A month remains before a new era of "10 percent of revenue" fines in which personal data breaches can shake a company's very survival. [Photo: Shutterstock]

A month remains before a new era of "10 percent of revenue" fines in which personal data breaches can shake a company's very survival. For South Korea's three mobile carriers, which suffered a string of hacking incidents last year, an environment is taking shape in which security failures will be harder to treat as one-off accidents. Attention is on whether the three firms, which have announced large-scale security investment plans, can strengthen their security capabilities in practice.

Industry sources and the Personal Information Protection Commission said on Aug. 5 that a revised Personal Information Protection Act will take effect on Sept. 11. It will allow fines of up to 10 percent of total revenue for companies that repeatedly or seriously violate the law.

The tougher fines apply when violations are repeated through intent or gross negligence over the past three years, or when harm is caused to at least 10 million people through intent or gross negligence. They also apply when a personal data leak occurs because a company fails to comply with a corrective order.

For the telecommunications industry, which suffered hacking incidents last year, the change is especially notable. An expanded fine could have a major impact on future business. The fine will vary depending on legal requirements and calculation criteria, but given telecom operators' revenue, the structure allows penalties to grow to the trillion-won level.

The industry also sees security incidents as having become management issues that boards and chief executives must manage directly. The revised act specifies business owners or representatives as the ultimate parties responsible for handling and protecting personal information, and it also strengthens procedures for appointing a chief privacy officer, or CPO. That means hacking incidents can directly lead to massive fines and liability for management.

Security failure is management risk... three telecom operators expand investment

The three telecom operators are also accelerating steps to increase security spending. Disclosures on information security by the Korea Internet & Security Agency showed SK Telecom, SK Broadband, KT and LG Uplus spent a combined 367.5 billion won on information security investment last year, about 22 percent more than 301.2 billion won the previous year. Excluding SK Broadband, total investment by the three mobile operators was 335.3 billion won.

By company, KT was the largest at 127.6 billion won, followed by SKT at 111.1 billion won and LG Uplus at 96.6 billion won. The biggest year-on-year increase was at SKT, up 70.3 percent. LG Uplus rose 16.7 percent and KT increased about 2 percent. The share of information security in IT investment was highest at LG Uplus at 7.7 percent, followed by SKT at 7.2 percent and KT at 6.3 percent.

Medium- to long-term investment plans are larger. SKT decided to invest 700 billion won in information security over the next five years. Based on that, it plans to build a zero-trust security system, double information security specialist staffing and establish a red team.

KT will invest 4 trillion won over three years in information security and IT innovation. It is also strengthening privacy governance by separately appointing a CPO and launching an advisory committee on personal information protection. LG Uplus is also strengthening zero-trust adoption, AI-based security monitoring, and response systems for voice phishing and smishing. LG Uplus is also focusing on strengthening its own security capabilities, including recently acquiring managed detection and response, or MDR, specialist Pagonetworks.

Even with hundreds of billions of won in investment, basic management gaps remain... effectiveness is key

Still, it is important to note that investment amounts are not necessarily proportional to the ability to prevent incidents. An industry official said the structure of recent telecom hacking incidents showed repeated gaps in basic management. The official said management systems and organisational security awareness were more important than the investment amount.

During the SIM information leak incident, SKT was found to have allowed unrestricted access from domestic and overseas internet networks to servers on its internal management network. It did not properly check abnormal logs shown in its intrusion detection system, and security patch application was insufficient.

KT's unauthorised small-amount payment incident also grew worse due to failures in basic authentication and access control. KT set a femtocell certificate validity period at 10 years and did not restrict connecting IP addresses. It also lacked a system to manage cell IDs used on unauthorised devices or detect abnormal access.

LG Uplus faces allegations it reinstalled its operating system and discarded servers suspected of being hacked before authorities began an investigation. Police are investigating the matter on suspicion of obstruction of official duties.

Ultimately, critics say assessing telecom operators' information security competitiveness requires looking not only at total spending but also at where the money was used. They say close examination is needed of replacement rates for ageing operating systems and servers, the speed of applying security patches, records of managing long-unused systems, account and certificate management, the scope of log retention and inspection, and the timing of detecting anomalies.

Choon-sik Park (박춘식), a former professor in the Department of Cyber Security at Ajou University, said disclosure items on information security should also be differentiated according to scale and conditions, such as large companies and mid-sized or small companies. He said the system should be designed to require more specific information from large companies while avoiding excessive administrative burdens on small companies.

He added that the government and experts should jointly identify items that show whether companies properly manage security, such as records of board reporting on security and whether investment plans are implemented. He stressed that companies that properly invest in information security should receive tax benefits or institutional incentives to encourage voluntary efforts to strengthen security.

Keyword

#Personal Information Protection Commission #Personal Information Protection Act #SK Telecom #KT #LG Uplus
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.