Gartner® の「SASEプラットフォーム部門 Magic Quadrant」で2 年連続リーダーに選出 レポートを読む

閉める
閉める
明日に向けたネットワーク
明日に向けたネットワーク
サポートするアプリケーションとユーザー向けに設計された、より高速で、より安全で、回復力のあるネットワークへの道を計画します。
Netskopeを体験しませんか?
Netskopeプラットフォームを実際に体験する
Netskope Oneのシングルクラウドプラットフォームを直接体験するチャンスです。自分のペースで進められるハンズオンラボにサインアップしたり、毎月のライブ製品デモに参加したり、Netskope Private Accessの無料試乗に参加したり、インストラクター主導のライブワークショップに参加したりできます。
SSEのリーダー。 現在、シングルベンダーSASEのリーダーです。
Netskope は、 SSE プラットフォームと SASE プラットフォームの両方で、ビジョンで最も優れたリーダーとして認められています
2X ガートナーマジック クアドラント SASE プラットフォームのリーダー
旅のために構築された 1 つの統合プラットフォーム
ダミーのためのジェネレーティブAIの保護
ダミーのためのジェネレーティブAIの保護
ジェネレーティブ AI の革新的な可能性と堅牢なデータ セキュリティ プラクティスのバランスを取る方法をご覧ください。
ダミーのための最新のデータ損失防止(DLP)eBook
最新の情報漏えい対策(DLP)for Dummies
クラウド配信型 DLP に移行するためのヒントとコツをご紹介します。
SASEダミーのための最新のSD-WAN ブック
SASEダミーのための最新のSD-WAN
遊ぶのをやめる ネットワークアーキテクチャに追いつく
リスクがどこにあるかを理解する
Advanced Analytics は、セキュリティ運用チームがデータ主導のインサイトを適用してより優れたポリシーを実装する方法を変革します。 Advanced Analyticsを使用すると、傾向を特定し、懸念事項に的を絞って、データを使用してアクションを実行できます。
Netskopeテクニカルサポート
Netskopeテクニカルサポート
クラウドセキュリティ、ネットワーキング、仮想化、コンテンツ配信、ソフトウェア開発など、多様なバックグラウンドを持つ全世界にいる有資格のサポートエンジニアが、タイムリーで質の高い技術支援を行っています。
Netskopeの動画
Netskopeトレーニング
Netskopeのトレーニングは、クラウドセキュリティのエキスパートになるためのステップアップに活用できます。Netskopeは、お客様のデジタルトランスフォーメーションの取り組みにおける安全確保、そしてクラウド、Web、プライベートアプリケーションを最大限に活用するためのお手伝いをいたします。

This report analyzes the primary cybersecurity risk trends impacting organizations within the Japan region. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.

10分 読む

リンク リンク

The 2026 Netskope Threat Labs Japan report details the increasing adoption of generative AI, trends in data policy violations, and malware distribution via cloud applications observed over the last year.

このレポートの内容 リンク リンク

This report explores recent trends in the adoption and governance of generative AI applications, enterprise AI platforms, API usage, cloud app activity, and data policy violations across Japan. It highlights how organizations are balancing rapid innovation with the need for stronger data protection, compliance, and risk management controls.

Mitigating shadow AI risk: While genAI adoption continues to rise, organizations in Japan are working aggressively to curtail shadow AI risks by guiding their employees to organization-managed genAI apps, rising to 79% (up from 15% one year ago) of AI users now using managed genAI apps instead of personal ones, which fell sharply from 85% to 11% over the same time period. In both instances, Japan is well ahead of global averages.

A new top genAI application: Google Gemini has overtaken ChatGPT as the most popular genAI app in Japan. This is the first region in the world where Netskope Threat Labs has reported this, with more expected in 2026.

Data exposure risks: Users continue to expose sensitive data to third parties in violation of organization policies, with intellectual property accounting for 50% of data policy violations involving personal cloud apps and regulated data accounting for 48% of data policy violations involving genAI apps.

GenAIの活用 リンク リンク

GenAI: 導入と使用の傾向

GenAI adoption in Japan has steadily increased over the past year, with genAI usage now observed in 80% of organizations, up from 69% a year ago. This upward trend reflects growing maturity and confidence in genAI technologies across Japanese organizations, which are gradually closing the adoption gap with global counterparts.

