Unannounced On-Site Inspections for Self-Correction

Strict Measures for Inadequate Basic IT Controls

The Financial Supervisory Service encouraged the chief executive officers and management teams of financial companies to implement organization-wide measures to strengthen information technology (IT) security and secure necessary resources, including organizations, budgets, and personnel, on September 9. The agency announced plans to conduct on-site inspections of high-risk financial companies with insufficient basic IT controls during future examinations.


Financial Supervisory Service headquarters in Yeouido, Seoul. Financial Supervisory Service

Financial Supervisory Service headquarters in Yeouido, Seoul. Financial Supervisory Service

View original image

On the afternoon of September 9 at its Yeouido headquarters in Seoul, the Financial Supervisory Service, with Deputy Governor for Digital and IT Affairs Lee Jongoh presiding, held a "CISO Meeting for the Entire Financial Sector" and called on financial institutions to reinforce internal IT controls. The meeting was attended by executives from banking, investment, insurance, credit, savings bank, and fintech associations, as well as CISOs from 16 companies.


This meeting was organized to review the responses of financial institutions to the reality of frontier artificial intelligence (AI)-driven cyber threats and to encourage the strengthening of response systems led by top management.


According to the Financial Supervisory Service, security threats have increased since the release of Anthropic's frontier AI model Mithos in April.


The number of new vulnerabilities disclosed by the U.S. National Institute of Standards and Technology (NIST) rose from 23,664 in the first half of last year to 35,872 in the first half of this year, marking an increase of 12,208 cases (51.6%). The number of security advisories announced by the Korea Internet & Security Agency (KISA) also grew by 63 cases (46.3%) during the same period, from 136 to 199.


In response, the Financial Supervisory Service assessed that with the possibility of AI being misused for hacking, not only could security vulnerabilities be detected more quickly, but large-scale automated attacks targeting multiple financial institutions could also become possible. The agency stressed the heightened need to reinforce the financial security system.


At the meeting, the Financial Supervisory Service discussed: ▲ Strengthening preparedness against AI-based security threats and ▲ Establishing thorough basic IT controls and self-correction systems within financial institutions.


First, the Financial Supervisory Service emphasized that at the organizational level, financial institutions must complete critical tasks such as ▲ establishing IT asset identification and management frameworks and ▲ preparing for large-scale security patches. The agency encouraged active participation from management, noting that accomplishing these tasks requires significant time and resources.


For financial institutions that demonstrate inadequate responses, the Financial Supervisory Service plans to intensively manage them through close monitoring, on-site inspections, and executive meetings.


The agency also addressed shortcomings found in basic IT controls, in addition to AI security. Since July, it has been promoting "self-correction" across the financial sector, whereby institutions inspect and improve basic IT control compliance on their own initiative.


The Financial Supervisory Service has called on financial institutions to establish effective self-correction systems by proactively identifying and addressing weaknesses in internal controls in a timely manner.


The agency further stated that in future examinations, it will focus on actual practices regarding basic IT controls, and will conduct on-site inspections of high-risk institutions with insufficient controls.


To support the establishment of effective self-correction systems, the Financial Supervisory Service announced plans to promptly share critical threat intelligence and diagnostic tools (checklists) with financial institutions. It will also improve the effectiveness of self-correction through unannounced on-site inspections.


Deputy Governor Lee stated, "If basic IT controls are compromised in an era of accelerated AI-driven cyberattacks, incidents could be repeated and lead to significant damage for both financial institutions and their customers. I urge management to take the lead in self-correction for establishing robust basic controls."



He added, "If formalistic or passive self-correction leads to insufficient basic IT controls and causes large-scale IT or security incidents, the Financial Supervisory Service will enforce the strictest measures possible."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing