KELA、富士通とサイバーセキュリティ協業契約を締結
~「攻撃を受けてから守る」から「攻撃される前に動く」へ。KELAのグローバルなサイバー脅威インテリジェンスと富士通の高度なサービス提供力を融合し、日本の「能動的サイバー防御(ACD)」を加速~
KELA 株式会社(本社:東京都港区、執行役員COO:廣川 裕司、以下、KELA)は、富士通株式会社(以下、富士通)と、日本市場におけるKELAグループ(イスラエル)のサイバーセキュリティソリューションの展開に関する協業契約を締結したことを発表します。
本契約は、富士通がKELAグループのソリューションを活用してマネージドセキュリティサービスを提供するManaged Security Service Provider(MSSP)モデルと、KELAソリューションそのものを再販・展開するResellerモデルの双方を対象としています。
今回の協業契約締結により、KELAグループが世界のダークウェブ、アンダーグラウンドフォーラム、サイバー犯罪コミュニティなどから収集・分析する 「サイバー脅威インテリジェンス(CTI)」と、「アタックサーフェスマネジメント(ASM)」、「継続的脅威エクスポージャー管理(CTEM)」、「第三者リスクの可視化とサプライチェーンリスク管理(TPRM)」などのテクノロジーを、富士通が有するサイバーセキュリティの専門性、コンサルティング、マネージドサービスなどの高度なサービス提供力と組み合わせます。
これによりKELAは、企業、政府機関、社会インフラ事業者などが、サイバー攻撃を受けてから対応する従来型の防御から、攻撃を受ける前に攻撃者の活動や攻撃の兆候・予兆を捉え、被害発生前にリスクを把握し、意思決定と対策につなげる「能動的サイバー防御(Active Cyber Defense:ACD)」への移行を加速させます。
■ 「攻撃前に動く」サイバー防御へ
サイバー攻撃は、これまで以上に高速化・巧妙化しています。 さらに、生成AIをはじめとするAI技術、クラウド、デジタルサプライチェーンの急速な普及により、企業・組織が管理すべきサイバーリスクは、自社ネットワークの内部だけでは捉えきれない範囲へと拡大しています。
攻撃者は、企業内部への侵入を開始する前から、企業やその取引先に関する情報を収集し、認証情報を窃取・売買し、インターネット上に公開された資産を探索し、脆弱性や攻撃可能な経路を見極めています。 したがって、これからのサイバー防御に求められるのは、「自社が侵害されたか」を監視するだけではなく、「攻撃者が自社に対して何を準備しているのか」を把握し、攻撃が現実の被害になる前に動くことです。
■ KELA の「Active Cyber Defense」アプローチ
KELA は、攻撃者側の活動を捉えるCTIを起点として、以下のような外部リスクを継続的に可視化します。
• ダークウェブやサイバー犯罪コミュニティにおける攻撃者の活動
• 漏えい・流出した認証情報や企業情報
• 自社およびグループ会社のインターネット上に公開されたデジタル資産
• 脆弱性、エクスポージャーおよび悪用可能性
• 取引先、委託先、サービスプロバイダーなど第三者に起因するリスク
さらに、サイバー脅威インテリジェンスを中核に、組織の外部攻撃対象領域、継続的な脅威エクスポージャー、第三者リスク、そして経営レベルのサイバーリスクを統合的に可視化し、「攻撃者」「自社」「第三者」という3つの視点から捉えて対処します。
今回の協業パートナーシップの対象となる主なKELAグループのソリューションは以下の通りです。
● KELA CTI Platform
― サイバー脅威インテリジェンス(CTI)
ダークウェブ、アンダーグラウンドフォーラム、サイバー犯罪コミュニティなど、攻撃者が活動するサイバー犯罪エコシステムから収集・分析した脅威インテリジェンスを提供します。
攻撃者の活動、漏えい情報、認証情報、攻撃対象に関する情報などを捉え、攻撃につながる兆候やリスクを早期に可視化します。
● ULTRARED CTEM Platform
― アタックサーフェスマネジメント(ASM)、継続的脅威エクスポージャー管理(CTEM)
インターネット上に公開されている自社・グループ会社のデジタル資産を継続的に把握し、脆弱性、エクスポージャー、悪用可能性などを可視化します。
「自社がインターネットからどのように見えているのか」 を継続的に把握し、対策すべきリスクの優先順位付けを支援します。
● SLING TPRM Platform
― 第三者リスクの可視化とサプライチェーンリスクの管理 (TPRM)
取引先、委託先、サービスプロバイダー、関連会社など、第三者およびサプライチェーンに起因するサイバーリスクを継続的に評価・管理します。
自社だけではなく、自社とつながる企業・組織を含めたサイバーリスク管理を支援します。
■ KELA × 富士通
KELA が持つ大きな強みは、攻撃者側の視点から得られるグローバルなサイバー脅威インテリジェンスです。 攻撃者がどこで活動し、何を狙い、どのような情報を取引し、どの企業・組織を攻撃対象としているのか。 KELA は、こうした「攻撃者の世界」から得られる情報を、企業・組織の防御に活用します。
一方、富士通は、日本の企業、政府機関、社会インフラを支える幅広い事業基盤と、サイバーセキュリティに関する専門人材、コンサルティング、マネージドサービスなどの高度なサービス提供力を有しています。
●KELA
「攻撃者(敵)を知る力」
「自社(己)の脆弱性・エクスポージャーを知る力」
「取引先・関連会社など、つながる組織(仲間)のリスクを知る力」
●富士通
「Red Team の実践知と総合力で、リスクを検証し、対策・改善につなげる力」
両社の強みを組み合わせることで、強固なサイバー防御のアプローチを日本市場で展開していきます。
KELA は、今回の富士通との協業を、単なるテクノロジーの販売・提供にとどまらない、日本におけるActive Cyber Defense の普及を加速する重要な取り組みと位置付けています。
