AI Automated Translation.

Font Size

Share

Expanding the scope and frequency of inspections is not enough… Without "asset identification," AI-driven hacking cannot be stopped

Expanding the scope and frequency of inspections is not enough… Without "asset identification," AI-driven hacking cannot be stopped

Status of IT asset vulnerability inspections in the financial sector and issues with asset identification / Graphic by Reporter Kim Hyeon-jeong
Status of IT asset vulnerability inspections in the financial sector and issues with asset identification / Graphic by Reporter Kim Hyeon-jeong

Even if vulnerability inspections are conducted more frequently and cover a broader range, blind spots for hacking will remain if financial institutions fail to comprehensively identify which IT assets they possess. As attacks leveraging artificial intelligence can exploit gaps in services excluded from regular inspection targets, there is a growing call for a system that makes "asset identification" a continuous process, rather than simply increasing the number of inspections.

According to industry sources on the 7th, while major commercial banks operate approximately 40 to 50 external-facing websites and web services each, the total reaches 300 to 400 when internal business systems used by employees are included. These internal systems include not only intranets but also various services for different business divisions, such as loan-related operational systems and systems used by capital markets departments to retrieve external information like bond yields and exchange rates.

Banks have conducted self-inspections on systems that are not subject to mandatory inspections. In particular, KakaoBank manages approximately 100 external and internal websites and web services as security inspection targets, regardless of whether they fall under legally mandated inspection requirements. The bank conducts regular inspections at least four times a year through the Financial Security Institute, information protection specialist firms, and penetration testing specialists, and performs ongoing checks when launching new services or adding features.

Since inspecting internal systems is not mandatory, management practices vary from bank to bank. One bank aims to inspect its internal services once a year while conducting ad hoc inspections in parallel, while another implements themed inspections with different focuses each time. Ultimately, assets outside the scope of mandatory inspections are left to the discretion of the banks, resulting in differences in inspection scope and frequency.

As financial regulators have decided to shorten the cycle for vulnerability analysis and assessment and expand the scope of inspections, it is expected that this will help reduce existing blind spots. Given the varying levels of management among financial institutions, there is an evaluation that expanding the scope of mandatory inspections is meaningful. A source from the Financial Services Commission stated, "We are pursuing a multi-faceted and systematic approach to supplementary measures, including shortening the vulnerability analysis and assessment cycle, expanding the inspection scope, and strengthening enforcement mechanisms."

"If we don't even know how many IT assets we have, how can we defend against AI?… Continuous identification must come first"

However, no matter how much the inspection scope is expanded, if financial institutions fail to comprehensively identify the services they operate and the IT assets within them, these may still be overlooked in the newly expanded inspection network.

A source in the financial sector noted, "Even a single app consists of multiple assets such as servers, databases, and network equipment, and their composition and number are constantly changing." The source added, "When internal systems are included, the number of items to be managed reaches several hundred, making it difficult even to determine what should be inspected and to what extent if assets are not accurately identified."

Assets outside the scope of mandatory inspections are also not subject to continuous reporting to regulators, making it difficult to grasp how many are actually being identified. Financial institutions undergo vulnerability inspections for electronic financial infrastructure facilities by the Financial Services Commission and for public-facing websites by the Financial Supervisory Service. The Korea Financial Data & Exchange receives open banking vulnerability checks on a two-year cycle, while MyData services undergo security vulnerability verification once a year by the Financial Security Institute. In contrast, banks state that it is confidential information how many of their other internal business assets are identified and managed.

Ultimately, in the AI era, there is an argument that knowing "what needs to be inspected" comprehensively takes precedence over "how frequently inspections are conducted." Professor Kim Seung-ju from the Graduate School of Information Security at Korea University stated, "Asset identification is the first button of security. Even with an AI defense system, if assets are not identified, the targets for application may be omitted." He added, "As U.S. federal government systems update asset information on a weekly basis, South Korea should move beyond inspections conducted one to two times a year to establish a system that continuously grasps assets and uses AI to inspect vulnerabilities based on that understanding."

"This article was translated using AI and may differ slightly from the original."