주메뉴바로가기본문바로가기
비즈한국 비즈한국

Exclusive
Analysis of 8 ICT Firms' Disclosures: Telecom Trio and 'Nae-Ka' Spend Less Than 1% of Revenue on 'Information Security'

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] Following a series of hacking incidents, including the data breach at SK Telecom017670, the vulnerability of the entire domestic industry has been laid bare. This year alone, companies such as GS Retail007070, JobKorea, SK Telecom, and CJ OliveNetworks have suffered large-scale personal data breaches. With attack methods evolving from cloud, device, and ransomware threats to the hacking of SK Telecom's HSS (Home Subscriber Server), it is assessed that the risk factors facing companies have become increasingly diverse.

Companies that handle vast amounts of personal information, sensitive data, and information directly linked to national infrastructure are held to a higher standard of responsibility. Any loopholes in these companies' security systems can lead to risks for society as a whole. We analyzed the mandatory information security disclosure documents of major ICT (Information and Communication Technology) firms—including the three major telecommunication carriers, Naver032640, Kakao, and the three major network companies—to examine their current status of information security investment and response strategies.

The vulnerability of the domestic industry is being highlighted as companies suffer consecutive hacking damages. A data breach occurred on the 30th of last month at AlbaMon, operated by JobKorea. Photo=AlbaMon
The vulnerability of the domestic industry is being highlighted as companies suffer consecutive hacking damages. A data breach occurred on the 30th of last month at AlbaMon, operated by JobKorea. Photo=AlbaMon

'Persistent' Hacking Risks… How Much Does the ICT Industry Spend on Information Security?

While private cybersecurity response capabilities have come under fire following a series of data breaches, it has been found that domestic companies allocate only about 6% of their total IT investment to information security. Over the three years since the implementation of mandatory information security disclosure, the average ratio of information security investment to IT investment has hovered around 6.1%. An analysis of the information security status data disclosed by eight major ICT companies to the Korea Internet & Security Agency (KISA) shows that NHN Cloud (7.1%), LG Uplus032640 (6.6%), and KT030200 (6.4%) had higher information security investment ratios than the domestic average. These were followed by: △Naver Cloud (5.7%), △KT Cloud (5.2%), △SK Telecom (4.1% / SK Broadband 4.6%), △Kakao (3.9%), and △Naver (3.7%).

This index indicates how much priority is placed on security. As digital infrastructure grows, so do the points of security vulnerability; therefore, security investment must increase in proportion to the scale and complexity of IT systems to effectively control risks. On average, this is half the level of the United States. According to a report last year by the U.S. cybersecurity consulting firm IANS Research, the average information security investment ratio for U.S. companies is 13.2%, a figure that has been steadily increasing from 8.6% in 2020.

Graphic=Reporter Kim Sang-yeon
Graphic=Reporter Kim Sang-yeon

According to last year's disclosures, as of 2023, the ratio of information security investment to revenue remained in the 0% range for all companies surveyed, excluding cloud firms. In the case of the three cloud companies, the ratios were: △NHN Cloud 4.50%, △Naver Cloud 2.48%, and △KT Cloud 1.64%. The three major telecom carriers (SK Telecom, KT, and LG Uplus) ranged from 0.44% to 0.49%, while Naver and Kakao stood at 0.43% and 0.34%, respectively. SK Telecom's figures reflect the investment amount of SK Broadband, which operates its wireline business separately.

Even when compared to operating profit, the information security investment ratios of the telecom carriers and the two major IT giants did not exceed 10%. By industry, the ratios of information security investment to operating profit for the telecom sector were: △SK Telecom 8.69%, △KT 7.38%, and △LG Uplus 3.60%. While Kakao’s total information security investment was 61% of Naver's, its ratio of information security investment to operating profit was 5.11%, higher than Naver’s.

Graphic=Reporter Kim Sang-yeon
Graphic=Reporter Kim Sang-yeon

The three cloud companies were found to maintain higher ratios of information security investment relative to operating profit. As of 2023, Naver Cloud invested more than three times its operating profit into the information security sector. Despite a 28.4 billion won deficit, NHN invested 6.3 billion won, and KT Cloud (25.19%), which recorded a 44.2 billion won profit, spent 11.133 billion won on information security that same year. Because cloud services store and process massive amounts of customer data, security incidents such as data leaks or service disruptions can cause enormous damage; therefore, aggressive investment in information security systems and the securing of expert personnel are required. This is also influenced by the fact that cloud services require significant initial infrastructure investment and relatively smaller operating profit scales compared to other companies.

'Complacent Attitudes' of Companies Locking the Stable After the Horse Has Bolted

"I thought of it only as an area dedicated to IT."

"It appears to be a situation that should be considered not as a security issue, but as national defense."

SK Group Chairman Chey Tae-won made these remarks during a Q&A session following his public apology at the group's headquarters in Euljiro, Seoul, on the 7th. It was his response to a question about his personal thoughts. Chairman Chey stated, "Until now, I thought of security only as an area for the information and communications department and relied solely on the dedicated team," adding, "Through this incident, I have realized how important security is to the entire group and I will increase investment in the future." The image of the chairman only now recalling the importance of security showed a disconnect with the company's busy efforts to handle the aftermath of the leak and the public sentiment.

SK Group Chairman Chey Tae-won announcing a public apology regarding the SK Telecom hacking incident at SK T-Tower in Jung-gu, Seoul, on the 7th. Photo=Reporter Kang Eun-kyung
SK Group Chairman Chey Tae-won announcing a public apology regarding the SK Telecom hacking incident at SK T-Tower in Jung-gu, Seoul, on the 7th. Photo=Reporter Kang Eun-kyung

SK Telecom faced criticism in the large-scale data breach because it had made the smallest information security investment among the three major carriers. The investment amount disclosed by SK Telecom last year was the lowest (60 billion won) among the three telecom companies. This was less than the 63.2 billion won spent by LG Uplus, and even when combined with SK Broadband (26.7 billion won), which handles the separated wireline business, the total of 86.7 billion won remained lower than that of KT (121.7 billion won), which operates both wireline and wireless businesses.

SK Telecom plans to overhaul its cybersecurity system at the group level. To elevate the group's information security system, it will establish a 'Special Committee for Information Security Innovation' and place it as the ninth committee under the SUPEX Council, the group's highest decision-making body. Experts from academia and industry will participate to enhance independence and expertise.

KT and LG Uplus have also pushed for reorganization, such as increasing information security investments, following their own hacking incidents where security networks were breached. Experts pointed out the need to reasonably assess the impact of security risks on business. Kwon Heon-young, a professor at Korea University's Graduate School of Information Security who participates in the committee as an external expert, noted, "In Korea, the compensation for damages recognized by the courts is very low, and the burden of proving damages is placed on the victim. Companies are negligent in information security investment because they do not bear concrete and clear responsibility." He added, "Since they are putting forward follow-up measures such as increased investment after the leak, it must lead to revolutionary improvements."

Jeon Chang-bae, Chairman of the IAAE (International AI Ethics Association), emphasized, "Security results depend on the amount invested. Currently, I believe the absolute figures are insufficient. Most of the companies involved, including the three major telecom carriers, are talking about shifting to AI. I have doubts about whether investments are being made properly in relation to AI security, which will be a major issue in the future. Proactive consideration is needed."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
단독
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지