KELA グループのグローバルな脅威インテリジェンスと、富士通の日本市場における高度なサービス提供力を組み合わせることで、企業・政府機関・社会インフラ事業者が、攻撃を受ける前にリスクを把握し、判断し、行動できるサイバー防御の実現を支援します。
KELA は今後も、富士通との協業を通じて、日本における「能動的サイバー防御(Active Cyber Defense:ACD)」の普及と発展を加速し、企業・政府機関・重要社会インフラ事業者等のビジネスレジリエンスの向上、ひいては安全で持続的な事業成長に貢献してまいります。
■ 富士通株式会社からのコメント
富士通株式会社
Uvance Wayfinders
Partner 佐藤 丈師 氏
富士通は、Red Teamで培った攻撃者視点の実践知とKELAの脅威インテリジェンスを掛け合わせ、脅威に先回りするActive Cyber Defense(能動的サイバー防御)を支
援する、企業・組織向けのサービスとして提供します。脅威インテリジェンスは入手した後にどのように活用するか、アタックサーフェスマネジメントは資産やリスクを可視化してからが本番です。私たちは脅威ハンティングを通じてこれらを結び付け、対処すべきリスクの見極めから初動対策の立案までを包括的に支援することでお客様の防御力の強化に貢献します。
■ KELA について
https://www.kelacyber.com/ja/
KELA グループは、イスラエルに本社を置くサイバー脅威インテリジェンス企業です。 2009 年の設立以来、ダークウェブ、アンダーグラウンドフォーラム、サイバー犯罪コミュニティなど、攻撃者が活動するサイバー犯罪エコシステムから独自のサイバー脅威インテリジェンスを収集・分析し、攻撃者の視点から企業・組織の外部リスクを可視化してきました。
現在は、サイバー脅威インテリジェンス(CTI)を中核に、External Attack Surface Management(EASM)、Continuous Threat Exposure Management(CTEM)、Third Party Risk Management(TPRM)などのテクノロジーを提供し、「攻撃を受けてから守る」だけではなく、「攻撃される前に動く」能動的なサイバー防御を支援しています。
KELA グループは、北米、欧州、アジアを含むグローバル市場で企業・政府機関などにサービスを提供しています。 日本法人であるKELA株式会社は2019年に設立され、日本市場におけるKELAグループのサイバー脅威インテリジェンスおよび能動的サイバー防御ソリューションなどの普及を推進しています。
【本件に関するお問い合わせ先】
KELA 株式会社
マーケティング・広報担当(前田・中村)
Mail: jp-pr@ke-la.com
KELA and Fujitsu Enter into Cybersecurity Collaboration Agreement
~ From "defending after an attack" to "acting before an attack" - combining KELA’s global cyber threat intelligence with Fujitsu’s advanced service capabilities to accelerate Active Cyber Defense (ACD) in Japan ~
KELA K.K., the Japanese entity of cyber threat intelligence company KELA Inc. (Head Office: Minato-ku, Tokyo; Executive Officer & COO: Yuji Hirokawa; hereinafter, “KELA”), today announced that it has entered into a collaboration agreement with Fujitsu Limited (hereinafter, “Fujitsu”) regarding the deployment of KELA Group (Israel) cybersecurity solutions in the Japanese market.
The agreement covers both a Managed Security Service Provider (MSSP) model, under which Fujitsu uses KELA Group solutions to provide managed security services, and a reseller model, under which Fujitsu resells and expands KELA solutions in the market.
Through this collaboration, KELA Group’s technologies - including Cyber Threat Intelligence (CTI) collected and analyzed from the global dark web, underground forums, and cybercrime communities; Attack Surface Management (ASM); Continuous Threat Exposure Management (CTEM); and Third-Party Risk Management (TPRM), including third-party risk visibility and supply-chain risk management - will be combined with Fujitsu’s cybersecurity expertise and advanced service delivery capabilities, including consulting and managed services.
By bringing these capabilities together, KELA aims to accelerate the shift for enterprises, government organizations, and social infrastructure operators from conventional defense that reacts after an attack to Active Cyber Defense (ACD): identifying attacker activity and early indicators before an attack, understanding risk before damage occurs, and turning that visibility into decisions and action.
■ Toward Cyber Defense That Acts Before an Attack
Cyberattacks are becoming faster and more sophisticated than ever. At the same time, the rapid adoption of generative AI and other AI technologies, cloud services, and digital supply chains is expanding the scope of cyber risk beyond what can be understood from inside an organization’s own network alone.
Attackers begin collecting information on organizations and their business partners before attempting an intrusion. They steal and trade credentials, identify internet-exposed assets, and assess vulnerabilities and possible attack paths. Cyber defense therefore needs to go beyond monitoring whether an organization has already been compromised. Organizations need to understand what attackers may be preparing against them and act before those activities result in real-world damage.
■ KELA’s Active Cyber Defense Approach
Starting with CTI that captures attacker-side activity, KELA continuously provides visibility into external risks such as:
• Attacker activity on the dark web and across cybercrime communities
• Leaked or exposed credentials and corporate information
• Internet-exposed digital assets of the organization and its group companies
• Vulnerabilities, exposure, and exploitability
• Risks arising from business partners, contractors, service providers, and other third parties
With cyber threat intelligence at the core, KELA further integrates visibility across an organization’s external attack surface, continuous threat exposure, third-party risk, and management-level cyber risk, enabling organizations to address cyber risk from three perspectives: the attacker, the organization itself, and connected third parties.
The principal KELA Group solutions covered by this collaboration include:
● KELA CTI Platform - Cyber Threat Intelligence (CTI)
Provides threat intelligence collected and analyzed from the cybercrime ecosystem in which attackers operate, including the dark web, underground forums, and cybercrime communities. It captures attacker activity, leaked information, credentials, and information relating to potential targets to provide early visibility into indicators and risks that may lead to attacks.
