"Security Networks Vulnerable Even to Low-Cost AI... Financial Sector Needs a 'Joint Shield'"
[AI Targeting the "Weak Links" in Finance] ②
Small and Midsized Firms Struggle with Limited Security Personnel and Budgets
Joint Security Monitoring via the Financial Security Institute as an Alternative
Large Firms and Partners Must Strengthen Supply Chain Security Together
As hacking techniques utilizing artificial intelligence (AI) become more sophisticated, there are increasing calls for the financial sector to shift to AI-based defense systems. In particular, as small and midsized financial firms lack adequate budgets and security personnel, making it difficult for them to independently acquire expensive equipment and expertise, there is a growing consensus on the need for a joint response framework at the industry level. Experts stress the importance of leveraging security assessments by specialized institutions and shared security monitoring, thereby reducing costs, while large financial companies should also work to raise the security standards of their partners.
Narrowing the Gap in AI Security Capabilities... Regulatory Authorities Share Vulnerability Information Across the Financial Sector
Cha Sangmi, Professor in the School of Business at Ewha Womans University, commented on September 14, "Attackers are already creating malicious code and probing vulnerabilities with widely available AI APIs that cost as little as tens of thousands of won, while small financial institutions on the defense side are restricted by network separation and unable to use general-purpose AI as a defense tool--this is like telling someone to stop bullets with stone axes." She emphasized, "The smaller and mid-sized firms that cannot afford expensive security equipment have an urgent need to use general-purpose AI for source code analysis and vulnerability detection."
As generative AI accelerates the speed of attacks, there are calls for establishing an institutional framework that would allow small and midsized financial firms to leverage external security services, such as AI/software-as-a-service (SaaS)-based vulnerability detection and source code reviews.
She pointed out that instead of simply setting relaxed network separation requirements based on company size (such as over 2 trillion won in assets), the standards should be subdivided according to risk and connectivity—such as the amount of data held, API traffic, and actual security capabilities. Professor Cha said, “As long as minimal technical safeguards like data masking and security gateways are in place to prevent the leakage of core personal information or critical assets, small and midsized financial institutions should be allowed to utilize AI-based defense tools.” She added, “Easing network separation should not just be viewed as a move to improve operational efficiency for large firms, but as a way to enhance the defensive capabilities of small and midsized financial institutions.”
However, expanding external connectivity could provide new channels for attack, especially for companies with insufficient security capabilities. An official from the Financial Services Commission commented, “Rather than applying relaxed network separation rules uniformly, we must consider each company’s security capabilities and risk levels. Companies that lack sufficient security capability or technological expertise should utilize external vulnerability analysis and specialist agency support.”
The authorities plan to reference vulnerabilities, attack methods, and response measures identified in ongoing AI security tests in future industry-wide guidelines, sharing this information across the entire financial sector. After assessing the feasibility of AI-based attacks on companies with a certain level of security capability, the aim is to collectively accumulate cases and experience in responding, thereby narrowing the gap in security capabilities between companies.
Limits of Going It Alone for Small and Midsized Firms... Industry-Wide "Joint Security Monitoring" Needed
The problem is that small and midsized financial institutions have limited security staff and budgets, and do not have sufficient capabilities for an independent response. Jun Deokjo, CEO of cybersecurity firm CQB Star, said, “For small and midsized financial firms, even if advanced security solutions are provided or adopted, there is often a lack of expert personnel to operate them, or security awareness among CEOs and frontline staff is low, so security services are not proactively strengthened. Simply providing security equipment or vouchers to individual companies is not enough—we need a system that offers joint security monitoring and vulnerability response for small and midsized firms.”
In addition to the government's support for vulnerability assessments, penetration testing vouchers, or matching funds for equipment, there is a need for a system that can collectively manage the security of multiple small and midsized financial institutions and support incident response.
One proposed approach is to utilize specialized financial security organizations. Rather than having small and midsized institutions purchase expensive equipment or hire dedicated experts, the Financial Security Institute could provide security assessments and technical support across multiple firms. This year, the Financial Security Institute is conducting vulnerability analysis and assessments for 178 financial institutions, including comprehensive assessments, individual reviews, and checks of websites accessible to the public. The dedicated penetration testing team has also been expanded from six to twenty members.
Strengthening security in consignment and partnership processes where large financial firms are connected to PG companies, merchants, and other partners is also imperative. This is because attackers often breach the systems of less secure partners first and then move laterally to access large firms’ systems or customer data. In the case of Toss Payments, authentication information (integration keys) for the payment integration platform used by particular merchants was exposed externally, allowing third parties to view payment records. A total of 4,131 payment records and data for 2,671 individuals were exposed.
Yeom Heungyeol, Professor in the Department of Information Security at Soonchunhyang University, said, “Attackers can infiltrate less secure partners and then access the systems or customer data of major firms. It's essential to minimize access privileges, implement multi-factor authentication, maintain network separation and isolation, detect abnormal activities, and conduct regular supply-chain security assessments.”
Large Firms Are Not Exempt... Building a "Joint Shield" with Partners
There is also a recommendation that both large and small/midsized financial firms build cooperative defense networks—a "joint shield." This involves large companies providing common funding at the industry level to support security reviews and the construction of security infrastructure for their smaller peers. Since financial companies share data among various players—card companies, insurers, PG companies, and more—an incident in one place can quickly spread to other firms or compromise customer data.
Professor Yeom stated, “Because it is difficult for small and midsized financial firms to independently raise their security capabilities, support is needed for joint security monitoring, the costs of deploying security solutions, hiring and training expert personnel, and conducting incident response drills. Large firms should expand mutual support to raise partners’ security levels, and the government should set minimum security standards and frameworks for joint response suitable for small and midsized financial companies.”
There is also discussion of having industry associations outsource member companies’ security assessments to the Financial Security Institute. Associations—for savings banks, card companies, loan companies, fintech firms, etc.—would share some costs, and the specialized security organization would scan websites and source code to detect and address vulnerabilities in advance. A Financial Security Institute representative commented, “If individual financial firms make joint use of AI-based assessment services from a specialized institution, instead of each separately acquiring costly security solutions or expert personnel, they can reduce both cost and workforce burdens while raising security standards.”
Hot Picks Today
"This Chuseok Feels Too Short, Let's Take Monday Off Too"... Anticipation Grows for Surprise Designation of September 28 as a Temporary Public Holiday
- "Each 10-Won Drop in Exchange Rate Boosts Profit by 2.5 Billion Won"...Stocks Benefiting from the Strong Won at 1,340 Won Level
- '12 Billion Bottles of Surplus' – Enough for the World to Drink for 3 Years... Wasn't MZ Just Trending Recently?
- "The First Thing You Do at a Restaurant May Expose You to Harmful Substances While Trying to Be Polite"
- "What Did They Put on the Porsche?"...The Story of a 27-Year-Old Chinese Owner Who Covered Their Car with Photos of 90 Missing Children
Joint countermeasures are also being pursued overseas. The Society for Worldwide Interbank Financial Telecommunication (SWIFT) has conducted a case study with 13 global banks using federated learning, allowing them to collaboratively advance fraud detection models without transferring data outside their respective banks.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.