the need for measures across the entire trading network
  • There is a marked shortage of people inside SMEs who can drive security measures forward

In response, the guideline expanded the “Five Articles of Information Security” into six by adding “take backups,” reorganized its organizational and technical countermeasures in light of the SCS evaluation system (a security assessment system for supply chain reinforcement) being developed by the Ministry of Economy, Trade and Industry and the Cabinet Secretariat’s National Center of Incident Readiness and Strategy for Cybersecurity, and added a practical guidebook (Appendix 1) to support securing and developing security personnel.

The two pillars of this revision — “backups” and “supply chain” — mirror exactly the threats SMEs face today. Ransomware and attacks routed through business partners have each ranked near the top of IPA’s annual “10 Major Threats in Information Security” (organizational edition) for 11 and 8 consecutive years, respectively. (See our article on the 10 Major Threats 2026 for details.)

3. For Business Owners — Security Isn’t “The Staff’s Job”

Part 1, for business owners, barely touches on technology. What it covers instead is what you stand to lose by neglecting security (business disruption, loss of trust, damages), what legal responsibilities a business owner bears (safety-management measures under the Act on the Protection of Personal Information, the duty of loyalty under the Companies Act, and so on), and what business owners themselves should be doing.

The three principles business owners are told to keep in mind are:

  1. Drive information security measures forward with the business owner’s own leadership
  2. Account for the information security measures of outsourced vendors as well
  3. Maintain constant communication about information security with everyone involved

Building on that, the guideline lays out “seven key actions” business owners should take: setting an organization-wide response policy, securing budget and personnel, having necessary measures examined and instructing that they be carried out, instructing periodic review of those measures, building a structure for emergency response and recovery, clarifying security responsibilities when outsourcing or using external services, and staying current on the latest trends.

From the front line, security measures tend to look like an inconvenient hassle that reduces convenience. That’s exactly why “the business owner judges, decides, and leads” is placed as the very first principle. This guideline’s consistent stance is that simply telling a staffer to “handle it somehow” doesn’t work.

4. The Practical Section — Proceeding in Three Stages

Part 2, the practical section, is structured in stages: “start with what you can” → “begin organizational efforts” → “take it on in earnest.”

Stage 1: Start with what you can
        Implement the Six Articles of Information Security
        ↓
Stage 2: Begin organizational efforts
        Draft an information security basic policy and communicate it
        Assess your current state with the "5-Minute Self-Assessment" (25 items)
        Decide which measures aren't yet in place and communicate that
        ↓
Stage 3: Take it on in earnest
        Draft regulations, manage assets, defend against and detect attacks,
        inspect and improve, build incident-response structure, manage business partners
        ↓
Further: Measures to strengthen things even more
        Risk analysis, measures for websites, cloud, and telework

What matters is that Stages 1 and 2 require almost no special knowledge and almost no budget. Rather than “we can’t do anything without budget,” it’s designed so that “even without a budget, you can start this much today.”

5. The Six Articles of Information Security — What the First Step Actually Involves

Stage 1’s “Six Articles of Information Security” are the basic measures every company must implement regardless of its size.

  Article What to do
1 Keep the OS and software always up to date! Apply patches, or use the latest version. Leaving things outdated invites attacks on already-fixed weaknesses
2 Install antivirus software! Install it, and keep the virus definition files always up to date
3 Strengthen your passwords! “Long,” “complex,” “never reused.” Prevents unauthorized logins from misuse of leaked IDs and passwords
4 Review your sharing settings! Check the settings of cloud services and networked multifunction printers, and eliminate any state where unrelated people can view them
5 Take backups! Make sure the business can continue even if data is lost or encrypted due to failure, operator error, or virus infection
6 Know the threats and attack techniques! Attack techniques change every year. Stay informed through the latest updates from IPA and others, and prepare so you don’t get fooled

For the fifth item, “backups,” added in the 4.0 edition, the guideline specifies operating it as a set of three: acquisition (decide the scope and interval), storage (decide the location, generation management, and retention period), and recovery (build a plan and confirm you can actually restore correctly). It only counts as a real measure once you also keep the backup disconnected from the production environment, so it isn’t encrypted along with the original data by ransomware, and confirm recovery so you avoid the trap of “we thought we had a backup, but it turns out we can’t restore from it.”

