AI Automated Translation.

Font Size

Share

AI agent takes on hacker role… KISA deploys it for first time in simulated penetration training

AI agent takes on hacker role… KISA deploys it for first time in simulated penetration training

Simulated cyber crisis response training for the second half of 2026 / Photo provided by Korea Internet & Security Agency (KISA)
Simulated cyber crisis response training for the second half of 2026 / Photo provided by Korea Internet & Security Agency (KISA)

The Korea Internet & Security Agency (KISA) will pilot the use of AI (artificial intelligence) agents in simulated penetration training to assess corporate cybersecurity levels. Moving beyond the conventional approach where white-hat hackers manually identify vulnerabilities, AI will now create attack scenarios tailored to each company’s website characteristics and examine various intrusion possibilities.

On the 1st, KISA announced that it is jointly with the Ministry of Science and ICT publicly recruiting companies to participate in the '2026 Second Half Cyber Crisis Response Simulation Training' by next month's 2nd.

KISA conducts simulated cyber crisis response training for private enterprises twice a year, in the first and second halves. The training consists of four areas: (1) responding to phishing emails targeting employees; (2) detecting and responding to DDoS (Distributed Denial-of-Service) attacks; (3) simulating penetration of corporate websites; and (4) detecting and responding to vulnerabilities in corporate servers.

The most significant change in this year's training is the use of AI agents for simulated penetration. Previously, white-hat hackers directly analyzed corporate websites to identify vulnerabilities and assess intrusion risks. Starting from the second half, KISA will pilot a new approach where AI agents analyze website-specific characteristics to derive attack scenarios and then evaluate vulnerabilities based on those scenarios.

As generative AI and AI agents are increasingly used in cyberattacks, concerns over the automation and intelligence of attacks have grown. In response, defense training is also being enhanced with AI. KISA plans to use AI agents to explore a wider range of intrusion possibilities than manual methods and elevate the overall level of simulated training.

The effectiveness of repeated training has also been confirmed. According to KISA, companies that conducted more internal security training during the first half of this year showed lower rates of employees opening phishing emails or becoming infected. In DDoS attack drills, companies with prior training experience responded on average more than three times faster than those participating for the first time.

Companies completing the training will receive response guides by category and data on recent security breach trends. Participation can also be recorded in information protection disclosures, which cover investments, personnel, certifications, and activities related to information security. Companies of any size or industry may participate. The recruitment period runs from today until next month's 2nd. Actual training will take place from October 19th to 30th.

Lee Yong-pil, KISA Digital Wi Hyeop-ye-bang (Head), stated, "Through the first-half simulation training, we confirmed that repeated drills effectively enhance an organization's capability to respond to real cyber threats. We have upgraded our training methods to keep pace with rapidly evolving attack techniques, including the use of AI."

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."