주메뉴바로가기본문바로가기
비즈한국 비즈한국

Companies with Top-Tier Security Certifications Hacked One After Another; Is the Government Free of Responsibility?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] With the recent string of hacking incidents causing widespread damage, the government has launched a comprehensive review of its security framework. It is pushing for measures that allow for ex-officio investigations without requiring corporate reports when signs of hacking are identified, as well as the implementation of punitive fines. However, critics point out that the government itself must also "go under the knife." Many believe the government’s management gaps and inadequate cooperative systems are among the root causes of these hacking incidents.

Over the past five years, personal information leaks have been confirmed in just five government ministries—including the Ministry of National Defense, the Ministry of Land, Infrastructure and Transport, and the Personal Information Protection Commission—totaling over 38,000 cases. This highlights that the government is not immune to such leaks. The growing consensus is that hacking incidents must be viewed not just as corporate risks but as national crises, necessitating a complete overhaul of cyber security.

The government is initiating a full-scale review of its security systems following a series of hacking incidents. Ryu Je-myung, Second Vice Minister of Science and ICT, announces the final investigation results of the SK Telecom breach at the Government Complex Seoul in Jongno-gu, Seoul, on July 4. Photo = Reporter Im Jun-seon
The government is initiating a full-scale review of its security systems following a series of hacking incidents. Ryu Je-myung, Second Vice Minister of Science and ICT, announces the final investigation results of the SK Telecom017670 breach at the Government Complex Seoul in Jongno-gu, Seoul, on July 4. Photo = Reporter Im Jun-seon

Where Was the Government's Incompetent Response Exposed?

The government's role in information security is divided into two pillars: proactive management, such as the "security certification system," and reactive response through "breach investigation and sanctions." Since the SK Telecom hacking incident in April, a series of large-scale data breaches occurring every month have exposed flaws in both the government's preventative and responsive systems.

Companies recently affected by hacking, such as SK Telecom, Yes24053280, Lotte Card, and KT030200, all hold the "ISMS-P (Information Security and Personal Information Protection Management System)," the highest level of security certification in Korea. Among them, Lotte Card received this certification from the Financial Security Institute just two days before its server hack occurred. This certification was meant to acknowledge that the company possessed the capacity to effectively respond to cyber threats. Most companies and organizations outside the financial sector receive ISMS-P certification through the Korea Internet & Security Agency (KISA).

Industry insiders view this security certification, introduced by the government to ensure the safety of information and communication networks, as a merely formal system that satisfies only minimum requirements. An official from a domestic security consulting firm that performs mock hacking and penetration testing for companies stated, "ISMS-P is merely a benchmark confirming that essential security requirements were met at a certain point in time; it does not guarantee the absolute safety of a system. Companies must continuously manage and operate systems to address new threats."

KT CEO Kim Young-shub apologizes at a press briefing regarding small payment damages at the KT Gwanghwamun branch in Jongno-gu, Seoul, on the 11th. Photo = Reporter Im Jun-seon
KT CEO Kim Young-shub apologizes at a press briefing regarding small payment damages at the KT Gwanghwamun branch in Jongno-gu, Seoul, on the 11th. Photo = Reporter Im Jun-seon

Holes in the post-incident response were also laid bare. KT, while dealing with unauthorized small payment incidents, reported six instances of server intrusion to KISA on the 18th after verifying the results of a security inspection that had been ongoing for four months. Following the SK Telecom incident, the Ministry of Science and ICT had formed a joint public-private investigation team to inspect the security status of telecommunications companies and major platforms. At the time, the Ministry's announcement was that "no unusual findings were discovered."

During a joint briefing on the 19th, Second Vice Minister Ryu Je-myung addressed the controversy over the poor inspection, explaining, "We confirmed that the malicious code found at SK Telecom was not present at KT or LG Uplus032640. While we conducted a fairly intensive investigation, we lacked the physical conditions and situational capacity to perform a comprehensive survey (of the entire security status)."

