[Beyond the Scene] In the Era of 'AI Hacking', Small and Micro-Sized Firms Left Out of Eased Network Separation
"From now on, the use of artificial intelligence (AI) in hacking attacks on the financial sector will inevitably increase. For small and micro-sized financial companies, which cannot afford expensive security equipment and personnel, network segregation regulations should be relaxed more boldly so that they can quickly identify and respond to vulnerabilities using external AI."
This is what a financial industry official I met recently said. While the relaxation of network segregation rules is expanding from major financial firms to secondary financial institutions, the small and micro-sized players—who are in the greatest need of AI-powered defense—are actually being left out. Korea has traditionally relied on separating financial companies’ internal and external networks to prevent security breaches, but the advent of AI is now shifting the direction of these regulations.
The recent hacking incidents targeting electronic payment gateway (PG) companies have exposed the risks of such “weak links.” Attacks on companies like Toss Payments and Coem Payments led to the leakage of tens of thousands of payment data, including credit card information. This is not an issue that can be solved simply by raising defense barriers around large financial institutions. Since financial firms, PG companies, and merchants are all closely interconnected, a single vulnerability in any one area can serve as a penetration route threatening the entire financial ecosystem.
AI has also changed the dynamics of both attack and defense. The barriers to identifying security weaknesses and generating attack code—which previously required advanced technical skills—have dropped significantly. Financial authorities currently investigating the PG company hacks also suspect that hackers made use of AI. If attackers are armed with AI while defensive systems remain bound by outdated regulations, the outcome is all but predetermined.
In May, financial authorities allowed exceptions to network segregation requirements for AI used in security purposes. Although the relaxation has been extended to secondary financial institutions and electronic financial companies, the key criterion has merely shifted from assets of 10 trillion won to those with more than 2 trillion won—meaning company size remains the main benchmark.
It is now time to focus on “risk and connectivity” rather than just company asset size. Authorities should also consider how much sensitive data is being handled, how extensive the connectivity to external systems is, and how much data flows through APIs. Even a small company can serve as a strategic entry point in the financial network—making it an attractive target, as hackers could potentially steal personal information from major institutions through such a “gateway.”
This does not mean that regulations should be lifted for small and micro-sized companies without safety measures. If these firms lack in-house security capabilities, they can establish infrastructure to securely use external AI. One possible approach is for specialized organizations like the Financial Security Institute to analyze the programs running small and medium-sized companies’ financial systems with external AI in a controlled environment to proactively plug vulnerabilities before hackers can exploit them—a form of “joint shield.” Even financial institutions that are not eligible for network segregation relaxation should be allowed to use external AI in this manner for security purposes, which will require the authorities to review and adjust current regulations.
Hot Picks Today
"Three Days Off in a Row Is Sweet?" Four-Day Workweek Begins, but Unexpected Burnout Emerges
- Seoul's Jongno 3-ga Named World's Coolest Neighborhood... "Can't Miss Beer with Kimchi and Seafood Pancakes at Street Stalls"
- "Is It Really a Healthy Oil?"... The Surprising Risks of Frying Eggs with Coconut Oil
- "I Thought I Was Middle Class..." Surprised by High Savings and Asset Requirements That Feel Out of Reach
- "97.3% Satisfaction Rate": 600,000 Ride Han River Bus... "Intervals to Be Cut to 15 Minutes, Express Routes Planned"
In the AI era, merely adopting a strategy of completely blocking hacking attempts is not enough to counter threats. What matters most is the ability to uncover vulnerabilities before hackers do and to immediately detect intrusions to prevent the spread of damage. The principle espoused by the financial authorities—“AI must be stopped by AI”—must be applied first and foremost to the system’s weak links, in other words, those who are most in need of AI defenses.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.