Every one of these items looks obvious once it’s written down. But most real-world damage happens precisely where this obvious stuff wasn’t followed through. Thoroughly enforcing these six items company-wide, under the business owner’s top-down leadership, is the starting point.

6. The 5-Minute Self-Assessment, and Organizational Efforts from Stage Two Onward

The centerpiece of Stage 2 is Appendix 3, the “5-Minute Information Security Self-Assessment.” Just answering 25 questions with “in place / partially in place / not in place / don’t know” makes your company’s current state and weak points visible.

The 4.0 edition revised the example countermeasures in the assessment, adding items reflecting recent intrusion routes, such as “block unnecessary communication from outside into the internal network” and “operate your website securely.” Intrusions exploiting weaknesses in VPN equipment, and tampering with neglected websites, are routes through which SMEs have continued to suffer real damage. (Website-side measures are covered in detail in a separate article, “How to Use IPA’s ‘How to Secure Your Website’”.)

The assessment’s result isn’t meant to be a score you compete on. Use it as material for prioritization: among the items not yet in place, fix the ones that carry the greatest risk for your own business first.

7. SECURITY ACTION — A Free Program for Making Your Efforts Visible

Once you’ve started, it’s worth also using SECURITY ACTION alongside it. It’s a program where SMEs self-declare that they’re working on information security measures, letting them use “one-star” or “two-star” logo marks free of charge according to how far along they are.

  What the declaration means
★ One star Declares that the company is working on the Six Articles of Information Security
★★ Two stars Declares that, after assessing the company’s own situation with the “5-Minute Self-Assessment,” it has established and publicly posted an information security basic policy (a sample is in Appendix 2), and is working on measures

Since it’s a self-declaration, there’s no review process — which also means you can start right away. Displaying the logo on business cards or your website gives you something to show clients, and the declaration is sometimes required to apply for public support programs such as the IT Introduction Subsidy.

For a company that’s just received a security checklist from a client and isn’t sure what to do, being able to say “we’re working from the guideline’s six articles and self-assessment, and we’ve declared SECURITY ACTION” is a realistic and honest first step.

8. The Appendices Double as a “Template Library”

It’s fair to say much of this guideline’s practical value lies in its appendices. The 4.0 edition comes with the following eight, all downloadable free of charge from IPA’s page.

  • Appendix 1: Practical Guidebook for Securing and Developing SME Security Personnel (newly added in the 4.0 edition)
  • Appendix 2: Information Security Basic Policy (sample)
  • Appendix 3: 5-Minute Information Security Self-Assessment
  • Appendix 4: Information Security Handbook (template)
  • Appendix 5: Information Security-Related Regulations (sample)
  • Appendix 6: Asset Management Ledger (sample)
  • Appendix 7: Guide to Safe Use of Cloud Services for SMEs
  • Appendix 8: Guide to Security Incident Response for SMEs

You don’t need to write the basic policy, the regulations, or the asset ledger from scratch — the design assumes you’ll adapt the samples to your own company. If your company is stuck on getting internal rules in place, starting with Appendix 2 and Appendix 5 will move things along faster.

Closer to day-to-day operations, individual topics such as reviewing password-protected ZIP files sent by email — so-called PPAP (“Why PPAP Is a Bad Idea”) — and preventing information leaks from PCs being disposed of (“A Checklist Before Disposing of a Windows PC”) are continuous with the thinking behind this guideline.

Summary

Here are the key points of IPA’s “Information Security Guidelines for Small and Medium Enterprises,” 4.0 edition.

