"As the National Network Security Framework (N2SF) is introduced, zero-trust-based security is expanding in the public and financial markets, and there is more room for SaaS-based SSE to move in."
Monitorlab is making a full push into the public sector, a market it has long found difficult to enter, by leading with its Security Service Edge (SSE) platform. It also appears to be looking for higher growth in global markets than before.
Monitorlab CEO Lee Gwang-ho (이광후) held a briefing with reporters on Sept. 9 at the Integrated Application Security Fair 2026 (IASF 2026) and said, "Until now, there were many practical difficulties in supplying SSE to the public sector, but the atmosphere has changed with the introduction of N2SF. There are still obstacles, but the government's position is clear that it will enable public agencies to adopt SECaaS (Security as a Service)."
SSE, Monitorlab's main specialty, integrates multiple security functions into one and provides them through the cloud, including secure web gateway, cloud access security broker, remote browser isolation and zero-trust access. It is a solution that falls under SECaaS (Security as a Service).
The public sector has been structured so that public agencies cannot use cloud-based security products because of network separation policies. In this context, the National Intelligence Service introduced N2SF, a system that moves away from a uniform network separation structure and allows less important information to be disclosed on the internet.
N2SF's core is to divide data importance into C (Classified), S (Sensitive) and O (Open), and to allow O-grade data to be disclosed on the internet.
It is not mandatory, but the National Intelligence Service, which has strong influence in the public security market, is using it as a guideline. The government is also encouraging public agencies to apply N2SF. The related industry has high expectations that a new security market that did not exist in the past will open. Lee's effort to break into the public sector with SECaaS is also based on this situation.
Even if the barrier to SECaaS in the public sector has been loosened, there are practical difficulties. Certifications needed to enter the public sector remain a burden in terms of cost and time. To push SECaaS into the public sector, companies need a National Intelligence Service security function confirmation letter or CC (Common Criteria) certification, as well as the Ministry of Science and ICT's Cloud Security Assurance Program (CSAP).
CSAP is divided into SaaS and IaaS. For a SaaS company to obtain CSAP, it must also obtain certification in the IaaS category. Since it is known that obtaining each certification costs hundreds of millions of won, it may not be easy for smaller security firms to pursue certifications unless demand supports it. Even if the door for SECaaS to enter the public market has opened, it remains uncertain whether demand will increase enough to justify spending money to obtain certifications.
The National Intelligence Service said it would introduce a new cloud security certification system to replace CSAP, but it is reported to be similar to CSAP in broad terms. Given that it is not easy to obtain CSAP related to IaaS beyond SaaS, Monitorlab is also cooperating with LG Uplus. LG Uplus provides U+SASE, a cloud-native integrated security platform, in cooperation with domestic security firms including Monitorlab.
Lee said, "Domestic security companies are emerging that want to jump into the SECaaS market, and the fact that there are certifications needed to target the public sector could become a barrier to entry for other companies," showing confidence.
Founded in 2005, Monitorlab built its position in the web firewall market based on its own proxy technology that relays requests and responses in a web traffic environment and filters harmful access. In 2016, it unveiled its SECaaS platform, AionCloud, expanding its business into cloud security services. In 2025, it acquired Soma, an EDR specialist focused on threat hunting, expanding from network security to endpoints. It has recently released a generative AI security solution.
Revenue stagnated at 14.2 billion won in 2023 and 14.9 billion won in 2024, then rose to 19.2 billion won in 2025. The average growth rate over the past 3 years is 8.8 percent. Lee said, "Revenue growth in on-premise appliances is modest, but subscription platform revenue such as AionCloud is growing rapidly."
AionCloud is an SSE platform that bundles web firewall, secure web gateway (SWG), cloud access security broker (CASB), remote browser isolation (RBI) and zero-trust network access (ZTNA) functions into one. It is currently provided through 40 global edge infrastructures in 15 countries.
Monitorlab has proactively invested in its own infrastructure to provide AionCloud even when domestic demand has not been strong. Lee stressed that this puts the company in a favorable position in many ways compared with companies starting now. He said, "Overseas revenue accounted for about 2 percent of total revenue as of last year, but inquiries and demo requests are increasing in Japan and elsewhere," adding, "We will expand our share of the global SSE market by leveraging local subsidiaries in the United States and Japan and overseas partnerships."
Generative AI security is also a keyword Lee emphasizes as a new growth engine. The main theme of IASF 2026 was also generative AI security. Monitorlab provides GenAI Security, a generative AI security solution focused on preventing prompt injection, AI misuse and sensitive information leakage that may occur during corporate use of generative AI. GenAI Security can be used both as an on-premise solution and as a service on AionCloud.
Lee said, "We are preparing AI agent security as the next stage after generative AI security," adding, "We will expand the security scope to include traffic of MCP (Model Context Protocol), the standard protocol that connects AI agents with internal data and systems. We will identify which agent calls which tool registered on which server and how, block unauthorized calls based on an allowlist, and leave all call histories as audit logs to support post-incident tracking."