When public sector organizations experience cyber security breaches, disciplinary action will be further strengthened, especially focusing on high-level officials. This move follows criticism that, although most information leakage incidents were caused by failure to follow basic guidelines, appropriate disciplinary measures were not being taken against administrators. The government plans to raise the standards for disciplinary action regarding violations of basic security rules so that, going forward, the head of the relevant institution will be held primarily responsible.


On October 1, the Ministry of the Interior and Safety announced these measures as part of its "Plan to Strengthen Cybersecurity Accountability in the Public Sector," in cooperation with the National Intelligence Service, the Ministry of Personnel Management, and the Personal Information Protection Commission.


According to the Ministry of the Interior and Safety, most recent public sector cyber security incidents—including the hacking of the Onnara system, ransomware infections at national university hospitals, and personal information leaks from the Korea National Diplomatic Academy and the Institute for Information & Communications Technology Planning & Evaluation—resulted from failures to comply with basic security rules. Despite this, institution heads who were not political appointees were excluded from disciplinary action. Between 2021 and May of this year, among approximately 247 cases of information leakage in the public sector, there were zero instances where the institution head was disciplined. Only 9 cases involved disciplinary measures against those in charge or managers, representing merely about 1% of the total. The Ministry of the Interior and Safety analyzed that, because the results of the "cybersecurity status evaluation," which assesses compliance with cybersecurity rules, contributed just 0.6 out of 100 points in the overall government work evaluation, there was insufficient incentive for organizations to improve their cybersecurity efforts.


Accordingly, when an information leakage incident occurs in the public sector, the government will increase the standards for disciplinary action for breaches of cyber security rules and will explicitly stipulate stronger accountability regulations for high-level supervisors. The Ministry of Personnel Management plans to introduce new provisions in the "Enforcement Rules for Civil Servant Discipline Decree" in November, establishing strict supervisory responsibility in the event of information leakage incidents. In addition, the National Intelligence Service will expand the scope of its "cybersecurity status evaluation" to all public sector institutions by 2028, increasing the number of organizations assessed from 153 to 2,160.


Measures will also be put in place to prevent a tendency to avoid work related to cyber security amid the tougher disciplinary actions for security breaches.



New information security work allowances will be established, and those in charge of information security will be given preferential treatment through additional points in their performance evaluations. In terms of organization and budget, central administrative agencies and metropolitan governments will strengthen their cyber security workforce. In the mid to long term, dedicated organizations led by private-sector experts will be established to further enhance professional capabilities.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing