[Exclusive] Financial Sector's Information Security Apathy Persists... Security Budget Execution Rate Lags Behind IT
[Vulnerable Financial Security] ①
IT Budget Execution Rate Hits 40.1% in First Half; Information Security Lags Behind at 35.7%
Budget Execution Gap Widens from 1.2 Percentage Points in 2022 to 4.8 Percentage Points Last Year
Accelerating Digital Competition with AI and Super Apps
“Constant and Preventative Security Frameworks Are Needed”
While the financial authorities are moving to strengthen internal controls in response to a series of security incidents across the financial sector, such as hacking and customer information leaks, it has been revealed that the budget execution rate for information security by financial companies is lower than the overall information technology (IT) budget execution rate. The gap between IT budget execution and information security budget execution widened from 1.2 percentage points in 2022 to 4.8 percentage points last year. As competition for digital innovation businesses—such as artificial intelligence (AI) and mobile platforms—intensifies, there are mounting calls to enhance security investment and management systems to better protect customer information and financial assets.
An image depicting law enforcement authorities investigating a cyberattack on a financial institution. The Asia Business Daily Database.
View original imageAccording to materials titled "Status of Information Security Budgets and Personnel in the Financial Sector over the Past Five Years (2022–first half of 2026)" submitted to Kim Jaeseop, a member of the National Assembly’s Political Affairs Committee from the People Power Party, by the Financial Supervisory Service on October 6, the average IT budget execution rate at 34 financial companies across the entire financial sector in the first half of this year was 40.1%. In contrast, the information security budget execution rate was only 35.7%, meaning it was 4.4 percentage points lower than the overall IT budget execution rate.
By business segment, the information security budget execution rate in the first half of this year was highest for non-life insurance at 41.5%, followed by securities at 38.2%, banks at 36.1%, credit cards at 31.7%, and life insurance at 29.7%.
Broken down by company, Hanwha Life Insurance (19.1%), KB Securities (21.5%), KB Kookmin Card (21.9%), Shinhan Card (24.9%), KB Kookmin Bank (27.1%), Daishin Securities (27.4%), Lotte Card (27.6%), BC Card (27.7%), and KB Insurance (28.8%) all fell below the cross-sector average of 35.7%.
Expanding the time span, the trend of information security budget execution lagging behind IT budget execution becomes more apparent. The overall financial sector IT budget execution rates were 82.5% in 2022, 81.6% in 2023, 79.8% in 2024, and 83.6% last year. For the same periods, the information security budget execution rates were 81.3%, 79.0%, 75.6%, and 78.8%, respectively.
Moreover, the gap between the two budget execution rates has widened every year. The difference increased from 1.2 percentage points in 2022 to 2.6 percentage points in 2023, 4.2 percentage points in 2024, and 4.8 percentage points last year. Even in the first half of this year, the IT budget execution rate stood at 40.1% compared to 35.7% for information security, a 4.4 percentage point difference. Although it is difficult to compare half-year figures directly with annual rates, the slower pace of information security budget execution compared to total IT budgets has persisted into this year as well.
This widening gap is notable because competition for digital transformation among financial companies is accelerating. The IT budgets of these firms are being funneled not only into information security, but also into a range of areas critical for digital competence and business operations, including: AI chatbots, machine learning for credit scoring systems (CSS), MyData, mobile super apps, open banking, insurance AI underwriting, simple payment platforms, and mobile trading systems (MTS) for securities companies.
The investments themselves in new digital businesses are not inherently problematic. However, as digital dependence in financial services grows, the potential impact of security breaches can also increase. Hacking or leakage of personal information can cause direct financial loss to customers as well as erode trust in financial companies, underscoring the need for a balance between investment in new businesses and in security.
Experts emphasize that simply increasing the budget is not enough; a constant and preventative security management system must be established. Yeom Heungyeol, Professor of Information Security at Soonchunhyang University, said, "It is important to establish a risk assessment-based security management system that constantly checks for system vulnerabilities and develops and upgrades security measures. Financial companies should fundamentally enhance their security management systems by expanding their workforce and increasing investment in information protection."
Professor Yeom added, "The ultimate goal of a preventative system is to build a 'zero trust'-based security management framework. All access must be rigorously verified based on the premise that hackers may already have penetrated internal networks. Especially in the financial sector, breaches can immediately result in financial loss, so an even higher level of security management is required than in other industries."
Shifting the mindset of senior management is also viewed as a key challenge. Article 8, Paragraph 2 of the current Regulation on Electronic Financial Supervision stipulates that "Financial companies or electronic financial businesses must secure enough personnel and sufficient budgets with expertise in information technology and information protection." Experts point out that companies need to move beyond reactive measures—such as increasing staffing and budgets after an incident—and instead implement systems that proactively check for vulnerabilities and preemptively mitigate risks in daily operations.
Hot Picks Today
[Exclusive] "Forecasts of Over 10 Billion, but Only 100 Million Earned"... 95% Followed This Pattern: Why Are KOSDAQ Special Exception IPOs Inflated? [KOSDAQ Inflated IPOs]①
- [Breaking] Cho Hee-dae: "No Constitutional Basis for Retrial Request... Difficult to Proceed"
- "I Have 73 Million Won in Debt"... How Documenting Debt Repayment Went Viral on TikTok
- "Drinking This in the Morning Is Like Drinking Alcohol"..."Doctors Warn: Never Consume It"
- "This Is How You Give a Winner’s Interview": Choi Siwon Recalls Son Heungmin... Lee Kangin’s Remarks Spotlighted Again
Cha Sangmi, Professor in the School of Business at Ewha Womans University, suggested, "It is preferable for companies to make genuine efforts to prevent financial incidents themselves, rather than for the authorities simply to raise regulatory hurdles. To achieve this, it is essential for corporate management to take a proactive and participatory approach."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.