It's largely the same as credit cards - the card have multiple data partitions and secure read/write are encrypted. Balances are logged on both the card and the station-level servers and correctable errors and/or mid-ride updates, if any, are propagated while the user is in motion, so that they can be written upon exit.
^ that was the official explanation for a long time, but they've reportedly transitioned to more credit-card like online system with no station-level servers, and also raised fees, which was negatively received by many rail operators aside JR East itself(which owns the system). There had been few rail companies experimenting with NFC credit card rides, though I'm personally suspecting it's more of bargaining power development.open threat than those lines seriously considering a switch.
The chips in the cards are secure enough that physical tampering is extremely difficult and software tampering is difficult enough with security by obscurity + encryption - the catch is that, it turns out, early Suica cards used DES(not even 3DES it seems), and they just didn't tell anybody until those went out of circulation. Plus, the prepaid limit of 20k yen(local equivalent of $200) limits abuse potential of the system; it's not worth trying to commit blatant frauds on the train-and-sandwiches card.