  • Published March 27, 2026. A revision reflecting environmental changes: business disruption from ransomware, supply-chain-mediated damage, and a shortage of personnel
  • The approach is staged: start with the Six Articles of Information Security, then the 25-item self-assessment, then build out policy, regulations, and structure
  • The six articles now include “take backups!” — a real backup covers acquisition, storage, and confirmed recovery
  • Business owners have three principles and seven key actions of their own, so the effort isn’t left entirely to staff
  • Self-declaring through SECURITY ACTION (free) makes your efforts visible and is also a requirement for some public support programs
  • The eight appendices work as a ready-to-use template library for daily practice

The biggest obstacle to security measures is not knowing what to do — and that part is exactly what an official guideline has already answered for you. What’s left is applying it to your own environment and actually carrying it out.

For Those Struggling to Apply This to Their Own Environment

Plenty of companies, when they try to carry out the six articles’ “keep the OS and software up to date,” run straight into the wall of “our old business application can’t be updated because it won’t run on a newer OS.” Likewise, the order in which to fix issues found in the self-assessment depends on the configuration of your business systems.

Drawing on our experience developing and maintaining Windows business applications and web systems, Komura Software LLC takes on consultations about modifying existing software that’s blocking an update, and about prioritizing countermeasures. Even at the stage of “we ran the assessment, but from here it turns into a technical conversation we can’t move forward on,” we welcome a consultation starting from confirming your current state.

Recent articles sharing the same tags. Deepen your understanding with closely related topics.

These topic pages place the article in a broader service and decision context.

This article connects naturally to the following service pages.

Technical Consulting & Design Review

Deciding what order to fix issues found in the self-assessment, and identifying where the risk actually sits in your business systems or network configuration, falls squarely within technical consulting that includes design review.

Frequently Asked Questions

Common questions about the topic of this article.

What are the Six Articles of Information Security?
These are the basic measures that IPA's 'Information Security Guidelines for Small and Medium Enterprises,' 4th edition, says every company must implement regardless of size. They are: (1) always keep the OS and software up to date, (2) install antivirus software, (3) strengthen passwords, (4) review sharing settings, (5) take backups, and (6) know the threats and attack techniques in use. Through the 3.1 edition this was five articles; the sixth, 'take backups,' was added in light of the growing damage from ransomware.
What's the difference between SECURITY ACTION's one star and two stars?
One star is a self-declaration that the company is working on the Six Articles of Information Security, and any company just starting out on security can declare it right away. Two stars means the company has assessed its own situation using the guideline's appendix, the '5-Minute Information Security Self-Assessment,' and has established and publicly posted an 'Information Security Basic Policy,' declaring that it is working on countermeasures. Both are self-declarations to IPA and cost nothing.
A company with no dedicated IT staff — where should it start?
The guideline's practical section is structured around 'start with what you can.' It lays out the order as: first, implement the Six Articles of Information Security under the business owner's top-down leadership; next, use the 25 items in Appendix 3, the '5-Minute Information Security Self-Assessment,' to understand the current state; and then improve starting from the items that aren't yet in place. Neither the six articles nor the self-assessment requires specialized knowledge or a large budget.
What changed between the 3.1 edition and the 4.0 edition?
The 4.0 edition, published on March 27, 2026, reflects a set of environmental changes: business disruption caused by ransomware damage, the spreading impact of supply-chain-mediated attacks, and a shortage of security personnel. Specifically, it expands the 'Five Articles of Information Security' into six by adding 'take backups,' reorganizes countermeasures in light of the SCS evaluation system (a security assessment system for supply chain reinforcement) being developed by the Ministry of Economy, Trade and Industry and others, and adds a practical guidebook appendix to support securing and developing security personnel.

Author Profile

Profile page for the article author.

Go Komura

Representative of KomuraSoft LLC

Focused on Windows software development, technical consulting, and investigations into failures that are difficult to reproduce.

Back to the Blog