An analysis by the office of National Assembly Political Affairs Committee member Park Sung-hoon found that 20 financial firms with frequent system outages spent only about 305 billion won of their 438 billion won information-security budget last year. The figures emerge as the sector is repeatedly breached by hacking believed to involve AI.
According to Financial News, People Power Party lawmaker Park Sung-hoon analyzed data from financial authorities and found that the top 20 financial firms by number of system outages had a combined information-security budget of 438 billion won last year, of which 305.03 billion won was actually spent, an execution rate of 69.6%. Woori Bank spent 42.327 billion of 78.659 billion won, the lowest at 53.8%, followed by KB Kookmin Bank and Hanwha Life at 58.1% and Suhyup Bank at 60.7%.
광고 문의 · 300×250Many also cut this year's budgets. The same report said 7 of the 20 reduced their information-security budget from the previous year. Woori Bank cut 21.7% to 61.566 billion won, Citibank Korea cut 18.0% to 7.297 billion won, and Shinhan Bank cut 10.4% to 40.591 billion won. Hanwha Life, the Korea Development Bank, K Bank and Standard Chartered Korea also trimmed budgets, but the reduction rates were not given.
The timing is sensitive. According to Dailian, hacking incidents recently hit seven financial companies in succession, and authorities identified and circulated 28 IP addresses believed to be used in attacks involving AI agents. The Financial Supervisory Service issued a 12-item checklist and ordered all 500 firms in the sector to run emergency self-inspections, and Financial Services Commission chairman Lee Eog-weon urged at a meeting on the 4th that a system be built to defend against AI attacks with AI.
A low execution rate alone does not prove that investment was inadequate, since project schedules can slip and contracts can roll over after a budget is set. However, as Financial News reports, the sample is 20 outage-prone firms and some also cut this year's budgets, so there are calls for authorities to examine where security investment ranks among priorities.
Gaps in the rules were also pointed out. Dailian reported that current electronic financial supervision rules only require information-security budgets of at least 7% of the IT budget and security staff of at least 5% of IT staff, with disclosure not mandatory. An amendment to the Electronic Financial Transactions Act, which would clarify CEO responsibility and impose fines of up to 3% of total revenue for customer data leaks, has been pending in the Assembly for over ten months. Park stressed that weak security investment cannot be called management efficiency but is an issue of trust in the financial system, and that authorities should review investment practices comprehensively and hold lagging firms accountable rather than announcing measures after each incident.