AI Automated Translation.

Font Size

Share

Regulations unchanged for a decade, blind to the AI era… Financial firms face major overhaul of vulnerability checks, now required at least twice a year

Regulations unchanged for a decade, blind to the AI era… Financial firms face major overhaul of vulnerability checks, now required at least twice a year

Homepages of seven financial firms hit by suspected AI-driven hacking attacks are not subject to statutory vulnerability assessments
Financial Services Commission to shorten vulnerability analysis and evaluation cycle from once to twice a year for financial firms, and significantly expand the scope of mandatory homepage inspections
Also pushing to introduce enforcement fines of up to 50 million won per case

Vulnerability analysis and evaluation under the Electronic Financial Transactions Act (introduced in 2015) and proposed amendments / Graphic = Lee Ji-hye
Vulnerability analysis and evaluation under the Electronic Financial Transactions Act (introduced in 2015) and proposed amendments / Graphic = Lee Ji-hye

As a response to successive hacking incidents in the financial sector, plans are being pushed forward to shorten the cycle for vulnerability analysis and evaluation to at least once a year, and to significantly expand the scope of application for mandatory homepage inspections conducted twice a year. The recent hacking attacks, suspected to be carried out by AI agents, occurred on the "peripheral" systems of financial firms, yet these systems were not subject to statutory vulnerability checks. Criticism has emerged that current security regulations, introduced in 2015, are ill-suited for the age of artificial intelligence (AI).

According to financial authorities on the 6th, the Financial Services Commission is pushing a plan to significantly expand the scope of vulnerability analysis and evaluation for electronic financial infrastructure under the Electronic Financial Transactions Act. This is one of the follow-up measures in response to data breaches caused by suspected AI agent hacking attacks at seven financial firms recently.

Vulnerability analysis and evaluation for financial firms can be called the "starting point and foundation" for information security, but current regulations were established in 2015. Despite AI-driven hacking occurring openly, criticism has arisen that related regulations, created a decade ago before the experience of AI, have failed to keep pace with the times.

The financial authorities are first considering shortening the cycle for vulnerability analysis and evaluation of electronic financial infrastructure from the current minimum of "once a year" to at least twice a year. Financial firms with assets of 2 trillion won or more and a permanent workforce of 300 or more, or electronic financial service providers, are required by regulation to conduct self-inspections or contract with external firms to check for vulnerabilities, and to report periodically to the Financial Services Commission.

A source in the financial sector said, "Since the current standard is a minimum of once a year, most financial firms only meet the minimum requirement," adding, "If the inspection cycle is shortened, financial firms will need to have greater awareness of security and hacking risks, and invest more in costs and personnel."

The twice-yearly homepage (webpage) inspection cycle and scope will be significantly strengthened from current levels. Currently, only homepages involving financial transactions such as payments or transfers are subject to inspection. Since the law was enacted in 2015, most targets were homepages open to customers, such as internet banking. Homepages not involving financial transactions were excluded from the inspection scope. The recent suspected AI agent hacking attacks occurred on loan solicitor homepages and internal sales support homepages for employees, which are not included in the inspection scope under current regulations.

Financial firms operate a minimum of several dozen to over 100 homepages each. Consequently, when conducting twice-yearly homepage vulnerability checks, unclear regulations led to inconsistent inspection scopes across different financial firms.

A source in the financial sector said, "Just as rotting fruit on one side causes surrounding fruit to rot, if a homepage not involving financial transactions is vulnerable, we cannot guarantee the safety of customer-facing internet banking," adding, "Expanding the scope of homepage inspections is necessary to prepare thoroughly for hacking."

Substantial sanctions are also being pushed for financial firms that fail to conduct vulnerability checks. Currently, even if compliance is not met, financial authorities do not have appropriate sanction measures and limit themselves to verbal warnings. The government and the National Assembly introduced a bill at the end of last year to introduce enforcement fines of up to 50 million won in cases of non-compliance or violation of safety assurance obligations. Since the fine is per case, actual penalties could snowball. This places a significant burden on financial firms.

A source from the financial authorities stated, "Vulnerability checks are the fundamental basis for the security of financial firms, and we are reviewing institutional improvements to significantly strengthen regulations on vulnerability checks, including the enforcement fines announced earlier," adding, "We plan to swiftly supplement the system to ensure the financial sector maintains a higher level of awareness, taking the data breach incidents as an opportunity."

"This article was translated using AI and may differ slightly from the original."