Japan – Fujitsu has established a new cybersecurity strategy aimed at continuously developing organisations’ cyber defence capabilities as generative AI advances and enterprise IT environments become increasingly complex.
The Japanese technology company said the strategy treats cybersecurity as a continuous cyber defence lifecycle covering strategic planning, design and development, implementation, operation, evaluation and improvement, rather than primarily as an operational function following IT system deployment.
At the centre of the strategy will be a virtual Cyber Security Nerve Center, which Fujitsu said will support cybersecurity decision-making using assessments and evidence generated through its Cyber Nerve System. The Nerve Center will also consolidate knowledge from Fujitsu’s Customer Zero initiatives and customer engagements, while incorporating market, threat and technology developments into its cybersecurity strategy.
Fujitsu has also defined a Cyber Defense Operations Model and Fujitsu Cyber Defense Framework to provide a structured approach to building, operating, and improving enterprise cyber defence capabilities.
The company said it will evaluate technologies developed by Fujitsu Research, Uvance Wayfinders, service development divisions and external partners, with new products and capabilities developed and tested in Fujitsu’s own environment where required. These capabilities are expected to be offered to customers through services including consulting, AI-enabled vulnerability assessments, AI Threat Hunting and AI Red Team Operations.
Four models underpin cyber defence approach
Fujitsu’s Cyber Defense Operations Model comprises four sub-models covering the scope, principles, responsibilities and levels of enterprise cyber defence.
The Cyber Defense Domain Model defines the assets that organisations should protect based on their operational roles rather than device types. It covers both IT and physical environments, including areas such as surveillance cameras and medical equipment.
The Cyber Defense Philosophy Model introduces the concept of “deceleration defense”, which focuses not only on preventing attacks but also on delaying attackers to give defenders more time to observe activity and introduce additional countermeasures.
The Cyber Defense Relationship Model addresses defence responsibilities and protection requirements across relationships with group companies and business partners, with the aim of strengthening resilience throughout the supply chain.
The Cyber Defense Proximity Model establishes defence levels according to the distance from an attacker’s objective, helping organisations determine security priorities and investment requirements.
Fujitsu said its Cyber Defense Framework will put these models into practice through a lifecycle spanning strategic planning, design and development, operation and continuous improvement.
The company will also use its Cyber Nerve System to identify cyber threats and risks from data generated through the framework and visualise the resulting analysis. Fujitsu said this will provide a shared view of the cyber defence environment and support operational teams in carrying out their defence activities.
Cyber Security Nerve Center to guide strategy
The Cyber Security Nerve Center will comprise approximately 100 members and will be responsible for defining the strategy and policies of the Cyber Nerve System.
According to Fujitsu, the Nerve Center will use assessments and evidence generated by the system to support executive decisions concerning issues such as system shutdowns, cyber defence priorities and investment policies.
It will also bring together Fujitsu’s cybersecurity knowledge and technologies across different functions, while incorporating technologies from external partners and startups.
Knowledge gathered through Fujitsu’s Customer Zero initiatives and customer engagements will be fed back into the Cyber Nerve System and customer-facing services. Fujitsu said this approach is intended to enable the continued development of enterprise cyber defence capabilities.
The company also plans to commercialise capabilities including AI Threat Hunting and AI Red Team Operations as services.
AI adds to cyber defence challenges
Fujitsu’s strategy comes as organisations face increasingly sophisticated cyberattacks and more complex IT environments.
The company said attackers are using generative AI for activities including vulnerability discovery, attack path analysis, attack code generation and lateral movement following a compromise. At the same time, cloud services, external data collaboration and supply-chain connections have expanded the environments that organisations need to protect.
Fujitsu said these developments make it increasingly difficult to maintain enterprise-wide cyber defence through security operations focused solely on preventing intrusions or responding after an incident.
The company is therefore positioning cyber defence as a management priority based on the assumption that attacks will occur, with an emphasis on limiting their impact and maintaining business continuity.
Fujitsu will also use its Security Meister programme to develop cybersecurity specialists, including internal white hat hackers and Security Architects. The programme will incorporate practical knowledge from the Nerve Center, recent threat analysis and experience from actual defence activities.
The company said it will progressively introduce consulting, system construction and operation services, and AI-powered defence services as part of its cybersecurity strategy.
Future developments are expected to include advanced monitoring and automated response, as well as support for deploying AI agents in customer environments. Fujitsu also plans to develop a cyber defence platform covering enterprises and their supply chains, incorporating technologies including its large language model Takane.