Delayed initial responses and recurring allegations of cover-ups also highlight the inadequacy of the government's response. Under current law, investigations are only possible if the affected company or organization reports the incident voluntarily. Another limitation is that government "recommendations" post-incident lack binding power. The government recommended that SK Telecom prepare a plan for 100% compensation for damages and expand the scope of penalty waivers, but the company did not comply.

A press conference apologizing to customers for cyber security incidents held at the Booyoung Taepyeong Building in Jung-gu, Seoul, on the 18th. Photo = Reporter Im Jun-seon
A press conference apologizing to customers for cyber security incidents held at the Booyoung Taepyeong Building in Jung-gu, Seoul, on the 18th. Photo = Reporter Im Jun-seon

"Need to Reorganize Certification System and Establish a Control Tower"

The fact that "femtocells" (micro-mobile base stations), identified as the method used in the unauthorized KT payment incident, were excluded from the current information protection management system has underscored the need for a revamp of the pre-certification system.

Rep. Lee Hae-min of the National Assembly's Science, ICT, Broadcasting, and Communications Committee, a former Google employee, emphasized, "There is a question as to whether the current certification system is actually granting companies a free pass. We must completely overhaul the security certification framework to reflect reality, and for hacking incidents at the very least, we should even consider a punitive damages system to ensure companies take responsible action."

The aforementioned security industry insider noted, "While it is difficult to apply universally like the current ISMS certification, there is a need to strengthen it against realistic threats so that a company's actual defensive capabilities can be assessed. Even after obtaining certification, we should induce continuous security management by requiring periodic vulnerability assessment reports or ensuring a certain level of security personnel and budget."

The government has scrambled to prepare countermeasures. It is pushing to expand investigation authority—such as revising the Information and Communications Network Act to allow the government to launch ex-officio investigations based solely on signs of hacking—and is strengthening security obligations for companies and organizations that hold large amounts of personal data. The plan is to increase response capacity by applying punitive fines for violations of security obligations. The revision being reviewed includes the establishment of an "Infringement Incident Investigation Deliberation Committee," which would allow for ex-officio investigations into major issues following expert review.

Both experts and the National Assembly emphasize the government's responsibility and role. There is a growing recognition that a series of security incidents is not just a problem for individual companies, but a policy challenge at the national level.

KT CEO Kim Young-shub speaks at the National Assembly's Science and ICT Committee hearing on the hacking crisis on the 24th. Photo = Reporter Park Eun-sook
KT CEO Kim Young-shub speaks at the National Assembly's Science and ICT Committee hearing on the hacking crisis on the 24th. Photo = Reporter Park Eun-sook

In particular, it has been pointed out that a new security paradigm is required, considering the Korean security environment where the traditional principle of "network separation" (a concept where all business PCs are disconnected from the internet) is weakening.

Professor Kim Seung-joo of the Graduate School of Information Security at Korea University, who appeared as a witness at the National Assembly's Science and ICT Committee hearing on the 24th, explained, "The shift began during the COVID-19 pandemic, and as AI policies were introduced, connectivity expanded. Internal network systems that used to be completely cut off were like 'sterile rooms,' but now that (cyber intrusions) have entered all at once, they are collapsing helplessly." Professor Kim added, "We must solidify cyber security based on a system of early detection, preemptive defense against vulnerabilities, and neutralization/blocking when damage occurs."

The need for a comprehensive response through a control tower, moving beyond the "siloed" approach between ministries, was also raised. While financial information leak incidents are managed by the Financial Security Institute under the Financial Services Commission's notifications, incidents in other industries are handled by KISA under the Ministry of Science and ICT, in accordance with the Information and Communications Network Act and the Information Security Industry Act. As hacking damage occurs without regard to sector, experts suggest a unified management and supervision system should be established.

Jang Hang-bae, a professor of Industrial Security at Chung-Ang University, explained, "While there is a formal system in place where the Financial Security Institute, KISA, and the National Intelligence Service handle their respective sectors under the oversight of the National Security Office, it is a fact that it lacks responsiveness because it is divided into councils and has limitations in terms of organizational size and mobility. If decision-making were carried out through a substantial control tower in the security sector, similar to the function of the Office for Government Policy Coordination, it could operate properly."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지