The protagonist of the government’s initiative to develop a cybersecurity-specialized independent AI foundation model, commonly referred to as the "Security DOKPAMO" project, was officially selected on the 3rd. It is welcome news that this effort aims to build an AI foundation specialized in security using domestic technology. Now, attention must move beyond merely asking what kind of model will be created. What matters more is how much the resulting model can actually transform security practices in real-world industrial settings.
What the security field needs is not an AI that speaks well. It requires an AI capable of analyzing the flood of threat information generated daily, detecting anomalies within vast volumes of logs, inspecting vulnerabilities, and supporting response efforts when incidents occur. Ultimately, the success of Security DOKPAMO cannot be evaluated solely by model size or benchmark scores. The critical factor is how deeply it integrates into actual security operations on the ground.
To achieve this, a common security service that multiple industries can jointly utilize must first be established. Functions such as malware analysis, vulnerability inspection, threat intelligence, anomaly detection, security monitoring, and incident response are essential regardless of industry sector. If these functions are provided as shared infrastructure, they can offer tangible benefits not only to large corporations but also to SMEs (small and medium-sized enterprises) that lack sufficient security personnel and budgets.
However, security becomes even more challenging from this point onward because the objects to protect and the nature of threats differ across industries. In finance, detecting suspicious transactions, preventing account takeovers, and safeguarding personal information are paramount. For manufacturing, securing smart factories, operational technology (OT), industrial control systems, supply chains, and protecting core technologies from leakage are key challenges. In defense, safeguarding national critical technologies and partner companies is crucial. In healthcare, protection must extend beyond patient data to include the safety of medical devices. The public sector also operates under a distinct security environment due to its handling of nationally important information and administrative networks. Without understanding industry-specific on-site data and operational contexts, AI responses may appear plausible but remain impractical for actual incident response.
Therefore, a single general-purpose AI should not attempt to solve security challenges across all industries using the same approach. While common security functions should be developed collaboratively, services must then be built atop them that reflect industry-specific characteristics such as finance, manufacturing, defense, healthcare, and public sector needs. Even when using the same AI, the data required for training differs, the assets to protect vary, and applicable laws and regulations are not uniform. A foundation for safely accumulating and utilizing industry-specific on-site data is also necessary.
One more consideration is essential. Until now, the focus has primarily been on "AI for Security," which leverages AI to strengthen security measures. Now, preparations must also include "Security for AI," which ensures the safe protection of AI itself. Data poisoning, model theft, prompt attacks, and misuse of authority by AI agents could emerge as new security threats in the future.
It would be a waste to treat the Security DOKPAMO project merely as a standalone technology development initiative. Instead, it should be cultivated into an ecosystem where companies, the security industry, universities, and research institutions continuously accumulate and leverage threat information, incident experiences, and industry-specific expertise. Ultimately, what is needed is not another security LLM. What is required is a common security foundation accessible to all, coupled with professional services that properly understand the differences across industrial settings. We hope Security DOKPAMO will evolve from a laboratory model into "our security AI" that is genuinely deployed and utilized in real-world industrial environments.
