Security Staff Numbers Rise, But IT Workforce Grows Even Faster
Proportion of Information Security Personnel Drops Across KakaoBank, K Bank, and Toss Bank
Five Major Banks See Increase, But 14-Bank Average Still Out of Reach

As security threats such as hacking and information leaks intensify in the financial sector, it has been found that the proportion of information security personnel among the IT workforce at internet-only banks, which operate non-face-to-face 24-hour services, has actually decreased.


According to data on “Information Security Personnel in the Banking Sector” submitted to Assemblyman Cho Jeonghun of the National Assembly’s Political Affairs Committee by the Financial Supervisory Service as of October 2, the share of information security staff among IT employees at the three internet-only banks (KakaoBank, Toss Bank, and K Bank) fell from 10.89% at the end of 2021 to 9.34% at the end of the first half of this year, a decrease of 1.55 percentage points.


While the total IT workforce at the three internet-only banks surged by 95.93%, from 836 people at the end of 2021 to 1,638 people at the end of this year’s first half, the number of information security personnel increased by only 68.13%, from 91 to 153. As a result, the proportion of information security staff among IT personnel decreased across all three banks: KakaoBank (11.10% → 9.70%), K Bank (12.30% → 10.10%), and Toss Bank (8.20% → 8.00%). Kwon Heonyoung, Professor at Korea University’s Graduate School of Information Security, commented, “In the early stages of internet-only banks, concerns about information security led to a higher proportion of related personnel, but now, growing demand for software personnel is believed to be driving down the share of security staff.”


[Exclusive] Information Security Gains Importance, but Three Internet Banks See Decline in Security Staff Proportion [Growing Financial Security Threats]② View original image

In contrast, the share of information security staff among IT employees at the five major commercial banks (KB Kookmin, Shinhan, Woori, Hana, and NH NongHyup) and at the six regional and regional base banks (iM Bank, Busan, Kyongnam, Jeonbuk, Gwangju, and Jeju Bank) increased between the end of 2021 and the end of the first half of this year. However, it still lagged behind the average level of the 14 banks, including the three internet-only banks. For all 14 banks (the five major commercial banks, regional banks, and internet-only banks), the proportion of information security staff within IT grew from 8.02% at the end of 2021 to 8.55% at the end of the first half of this year.


Among the five major commercial banks, the share of information security personnel in IT increased from 7.73% to 8.50% during this period. Hana Bank saw the biggest increase, rising by 3.20 percentage points from 7.80% to 11.00%. NongHyup Bank increased by 0.40 percentage points from 8.90% to 9.30%, and Shinhan Bank increased by 1.00 percentage point from 8.00% to 9.00%, both surpassing the 14-bank average (8.55%) at the end of the first half of this year. In contrast, Woori Bank, which had the highest proportion among the five major banks at 9.20% at the end of 2021, dropped by 1.10 percentage points to 8.10% by the end of the first half of this year. Kookmin Bank recorded only a modest increase of 0.40 percentage points, from 5.80% to 6.20%, during the same period.


For the six regional and regional base banks, the share of information security staff increased from 7.14% at the end of 2021 to 7.78% at the end of the first half of this year, though it remained below 8%. Gwangju Bank (18 personnel), Jeonbuk Bank (12 personnel), and Jeju Bank (9 personnel) each had fewer than 20 information security staff members.


Assemblyman Cho stated, “As the digitization of finance accelerates, the importance of security grows as well. The number of customers and transactions is rising and IT staff are increasing, but it is unacceptable to leave the proportion of security personnel lagging behind this reality. Financial regulators must go beyond simple ratios and review whether actual security capabilities are sufficient, and financial institutions must fulfill their information protection responsibilities in line with their growth.”


Professor Kwon also suggested, “Recently, banks have elevated their Chief Information Security Officer (CISO) to the level of executive vice president, emphasizing the importance of security. However, practical governance is also needed, ensuring that security-related executives are empowered to carry out authority and responsibility appropriate to their senior title.”


Meanwhile, according to the record of electronic financial incidents and breaches by bank, which was submitted by the Financial Supervisory Service to Assemblyman Cho’s office, a total of 422 incidents occurred at 13 banks (excluding iM Bank) from 2021 through September 8 of this year. By year, there were 73 incidents in 2021, 92 in 2024, 81 in 2025, and 36 from January to September 8 this year.



The five major commercial banks accounted for 193 incidents during this period, representing 45.73% of all cases. The three internet-only banks accounted for 175 cases (41.47%), and the five regional banks (Busan, Kyongnam, Jeonbuk, Gwangju, and Jeju) accounted for 54 cases (12.80%).


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing