South Korea's Financial Supervisory Service called in chief information security officers (CISOs) from financial companies and urged stronger responses to cyberattacks using artificial intelligence (AI). It plans to conduct on-site inspections of high-risk financial firms with weak basic IT controls. It also said it will take tough measures if passive self-corrections lead to a large-scale incident.
The FSS said on Tuesday it held a meeting of CISOs across the financial sector, chaired by Lee Jong-oh (이종오), deputy assistant governor for the digital and IT division. CISOs from 16 major financial companies attended, along with officials from associations related to banking, financial investment, insurance, credit finance, savings banks and fintech.
The FSS urged financial companies to build an enterprise-wide IT risk management system centred on top management and to strengthen IT asset identification and management, security vulnerability management and response systems for large-scale patching. It plans intensive management of companies with weak responses through close monitoring, on-site inspections and interviews with executives.
It said companies need to identify and centrally manage all IT assets, including systems and programs, cloud services and open source, and to internalise and automate vulnerability response procedures, such as setting patch priorities based on the importance of assets and business operations. It also told firms to establish consumer protection systems, including rapid service restoration and customer notification and compensation, when security incidents occur.
It will also strengthen checks on basic IT controls. The FSS said a significant portion of recent major IT incidents stemmed from weak basic controls, such as failing to apply security patches, leaving accounts of retired employees active, insufficient encryption of user information and inadequate testing of program changes.
The FSS will use a self-assessment tool through November to check five areas: protection of information processing systems, protection of electronic data, hacking prevention, management of public-facing web servers and controls over program changes. In future inspections, it plans to focus on the state of basic control operations and to conduct on-site inspections of high-risk companies.
The FSS said it will actively consider reducing sanctions for minor incidents at financial companies that fully remedy shortcomings through self-corrections. If weak basic IT controls lead to large-scale IT and security incidents due to formal or passive self-corrections, it will take the toughest possible measures.
Lee said, "Frontier AI-based security threats are not a vague concern but a real issue directly tied to the survival of financial companies." He added, "Management, including the CEO, should expand organisation, personnel and budgets and move to strengthen security across the enterprise."