AI Automated Translation.

Font Size

Share

[Exclusive] Amid hacking threats… securities firms’ information security staffing ratio has remained stagnant for six years

[Exclusive] Amid hacking threats… securities firms’ information security staffing ratio has remained stagnant for six years

IT security fails to keep pace with trading volume; securities firms also within reach of AI-driven hacking
Information security share of IT workforce stuck in the 9th% range for six consecutive years
IT investment grows only in the 6th% range despite 15% surge in KOSPI daily average trading value
>>>Expectations high that demands to review security capabilities will follow at Financial Services Commission national audit on the 8th

Current status of IT workforce at top 10 securities firms / Graphic by Lee Ji-hye
Current status of IT workforce at top 10 securities firms / Graphic by Lee Ji-hye

The number of information security personnel at South Korea’s top 10 securities firms increased by just six, from 125 at the end of 2024 to 131 in the first half of this year. The average is 13 per firm, and their share of IT (information technology) staff has remained in the 9th% range for six consecutive years, standing at 9.78%. As AI (artificial intelligence)-assisted hacking has breached even the security walls of major banks, there are calls that securities firms must first expand their security workforce.

According to documents submitted on the 6th by the Financial Supervisory Service to the office of Democratic Party of Korea lawmaker Park Hong-bae, a member of the National Assembly’s Political Affairs Committee, the number of executives and employees handling IT tasks at securities firms rose from 1,059 in 2021 to 1,340 in the first half of this year, an increase of 281. Among them, personnel responsible for information security increased by 32, from 99 to 131.

By firm, some increased their information security staff while others reduced it. Mirae Asset Securities grew from 19 in 2021 to 25 in the first half of this year, an increase of six (31.6%), and NH Investment & Securities rose from 16 to 22, an increase of six (37.5%). Shinhan Investment Corp increased by seven (50%), from 14 to 21. In contrast, KB Securities remained unchanged at 14. Daishin Securities decreased from five to four, and Hana Securities dropped from four to three, each losing one person. Meritz Securities saw its IT workforce grow from 37 to 50, but its information security staff increased only from one to two.

Securities firms’ IT investment amounts are also failing to keep pace with the speed of growth in domestic stock trading. IT investment includes not only information security but also IT security and development solutions. According to Park Hong-bae (Rep.), the IT investment executed by the top 10 securities firms last year was 1 trillion 403.4 billion won, a 6.19% increase from the previous year. This falls short of even half the growth rate (15.44%) in KOSPI daily average trading value over the same period. In both 2023 and 2024, the growth rate of IT investment by the top 10 securities firms was lower than the growth rate of KOSPI trading value.

IT investment amounts and growth rates for top 10 securities firms, and KOSPI daily average trading value and growth rates / Graphic by Lee Ji-hye
IT investment amounts and growth rates for top 10 securities firms, and KOSPI daily average trading value and growth rates / Graphic by Lee Ji-hye

The slow increase in information security personnel relative to IT investment is also cited as a problem. From 2021 to 2025, the IT investment of the top 10 securities firms increased by 42.1%, from 987.6 billion won to 1 trillion 403.4 billion won, while information security personnel grew by only 26.3%. In other words, not only is IT investment itself insufficient relative to rising trading volumes, but investment in information security within that remains stagnant.

Amid this, external hacking groups are believed to have conducted so-called “security system scans” against several securities firms as a preliminary investigation, heightening vigilance. A senior official in the financial investment industry said, “It has been determined that hackers scanned (checked) several securities firms for security vulnerabilities.” He added, “While they did not actually attempt access, this is an extremely serious matter, so the industry is strengthening security to the maximum extent, including real-time monitoring and sharing of the situation.”

As seen in the recent bank incident, where a “weak link” was breached through external partnerships and ancillary channels such as loan solicitor and employee work manual apps, there are opinions that securities firms should strengthen their management of third-party IT risks. Securities firms have recently strengthened partnerships and cooperation with virtual asset businesses, asset management companies, and non-financial channels. In this regard, a financial investment industry official explained, “We are applying the Financial Services Commission’s guidelines for third-party IT risk management in the same way as the banking sector.”

Ahead of the Financial Services Commission national audit on the 8th, the National Assembly’s Political Affairs Committee is also urging the industry to strengthen IT security and information protection. Park Hong-bae (Rep.) stated, “As the scale and trading volume of the stock market have grown rapidly, it is necessary to check whether securities firms’ security systems are at a commensurate level.” He added, “The financial authorities and the securities industry must recognize financial security as essential infrastructure for investor protection and proactively strengthen overall security capabilities across systems and personnel.”

"This article was translated using AI and may differ slightly from the original."