
[BODY]
Amid a series of large-scale personal data breaches, corporate cyber insurance uptake remains stagnant. According to the non-life insurance industry on the 26th, new cyber insurance contracts in the first quarter of this year totaled 1,617, up just 80 (5.2%) from the same period a year earlier. By contrast, personal data breach reports in the first half of this year reached 432, already approaching last year's annual total of 447.
The problem is that even large companies often subscribe only to the legal minimum coverage (1 billion won) to reduce premium burdens, making adequate compensation difficult. Coupang, which suffered a breach of tens of millions of individuals' personal information, is also reported to carry coverage of only 1 billion won. The industry argues that the minimum coverage should be brought to realistic levels of 10 billion to 100 billion won, depending on revenue and the scale of personal data held.
Another problem is that there are effectively no penalties for failing to obtain the insurance required to fulfill liability obligations. Rather, the government is pushing a plan to reduce the scope of mandatory subscription (from revenue of 1 billion won to 150 billion won or more), citing difficulty in identifying eligible companies. An industry official noted, "For small and medium-sized enterprises with insufficient compensation capacity, failure to obtain insurance could further weaken victim protection."






