기사 메일전송
"Security is the CEO's responsibility"... Government conducts a comprehensive review of corporate hacking response
  • Yonhap News
  • September 23, 2025 at 12:10 PM
기사수정

"Security is the CEO's Responsibility"... Government Conducts Comprehensive Review of Corporate Hacking Response


CJ ENM, KT Cloud, Bithumb, etc., Attend to Discuss Security Enhancement


Vice Minister Ryu Je-myeong: "Telecommunication companies should also consider external expert verification."


Ryu Je-myeong, Vice Minister of Science and ICT, briefing on the KT unauthorized small payment infringement incidentRyu Je-myeong, Vice Minister of Science and ICT, briefing on the KT unauthorized small payment infringement incident (Seoul=Yonhap News) Reporter Lee Jung-hoon = Ryu Je-myeong, Second Vice Minister of Science and ICT, is briefing on the KT unauthorized small payment infringement incident at the Government Complex Seoul in Jongno-gu, Seoul on the 10th. 2025.9.10 uwg806@yna.co.kr


Amidst a series of corporate hacks leading to personal information leaks, the government has decided to clearly define information protection as the responsibility of the Chief Executive Officer (CEO) and to strengthen related inspections.


The Ministry of Science and ICT held an emergency security inspection meeting on the 23rd at the Korea Information Security Industry Association in Songpa-gu, Seoul, targeting Chief Information Security Officers (CISOs) of major domestic companies to review each company's information protection systems.


The meeting was attended by approximately 30 companies from various industries, including Ryu Je-myeong, Second Vice Minister of Science and ICT; Lee Sang-jung, President of the Korea Internet & Security Agency (KISA); Lee Ki-joo, President of the Korea CISO Council; and representatives from CJ ENM[035760], KT Cloud, GS Retail[007070], Samsung Medical Center, Bithumb Korea, Viva Republica, LG Uplus[032640], and Lotte Engineering & Construction.


Attendees shared their ongoing information protection activities and internal management systems and discussed measures to respond to recent hacking incidents.


Vice Minister Ryu emphasized, "Even if the government prepares various measures, they are useless if security measures are not properly implemented in the field," urging companies to conduct practical security inspections and report to the authorities. This means that each company should clearly identify its key information assets, conduct vulnerability analyses, and then report back to the Ministry of Science and ICT.


It is reported that the authorities specifically focused on whether information protection is being managed as an issue directly overseen by the CEO, whether CISOs are guaranteed sufficient authority, and whether the board of directors and management are actively involved in security operations.


In a phone call with Yonhap News, Vice Minister Ryu stated, "We must fundamentally strengthen security awareness and capabilities with a sense of crisis that information protection is directly linked to a company's survival," adding, "We will also consider having telecommunication companies, due to their large scale, conduct verification work with external experts."


Lee Dong-geun, Head of KISA's Digital Threat Response Division, said at the meeting, "It is important for the CEO to be aware of assets at the internet interface when companies conduct due diligence on their information assets." He added, "If the details of vulnerability countermeasures are reported through the CISO and mid-to-long-term response plans are shared with the government, the CEO will be able to form a consensus on crisis situations and issue necessary directives."


He also proposed a method where the government formally requests CEOs to be informed of related risks and to conduct company-wide inspections to prevent incidents caused by negligent management of backup systems.


Company representatives attending the meeting on this day commonly pointed out the significant difficulties in securing information protection personnel and allocating budgets.


One attendee remarked, "If information protection disclosures go beyond mere announcements on the KISA website and are also disclosed on the Financial Supervisory Service's Electronic Disclosure System (DART), the internal persuasive power for enhancing security systems and budgets will increase."


Another attendee noted, "When calculating security personnel, the inclusion of personnel from partner companies leads to an exaggeration of the organization's actual operating staff, so a separate tally differentiating between full-time employees is needed."


In addition, various proposals were made, including regular joint meetings with CEO participation to discuss security operation systems, tax benefits for security investments, and the introduction of regulations that impose partial responsibility on consignment companies in the event of an incident.


The Ministry of Science and ICT plans to review the adequacy of each company's security investments and management systems based on these inspections and to implement institutional complementary measures if necessary.


Vice Minister Ryu urged, "To create a digital environment where citizens can feel at ease, approximately 30,000 CISOs on the front lines of companies should strive to enhance corporate information protection with a sense of responsibility." Yonhap News



What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site