
Despite repeated personal data breaches, companies are not increasing their cyber insurance coverage. Even large corporations subscribe only to the legal minimum, and the government is pushing a plan to exclude a significant number of small and medium-sized enterprises from mandatory coverage.
New cyber insurance contracts totaled 1,617 in the first quarter of this year, up just 80, or 5.2 percent, from a year earlier, according to the financial industry on the 27th. In contrast, reports of personal data breaches in the first half of this year reached 432, already approaching last year's annual total of 447.
The problem is that even as the scale of incidents grows, the capacity for compensation through insurance is not sufficient. Coupang, which suffered a breach of tens of millions of people's personal data, has coverage of only 1 billion won, the legal minimum. The insurance industry argues that minimum coverage should be raised to a realistic level of 10 billion to 100 billion won, depending on revenue and the volume of personal data held. Even so, the government is pushing a plan to reduce the scope of mandatory coverage — raising the revenue threshold from 1 billion won to 150 billion won or more — citing difficulties in identifying eligible subscribers. "Protection for customers whose information is leaked could be weakened," an industry official said.






