Digital transformation, paper and legacy systems in Japan
Digital asset ownership: a continuity checklist for Japan SMEs
Domains, DNS, email, logins and recovery details are business assets. How Japanese companies lose control of them, and a checklist to make them recoverable.
Your company’s domain, DNS, email, website hosting, social and map listings, payment accounts and the recovery details behind them are business assets, and losing control of any one of them can stop the business from receiving leads, sending email or taking payments. In Japan, the most common cause is not a sophisticated attack but ordinary drift: a web agency registered the domain, a former employee’s phone holds the two-factor codes, a LINE account belongs to someone personally. Continuity starts with an inventory of these assets, company ownership of each one, and a documented way to recover access if any single person or vendor disappears.
Most digital disasters start with something boring. A domain registered by a former employee. A DNS account nobody can log into. A recovery email pointing at an inbox that no longer exists. A website hosted under a vendor’s account the company never owned. A two-factor code on the phone of someone who left three years ago. None of it sounds dramatic, which is exactly why it gets ignored.
Why is digital infrastructure a business continuity issue?
When people talk about digital transformation, they usually mean new software: AI, CRM, automation, booking systems, better websites. All of that sits on a plainer foundation. Who owns the domain? Who controls DNS? Where does email live? Who can reset the admin account? Which phone number receives verification codes? Which inbox receives tax, bank and platform notices?
If those answers are unclear, the business is fragile behind a modern surface. A company can survive an ugly spreadsheet. It may not survive losing control of its main domain, because email, the website and many logins depend on it. It can live with an imperfect CRM, but not with the only person holding admin access leaving without a handoff.
Security matters, but the bigger risk is continuity. Can the business keep operating when the person who set things up is unavailable? Can a vendor be replaced without losing access? Can the company prove it owns its own accounts?
Why are Japanese companies particularly exposed?
This is not because Japanese people are bad at technology. Japan has excellent engineers and strong vendors. The exposure is organizational. Many companies are very good at keeping things moving despite messy infrastructure: someone remembers, a vendor handles it, a senior person knows who to call. The process is unofficial, but it works, until it does not.
Several Japan-specific patterns make this worse:
- Web agencies holding the keys. Many SMEs had their site built by a local web production company (制作会社) that registered the domain and hosting in its own account. When the relationship ends, transferring them can be slow or contested.
- Personal LINE and phone numbers. LINE official accounts, Google Business Profile listings and social accounts are often set up by one employee with their personal account or phone.
- Company domains that are hard to replace. A .co.jp domain can only be registered by a company registered in Japan, and each company can hold only one. Losing it is not a matter of buying another.
- Vendor-managed everything. Where an SIer or IT vendor administers email, file servers or Microsoft 365, the company may not hold a global admin account at all.
- Reluctance to touch working systems. Old sites and accounts stay as they are because changing them feels risky and nobody wants to stop the machine long enough to map it.
Japanese organizations are often impressive in a crisis: the emergency meeting, the apology, the late nights reconstructing what should have been written down. That effort is admirable. It is also a poor operating model. The goal is to avoid the avoidable panic.
Not every old process is a problem. What matters is knowing the difference between a trusted process and an unmanaged dependency.
Which digital assets does a small business need to control?
The list is ordinary, which is why the risk is so common:
- Domains and DNS records
- Company email and shared inboxes
- Website hosting and CMS admin access
- Google Business Profile and map listings
- LINE official account and social media accounts
- Analytics, advertising and tag manager accounts
- Cloud storage and shared drives (Google Workspace, Microsoft 365, Box, Dropbox)
- Payment accounts and invoicing tools
- CRM, booking, newsletter and form tools
- Password manager and two-factor authentication devices
- Vendor and contractor access
- Recovery emails, phone numbers and backup codes
- Brand files, source files, photos, video and website assets
- The documentation that explains how all of this connects
Many companies assume that because the website is online, everything is fine. Because email works today, email is fine. Because the vendor answers the phone, ownership is fine. That holds until a card expires and a renewal fails, a staff member leaves, a phone is lost, a platform locks an account for verification, or a phishing incident forces someone to ask who has access to what.
How do you secure ownership and access?
I build and maintain the website, domains, email, and event and ticketing systems for a Tokyo executive events network, and this kind of ownership and access work is part of keeping any setup like that dependable. Done well, it is quiet work:
Inventory the assets. List every item above, who administers it, which email and phone number it is registered to, what it costs and when it renews.
Move ownership to the company. Register domains, hosting and subscriptions to a company role address (for example admin@ your domain) and a company payment method, not an employee’s personal account or a vendor’s.
Separate people from accounts. Give each person and each vendor their own login with the permissions they need. Stop sharing one password across the team, and remove former staff and contractors.
Fix two-factor authentication. Make sure no critical account depends on a single personal phone. Use a password manager with shared vaults, register a second admin, and store backup codes somewhere the company controls.
Document recovery paths. For each critical asset, write down how to regain access if the main administrator is unavailable, and test it once.
Set a review cycle. Check the inventory when anyone joins or leaves, when a vendor changes, and at least once a year.
The benefit is calm. When a staff member leaves, there is a handoff. When a vendor needs replacing, you know what they controlled. When a website needs work, the developer is not reverse-engineering the company from a half-remembered login. The first hour of any problem goes to fixing it rather than reconstructing the organization’s memory.
Which organizations are most at risk?
The ones I worry about most are not those who know they have a problem. They are in the middle: enough digital tools to depend on them, not enough structure to manage the dependency. They have a website, email, social accounts, analytics, payment tools, cloud folders and years of accumulated logins, but the ownership underneath is still informal.
That is common, and not because anyone is reckless. The risk is hard to see from inside a busy week. Everything works, and the person who knows the setup is still around. Then a founder falls ill, a manager leaves, a vendor stops replying, or a domain renewal fails, and the company finds its digital infrastructure was never a system, only inherited permissions and good luck.
Questions every organization should be able to answer
- What are our critical digital assets?
- Which legal entity owns each one?
- Who has admin access, and who can recover it if that person is unavailable?
- Which accounts are tied to personal emails or personal phone numbers?
- Which vendors control infrastructure we should own directly?
- Which subscriptions are active, and which are business-critical?
- Which former staff and contractors still have access?
- Where are backup codes, source files, brand assets and documentation kept?
- What would break first if we lost the main domain, email account, website host or social account?
If these are hard to answer, that is the work. Small does not need to mean bureaucratic, but it should not mean casual either. A ten-person company, a regional project or a family business can still lose years of visibility if one account is locked.
Build before the storm
The best time to fix this is before a crisis, when nobody is panicking and the work can be done carefully. It is a lesson I took from the 2011 tsunami in Miyako. It is optimistic work: it assumes the business, its customers and its reputation are worth protecting properly.
For a quick first read, try the technology risk self-check. A Diagnostics review produces the full inventory of assets, owners and recovery paths, and I can carry out the cleanup with your team and vendors. For overseas-headquartered teams, see digital infrastructure for foreign-owned SMEs in Japan.
Further reading: what the 2011 tsunami taught me about business continuity · the hidden cost of good enough systems · how to buy business software without vendor lock-in · what a startup accelerator’s own systems tell founders