A major Korean conglomerate's supplier responded to a hacking incident by shutting down its factory and formatting all affected PCs rather than contacting authorities or cybersecurity firms. The company believed that temporarily halting operations and formatting computers would eliminate the installed ransomware and solve the problem.
"In reality, the hacker's intrusion path and vulnerabilities were neither identified nor addressed, so the situation remained unchanged," an industry official said. "The company only took proactive measures after being hacked three times over three years."
A mid-sized Korean construction company reported in its regular information security disclosure earlier this year that it had zero dedicated cybersecurity personnel, and that its sole security-related executive, the Chief Information Security Officer (CISO), had engaged in no security activities.
Despite a surge in corporate-targeted cyberattacks, security operations are being pushed to the back burner in Korean workplaces. The trend of neglecting security—such as having HR managers handle cybersecurity duties on the side—is growing, and many CEOs still view security investment as a disposable expense, according to industry insiders. Companies appear to comply with laws and government guidelines on the surface while remaining in a state of "substantive indifference" with minimal actual security activity.
Industry experts warn that cybersecurity has already deteriorated to a level that undermines Korea's industrial competitiveness. Without a shift in investment and awareness, national initiatives such as AI transformation could also be derailed. Some caution that Korea risks remaining a "global playground for hackers."
70% of Companies Have Zero Dedicated Security Staff; Compensation Disparities Persist
According to the 2025 Domestic Information Security Industry Survey published by the Ministry of Science and ICT (MSIT) and the Korea Information Security Industry Association, information security firms plan to hire only 2,029 security professionals—a 35.77% decrease from the 3,159 hired last year.
Only 28.6% of Korean companies have dedicated security personnel. Seven out of ten firms have no specialized cybersecurity staff. Among those with security personnel, most handle other duties concurrently. Some 63.6% of companies require security staff to perform dual roles, while 7.8% rely on external contractors. In some cases, government security disclosures revealed that HR managers oversee IT security operations at construction and other companies.
Lower compensation compared to general developers also hinders the expansion of cybersecurity talent. According to MSIT data from 2023, 55.3% of security industry workers earn less than 50 million won annually. Only 40.1% earn between 50 million and 100 million won, while just 4.5% earn 100 million won or more.
The vast majority (97.2%) of companies without cybersecurity staff believe they do not need such personnel. Among firms that allocate information security budgets, only 0.6% invest more than 100 million won. Some 75.8% of investing companies spend less than 5 million won.
'Advocating for Security Is Treated Like Opposing Cost Cuts... AI Transformation Remains Distant'
Critics argue that Korea's industrial cyber threats are being underestimated due to corporate awareness gaps. Damage goes unreported because companies either fail to report hacks or quietly pay ransoms to hackers. According to MSIT, 67.7% of companies that experienced security breaches took no meaningful action afterward.
"Many view information security as a factor limiting company growth or as an unnecessary expense," said Lee Sung-yeob, a professor at Korea University's Graduate School of Technology Management. "The more a CISO advocates for stronger security, the more they appear to oppose the CEO's cost-cutting efforts. This dynamic limits their role and creates a vicious cycle where security is never properly implemented."
Experts warn that the convergence of AI transformation (AX) and increasingly sophisticated hacking will inevitably lead to more security incidents. As industries accelerate digital transformation (DX) and AX, the attack surface has expanded while corporate countermeasures have failed to keep pace, creating more entry points for hackers. The growing prominence of state-sponsored hacking groups such as North Korea-backed Kimsuky signals the prospect of more intense cyberattacks.
"Security is determined by the weakest link, and currently a panorama of cyberattacks is unfolding across all aspects of Korean industry," said Yeom Heung-yeol, a professor of information security at Soonchunhyang University. "Given that Korea lacks even the ABCs of information security posture, companies and the government must face the reality of what is happening in cyberspace to defend against sophisticated attacks."
"If additional hacking occurs, trust in the internet—the foundation of our society and economy—will crumble, and this means the collapse of the foundation for AI and other electronic information industries," Yeom added. "Now is the time to begin a comprehensive overhaul, rebuilding from the basics including personnel and organizations."
Beyond Defense: Security Should Become an Export Industry Capturing Both National Security and Economic Benefits
The security industry warns that Korea will struggle to escape its status as a "global playground for hackers" unless a corporate culture takes root where C-level executives directly oversee security operations as CISOs. Proposed measures to raise industry security awareness include granting CISO authority at the C-level, providing incentives for security investment, and expanding CEO involvement in security.
"In the AI transformation era, a single incident can lead to massive losses for both companies and society as a whole," a senior security industry official said. "Companies must recognize that security is not a cost but a portfolio integrating investment, insurance, and risk management."
Momentum is building for developing the security industry as a national export sector. The rationale is to strengthen cyber response capabilities across industries while simultaneously benefiting the national economy.
"Korea's online network has a more complex structure than other countries, and domestic security firms have built high technical capabilities to adapt to this environment," said Jang Hang-bae, a professor of industrial security at Chung-Ang University. "Making cybersecurity an export industry is both the direction we must take and a path we can follow."
Major countries including the United Kingdom and Israel are already strategically developing cybersecurity to capture both national security and economic benefits. Since formally designating cybersecurity as a national security agenda in 2009, the UK has released successive policies including an export strategy in 2018 and an "Action Plan" in September this year. As a result, UK cybersecurity exports grew 243% from 2.1 billion pounds (approximately 4.1 trillion won) in 2018 to 7.2 billion pounds (approximately 14.1 trillion won) in 2023.
Israel has made cybersecurity startup development a pillar of national strategy, spawning successive unicorns in the field. Israeli security startup Check Point has a market capitalization exceeding 30 trillion won. Wiz, which Google acquired this year for $32 billion (47 trillion won), and CyberArk, acquired by Palo Alto Networks for $25 billion (37 trillion won), also originated in Israel.
"If domestic security products are validated and developed within a sovereign AI ecosystem, this will naturally lead to expanded overseas exports and international standardization," Jang said.






