[비즈한국] The burden of security has grown significantly for the three major telecommunications companies, following a series of massive personal data breaches, hacking incidents, and allegations of leaks. This comes as the amended Personal Information Protection Act took effect on the 11th, allowing for fines of up to 10% of total revenue for repeated or severe personal information infringements. While each company is increasing investments in information protection and expanding personnel, there are differences in how they are refining their accountability structures following these incidents.

KT and SKT Separate CISO and CPO… LG Uplus Maintains Dual Roles
According to the telecommunications industry on the 15th, KT and SK Telecom have refined their security organizations and management systems following a series of hacking and data leakage incidents. On the other hand, while LG Uplus is increasing its security investment, it maintains its existing system where one person holds both the Chief Information Security Officer (CISO) and Chief Privacy Officer (CPO) roles.
KT recruited a professional from the Korea Financial Telecommunications & Clearings Institute as CISO, and in April, appointed Kim Chang-oh, a former information security program manager (PM) at the Ministry of Science and ICT, as CPO, separating the two roles. Since then, it has strengthened information security governance centered on the CISO and established a "Red Team," a dedicated organization that examines the company's defense system from the perspective of an actual attacker.
SK Telecom began by reforming its security accountability structure. It elevated the CISO organization to be directly under the CEO and appointed a separate CPO, thereby separating the two roles. It also expanded the CPO's authority to manage and supervise the company's overall personal information assets, including IT and infrastructure. The scope of information security certification has also been expanded to include mobile phone customer management systems and key services.
Since the inauguration of CEO Hong Bum-seok, LG Uplus has been expanding a system to identify and respond to security risks in advance, such as by acquiring the security specialist company Fago Networks and participating in the "CVD (Coordinated Vulnerability Disclosure) and VDP (Vulnerability Disclosure Program) pilot project" promoted by the Ministry of Science and ICT. However, the current Head of the Information Security Center holds both the CISO and CPO roles, and it is understood that there are no plans to separate the two positions, even following recent hacking allegations.
Having one person hold both CISO and CPO roles, or having the CPO take on other duties, is not in itself a violation of the law. It is also difficult to conclude that separating the two roles will prevent personal data leaks. However, while the CISO is responsible for incident response and overall information protection, the CPO oversees the entire process from the collection and use to the storage and destruction of personal data. The amended Personal Information Protection Act has made the CPO's authority and the representative's final responsibility more explicit.
The amended law also includes provisions to guarantee the authority and status of the CPO to perform personal information protection tasks independently, and to ensure that necessary personnel and budgets are provided. What matters is whether the CISO and CPO are equipped with the necessary authority, personnel, and budget to effectively perform their respective roles. Regardless of whether roles are combined, the key is how the actual personal information management and supervision system is operated.
Expanding Security Investment and Personnel… Follow-up Measures are Ongoing
The three major carriers are also investing in information protection alongside organizational restructuring. According to the Korea Internet & Security Agency's information protection disclosures, last year's information protection investments were 127.6 billion won for KT, 126 billion won for LG Uplus, and 111.1 billion won for SK Telecom. However, it is difficult to compare security capabilities based solely on investment amounts, as the scale of operations, information system configurations, and the range of assets to be protected differ.
Expansion of dedicated personnel is also underway. SK Telecom has increased its dedicated information security staff by 56% compared to the previous year. KT has more than half of its 317 dedicated information security staff as internal security personnel and is working to secure additional staff. Following a recruitment drive for experienced security deliberation personnel last month, it is currently recruiting experienced security architects this month.
Apart from increased investment, challenges remain. SK Telecom is still in the process of implementing some measures, such as expanding the application of EDR (Endpoint Detection and Response) for real-time monitoring and blocking, and expanding the scope of ISMS-P (Information Security Management System & Personal Information Management System) certification. In July, KT also received a corrective order from the Personal Information Protection Commission to inspect vulnerabilities in overall communication equipment such as femtocells and to establish and report within three months on recurrence prevention measures, including the substantive performance of the CPO's role.
Regarding the disposal of relevant servers before the investigation into suspected personal data leaks began last year, the Personal Information Protection Commission views the possibility of evidence destruction as a concern and has requested an investigation by authorities. This is a matter for which facts and responsibilities must be confirmed through the investigation; evidence destruction has not been finalized.
Trillion-Won Fines for Repeat Offenses: Is It Actually Possible?
The backdrop to the carriers accelerating their security system enhancements is the significantly increased burden of potential fines. As the amended Personal Information Protection Act and its enforcement decree and notices took effect on the 11th, it has become possible to impose fines of up to 10% of total revenue for repeated or severe personal information infringements.
Targets for the special provision include cases where violations have been repeated over the past three years due to intent or gross negligence, cases where damage has been caused to more than 10 million people due to intent or gross negligence, and cases where accidents such as data leaks have occurred due to failure to comply with corrective orders. It is not that the maximum 10% is applied immediately just because an accident occurred or the scale of damage is large. The mandatory ISMS-P certification for mobile carriers is scheduled to be implemented starting next July.
To estimate the scale of the burden, a simple calculation of 10% of last year's consolidated revenue equates to approximately 2.82 trillion won for KT, 1.71 trillion won for SK Telecom, and 1.55 trillion won for LG Uplus. However, this figure is a simple calculation; actual fines are calculated by reflecting the severity of the violation, the duration and frequency, the scale of damage, and efforts toward investigation cooperation or recurrence prevention. Nevertheless, if an accident meeting the special requirements occurs, the financial risk the carriers would have to bear has increased significantly compared to before.
However, some suggest that the threshold for the enhanced special fines to be actually applied is quite high. The industry perspective is that for large corporations like telecommunications companies that receive security certifications and continue large-scale security investments, it is difficult to acknowledge intent or gross negligence solely based on the fact that an accident occurred.
An industry official stated, "Intent or gross negligence assumes highly exceptional situations, such as not taking necessary measures despite knowing the possibility of a personal information leak. The likelihood of actual application to companies like telecommunications firms that have received security certifications and continuously invested is not high. It has a strong punitive character aimed at cases where investigations confirm that essentially no preparation was made."