As AI-Driven Hacking Threats Grow, Security Staff at GAs and Capital Firms Remains in Single Digits
[AI Targets the Weak Links in Finance] ①
Major Banks Average 91.9 Security Staff... GAs at 1.3, Capitals at 7
Even with Increased Security Budgets, Manpower and Overall Scale Are Limited
Low-Cost AI Boosts Attack Capabilities... Small Firms
While generative AI is rapidly standardizing and elevating cyberattack capabilities, the defensive strength of small and mid-sized financial institutions is not keeping pace. These institutions lag far behind larger players in both security personnel and investment scale. With increased interconnectedness in the financial network, their vulnerabilities are more likely to spread risk throughout the sector. Experts point out the need to move away from leaving security solely to individual institutions, calling for initiatives to enhance the defensive measures of small and micro financial firms to reduce the overall "security asymmetry" within the industry.
As Banks Approach 100 Dedicated Security Personnel, General Agencies Have Only 1... Absolute Resource Limits Despite Higher Investment Ratios
According to the Korea Internet & Security Agency (KISA) on September 14, this year Shinhan Savings Bank had an average of 6.1 dedicated information protection staff, Welcome Savings Bank had 7.8, and Lotte Capital had 7, with all reporting single-digit figures. Financial companies report their information protection investment amounts and the number of dedicated personnel to KISA on a mandatory or voluntary basis.
Even when considering the differences in company size, there is a significant gap between these numbers and the average 91.9 dedicated personnel at the four major commercial banks (KB Kookmin, Shinhan, Hana, and Woori), as well as the overall financial and insurance industry average of 25.9.
The differences are also evident in information protection investment. This year, Shinhan Savings Bank invested 1,151,300,000 won, Welcome Savings Bank 3,751,800,000 won, and Lotte Capital 2,638,000,000 won—well below both the financial and insurance industry average of 9,552,000,000 won and the four major banks' average of 38,441,800,000 won.
On the other hand, the proportion of information protection investment relative to total IT investment was higher at these institutions than the average of the four major banks (8.5%), with Shinhan Savings Bank at 9.8%, Welcome Savings Bank at 15.8%, and Lotte Capital at 9.4%. Although they are allocating a not-insignificant share to security, the total IT budget and staffing are still much more limited than those at large institutions, resulting in inevitable limitations on the absolute scale of available defensive resources.
Concerns about security blind spots rise further at the level of general insurance agencies (GA) and similar entities. Even INKA Financial Service, a KOSDAQ-listed major GA, had only 1.3 dedicated information protection staff and invested just 243,600,000 won this year. The company maintained only one dedicated staff member for three consecutive years from 2023 to 2025, with a slight increase this year. Yet as of the first half of this year, there were 24,725 affiliated insurance planners, and the company handles a massive amount of customers' personal and credit information under recruitment and delegation contracts with multiple insurers.
Given that even a relatively large, publicly-listed GA has a dedicated security team of just over one person, smaller GAs, asset management companies, and lending agencies are likely to have even weaker security environments. The problem is that a smaller company may commit fewer resources to security, but the sensitivity of the personal and credit information it handles is not necessarily reduced.
Moreover, security costs do not diminish in proportion to company size. The equipment and solutions required for external intrusion and anomaly detection, vulnerability assessments, and more come with substantial costs and require specialized personnel for operation. Simply raising the proportion of investment in security does not equip these firms with large-scale defensive capabilities comparable to major financial institutions.
An industry official commented, "For smaller companies, it is often difficult to independently possess security equipment and professional staff. In some cases, such as certain asset management companies, when they become victims of ransomware, they resolve it by paying hackers directly rather than reporting the incident. There have even been instances where small virtual asset firms went bankrupt after losing their assets to North Korean hacker attacks."
AI Is Equalizing Attack Capabilities... Widening Security Asymmetry
The proliferation of generative AI is emerging as a particularly significant threat to small and micro financial firms. Capabilities such as vulnerability exploration and attack code development—which once required notable expertise—are now aided by AI, allowing even low- and medium-skilled attackers to rapidly augment their capabilities. As the technical barriers to entry are lowered for attackers, the defensive capacity of small financial institutions is not easily elevated in the short term, thereby amplifying the security asymmetry.
Cyberattacks using AI are also increasing rapidly. According to IBM, one out of every four malicious data breach incidents investigated between March last year and February this year involved the use of AI by attackers—a 56% increase over the previous year.
The recent information leakage incident at payment gateway firms demonstrates how a tightly interconnected financial network can serve as a path for risk proliferation. Even without directly attacking the core systems of a major credit card company, attackers can expose customer payment data by exploiting vulnerabilities at connected merchants in the payment process. This underscores why reinforcing security at individual major institutions alone cannot eliminate risk for the broader financial ecosystem.
Financial authorities are gradually easing network separation regulations to support AI utilization in the security operations of financial companies. The Financial Services Commission and Financial Supervisory Service have relaxed eligibility for regulation exemptions, lowering the qualification requirements from a first-tier threshold (10 trillion won in assets and more than 1,000 regular employees) to a second-tier threshold (2 trillion won in assets and more than 300 regular employees). While the direction is positive, critics argue that these thresholds based on assets and workforce size still end up excluding smaller firms in greater need of defenses, leading to a "mismatch" in AI adoption.
Since the risk of cyberattacks does not correlate directly with asset size, there are inherent limitations to the current "every company for itself" approach of relying on each company's investment capacity for security.
Hot Picks Today
"Canceled After Five Days and Lost 770,000 Won"... Hit by Steep Fees After Pressing the Cancel Button
- "Each 10-Won Drop in Exchange Rate Boosts Profit by 2.5 Billion Won"...Stocks Benefiting from the Strong Won at 1,340 Won Level
- After Flocking to Japan, Why Are Chinese Tourists Now Choosing Korea? ... A Dramatic Reversal in Just One Year
- "This Chuseok Feels Too Short, Let's Take Monday Off Too"... Anticipation Grows for Surprise Designation of September 28 as a Temporary Public Holiday
- "What Did They Put on the Porsche?"...The Story of a 27-Year-Old Chinese Owner Who Covered Their Car with Photos of 90 Missing Children
Chae Sangmi, a professor of business administration at Ewha Womans University, said, "The financial ecosystem is densely connected through APIs and open banking, so if the most vulnerable link is breached, the risk can cascade into major financial institutions. To strengthen overall security in the financial sector and guarantee survival-level defense for small companies, it is necessary to utilize AI-based defensive tools to address these blind spots."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.