Organizations using genAI apps in Japan

Organizations in Japan have aggressively mitigated the shadow AI risk associated with genAI adoption by aggressively driving their user base away from using personal instances, and toward company-managed tools. The following chart illustrates the radical change in behaviour that occurred over the past year as the use of personal genAI accounts dropped sharply, falling from 85% to just 11%, while the adoption of organization-managed genAI solutions surged from 15% to 79% over the same period. In both of these areas, Japan is doing much better than the other regions, where 62% of employees use organization-managed AI apps and 47% still use personal genAI apps. This dramatic change points to a strong move toward company-managed platforms that provide better data protection, governance, and compliance controls. As this transition accelerates, organizations in Japan are increasingly prioritizing enterprise-grade genAI solutions that enable innovation while reducing risk.

GenAI usage personal vs organization account breakdown in Japan

In Japan, the top genAI applications differ from global usage patterns. While ChatGPT is still the most popular genAI app globally. Google Gemini has become the most popular genAI app in Japan, where 60% of organizations are using it compared to 53% using ChatGPT. In fact, this is the first time that we are reporting the dethroning of ChatGPT as the most popular genAI app in any region. As usage of genAI apps managed by organizations continues to increase across the globe, we expect more regions to follow suit in 2026. Microsoft 365 Copilot is used by 31% of organizations, with Microsoft Copilot close behind at 30%. The remaining top applications include a mix of specialized and embedded AI tools tailored to local business and operational needs.

Most popular genAI apps based on the percentage of ogranizations using those apps in Japan

The chart below shows how usage of the top genAI applications in Japan has evolved over the past year, highlighting rapid shifts in the genAI landscape. Google Gemini surpassed ChatGPT in June 2025, marking a notable change in leadership among genAI tools that we expect to see occurring in other regions in 2026. ChatGPT usage declined over the year, while Gemini continued to gain momentum. Microsoft 365 Copilot also showed steady growth, driven by its integration into core productivity and enterprise workflows. In addition, Google NotebookLM emerged as a new entrant, with adoption beginning in April 2025 and reaching 16% by the end of the year, reflecting growing interest in specialized, knowledge-focused genAI tools.

Most popular apps by percentage of organizations in Japan

生成 AI: アプリの使用状況とデータ ポリシー違反

As genAI adoption continues to grow across Japan, concerns around data exposure are becoming increasingly important. Organizations are using genAI tools for tasks such as summarizing documents, generating reports, and supporting development workflows, all of which can involve sharing sensitive information and expanding the potential attack surface. As genAI becomes more embedded in daily operations, data protection has become a top priority, particularly as shadow AI remains a challenge.

Recent analysis of data policy violations in Japan shows that regulated data is the most frequently exposed category, accounting for 48% of incidents, followed by intellectual property at 38%. Source code represents 9% of exposures, while passwords and API keys account for 5%. On average, organizations in Japan experience more than 500 genAI-related data policy violations per month, underscoring the scale of the challenge. This shift highlights a higher risk around compliance-sensitive and proprietary information, reinforcing the need for robust DLP controls and secure, well-governed genAI deployments.

Type of data policy violations in Japan

最もブロックされたgenAIアプリ

Organizations across Japan are taking a cautious approach to genAI adoption, with many choosing to block specific applications due to security, privacy, and compliance concerns. While policies vary by organization, certain tools are restricted far more often than others, highlighting where perceived risk is highest. In some cases, blocking entire categories of genAI apps may offer more consistent protection than managing individual tools.

DeepSeek is the most frequently blocked genAI application at 30%, followed by Tactiq at 27% and Grok at 25%. These blocking patterns suggest that organizations in Japan are not only responding to risks associated with individual applications, but also strengthening broader governance strategies to manage genAI usage within established security and compliance frameworks.

Most blocked AI apps by percentage of organizations enacting a blanket ban on the app in Japan

エージェント型AIの導入 リンク リンク

ブラウザ外での生成AIAPIの台頭

Even when genAI agents and applications are deployed on-premises in Japan, the underlying models are often hosted in the cloud through SaaS or enterprise genAI platforms. These agents and applications typically connect via dedicated API endpoints rather than browser-based interfaces. For example, browser interactions with OpenAI occur through chatgpt.com, while internal tools, workflows, and AI agents commonly access models programmatically through api.openai.com.

Despite Google Gemini surpassing ChatGPT in application usage, api.openai.com remains the most widely used genAI SaaS API in Japan, with 61% of all organizations connecting to it. This is followed by api.anthropic.com at 33% and api.deepinfra.com at 14%, underscoring the continued importance of API-based genAI integrations in enterprise systems and agent-driven workflows.

The Top 10 SaaS API domains by percentage of organizations in Japan

マルウェアのダウンロード リンク リンク

クラウドアプリによるマルウェアの配布

Attackers frequently abuse trusted cloud platforms in Japan to distribute malware, taking advantage of the fact that users are more likely to open files hosted on familiar services. While these platforms work to remove malicious content, even short delays before detection can be enough for attacks to succeed and for infected files to spread internally.