● ULTRARED CTEM Platform - Attack Surface Management (ASM) and Continuous Threat Exposure Management (CTEM)
Continuously identifies an organization’s and its group companies’ internet-exposed digital assets and provides visibility into vulnerabilities, exposure, and exploitability. It helps organizations continuously understand how they appear from the internet and prioritize risks that require remediation.
● SLING TPRM Platform - Third-Party Risk Visibility and Supply-Chain Risk Management (TPRM)
Continuously assesses and manages cyber risks arising from business partners, contractors, service providers, affiliates, and other third parties and supply-chain relationships. It supports cyber risk management not only for the organization itself, but also across the wider ecosystem of connected organizations.
■ KELA × Fujitsu
One of KELA’s major strengths is its global cyber threat intelligence derived from the attacker’s perspective. KELA uses intelligence from the “attacker’s world” - where attackers operate, what they target, what information they trade, and which organizations they are focusing on - to strengthen the defenses of enterprises and organizations.
Fujitsu, meanwhile, has a broad business foundation supporting enterprises, government organizations, and social infrastructure in Japan, together with cybersecurity specialists and advanced service capabilities spanning consulting and managed services.
●KELA
The ability to understand the attacker
The ability to understand the organization’s own vulnerabilities and exposure
The ability to understand risks affecting business partners, affiliates, and other connected organizations
●Fujitsu
The ability to validate risk and connect findings to mitigation and improvement through Red Team expertise and comprehensive capabilities
By combining the strengths of both companies, KELA and Fujitsu will expand a more robust approach to cyber defense in the Japanese market.
KELA views this collaboration with Fujitsu as an important initiative that goes beyond the sales and delivery of technology, and accelerates the adoption of Active Cyber Defense in Japan. By combining KELA Group’s global threat intelligence with Fujitsu’s advanced service delivery capabilities in the Japanese market, the companies will support enterprises, government organizations, and social infrastructure operators in identifying risk, making informed decisions, and taking action before attacks occur.
KELA will continue to accelerate the adoption and development of Active Cyber Defense (ACD) in Japan through its collaboration with Fujitsu, contributing to stronger business resilience and, ultimately, safer and more sustainable business growth for enterprises, government organizations, and critical social infrastructure operators.
■ Comment from Fujitsu Limited
Fujitsu Limited
Uvance Wayfinders
Partner, Takeshi Sato
“Fujitsu will combine the practical attacker-perspective expertise cultivated through our Red Team activities with KELA’s threat intelligence to provide services for enterprises and organizations that support Active Cyber Defense by staying ahead of threats. Threat intelligence only creates value when it is effectively used, and Attack Surface Management becomes truly meaningful once assets and risks have been made visible. Through threat hunting, we connect these capabilities and provide comprehensive support from identifying the risks that require action through to planning initial response measures, helping customers strengthen their defensive capabilities.”
■ About KELA
https://www.kelacyber.com/ja/
KELA Group is a cyber threat intelligence company headquartered in Israel. Since its founding in 2009, KELA has collected and analyzed proprietary cyber threat intelligence from the cybercrime ecosystem in which attackers operate, including the dark web, underground forums, and cybercrime communities, providing visibility into organizations’ external risks from the attacker’s perspective.
Today, with Cyber Threat Intelligence (CTI) at its core, KELA provides technologies including External Attack Surface Management (EASM), Continuous Threat Exposure Management (CTEM), and Third Party Risk Management (TPRM), supporting a proactive approach to cyber defense that goes beyond “defending after an attack” to “acting before an attack.”
KELA Group serves enterprises and government organizations across global markets, including North America, Europe, and Asia. KELA K.K., its Japanese subsidiary, was established in 2019 and promotes KELA Group’s cyber threat intelligence and Active Cyber Defense solutions in the Japanese market.
【Media Contact】
KELA K.K.
Marketing & Public Relations (Maeda / Nakamura)
Email: jp-pr@ke-la.com