In Japan, Box has emerged as one of the most commonly abused cloud platforms for malware distribution, impacting 10% of organizations, followed by GitHub at 7.6% and Microsoft OneDrive at 7.1%. These trends highlight how attackers adapt to regional cloud usage patterns and continue to leverage widely trusted services to deliver malicious payloads.

Top apps for malware downloads in Japan

クラウド アプリの使用状況 リンク リンク

個人用アプリのアクティビティ

Across Japan, the widespread use of personal cloud and online applications in workplace environments continues to blur the boundaries between corporate and personal data management. Google Drive is the most commonly used personal app at 79%, followed closely by ChatGPT at 77% and Twitter/X at 76%. While much of this activity supports legitimate use cases such as collaboration, research, and productivity, it also introduces meaningful data security risks when sensitive information is involved. From personal genAI accounts to social and collaboration platforms, these applications remain key points of potential data exposure, particularly when used outside approved workflows or during employee transitions.

Top apps for upstream activities to personal apps in Japan

個人用アプリケーションにおけるデータポリシー違反

Across Japan, many organizations actively use DLP controls to monitor and manage the movement of sensitive data into personal applications, aiming to reduce accidental exposure or misuse. Recent incident analyses show that intellectual property accounts for 50% of policy violations, followed by regulated data at 37%, passwords and API keys at 10%, and source code at 2%. On average, organizations experience around 17 data policy violation incidents per month involving personal applications, reinforcing the scale and persistence of the risk. These figures continue the same trend observed last year, highlighting the persistent challenge of protecting commercially sensitive information in unmanaged or personal apps. Strengthening DLP coverage, improving employee awareness, and enforcing clear data-handling policies remain essential for minimizing both insider and external risks.

Data policy violations for personal apps in Japan

パーソナル アプリ データの違反

Organizations in Japan use a variety of tools to reduce the risk of data leaks through personal cloud and genAI applications. Measures include blocking uploads to personal apps, providing real-time guidance to employees to prevent sensitive information from reaching unmanaged services. Google Drive is the application that most frequently triggers such blocks, followed by Google Gmail at 19% and OneDrive at 18%. These efforts reflect ongoing attempts to limit unauthorized data movement and mitigate risks from personal accounts on unmanaged platforms.

Top apps for upstream blocks to personal apps in Japan

推奨事項 リンク リンク

マネージド型と個人用の両方の genAI ツールの使用と個人用クラウド アプリの誤用が増加する中、急速に変化する脅威の状況で組織を保護するには、可視性を強化し、ポリシーを改良し、プロアクティブな防御を優先することが不可欠です。

Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across the Japan region to take a fresh look at their overall security posture:

  • すべてのウェブおよびクラウド トラフィックを含むすべての HTTP および HTTPS ダウンロードを検査し、マルウェアがネットワークに侵入するのを防ぎます。 Netskopeのお客様は、 Netskope One Next Gen Secure Web Gateway すべてのカテゴリからのダウンロードに適用され、すべてのファイル タイプに適用される脅威保護ポリシーを備えています。
  • 正当なビジネス目的を果たさないアプリや、組織に不均衡なリスクをもたらすアプリへのアクセスをブロックします。 良い出発点は、現在使用している評判の良いアプリを許可し、他のすべてのアプリをブロックするためのポリシーです。
  • 使う DLP ソースコード、規制対象データ、パスワードとキー、知的財産、暗号化されたデータなど、個人のアプリインスタンス、genAIアプリ、またはその他の不正な場所に送信される可能性のある機密情報を検出するためのポリシー。
  • 使う リモートブラウザ分離(RBI) 新しく確認されたドメインや新しく登録されたドメインなど、より高いリスクをもたらす可能性のあるカテゴリに該当する Web サイトにアクセスする必要がある場合に、追加の保護を提供するテクノロジです。

Netskope Threat Labs

業界トップクラスのクラウド脅威およびマルウェア研究者が在籍し、 Netskope Threat Labs 企業に影響を与える最新のクラウド脅威を検出し、分析し、防御策を設計します。弊社の研究者は、DEF CON、Black Hat、RSA などのトップクラスのセキュリティ カンファレンスで定期的に講演やボランティア活動を行っています。

このレポートについて

Netskopeは、世界中の何百万人ものユーザーに脅威保護を提供します。このレポートに記載されている情報は、 Netskope One プラットフォーム relating to a subset of Netskope customers in Japan with prior authorization.

このレポートの統計は、2024 年 10 月 1 日から 2025 年 10 月 31 日までの期間に基づいています。統計は、攻撃者の戦術、ユーザーの行動、組織のポリシーを反映します。