
South Korea's non-bank financial firms need government support to strengthen their data protection capabilities, industry officials say. Each sector serves well over 10 million customers, but individual firms have far too little budget and staff to secure that data.
Depositors at the country's 79 savings banks numbered 6,473,529 as of the end of June, with 3,695,741 borrowers, for a combined 10,169,270 clients, according to financial industry data released on the 5th.
Industry officials say the burden of managing systems that handle customer data is growing as firms expand their reach through non-face-to-face channels. Shinhan Savings Bank spent 1.15126 billion won on information protection last year and Welcome Savings Bank spent 3.75182 billion won, according to this year's information protection disclosures compiled by the Korea Internet & Security Agency. Those sums accounted for 9.8% and 15.8% of total information technology spending, shares that are not lower than those at commercial banks, but the absolute amounts lag far behind the tens of billions of won that commercial banks invest.
Conditions for hiring specialists differ as well. Counting both in-house and outsourced personnel, Shinhan Savings Bank had 6.1 dedicated security staff and Welcome Savings Bank had 7.8, compared with nearly 100 at commercial banks. At two other non-bank firms, Lotte Capital and Lotte Card, information protection spending last year came to 2.63801 billion won and 12.57376 billion won, with 7 and 36.5 dedicated staff respectively. "If security professionals are coming to the financial sector, wouldn't they go to the banks first?" an official in the savings bank industry said. "Once you take out the insurers, brokerages and card companies, hardly anyone wants to come all the way down to savings banks and mutual finance."

Industry officials argue that raising security spending does little to improve defenses without the staff to put it to use. Welcome Savings Bank increased its security spending 43.2% last year, but its dedicated headcount fell to 7.8 from 8.3. "Even if you bring in artificial intelligence tools that help analyze vulnerabilities, you still need people to review the findings and fix the systems," a financial industry official said.
Some say support for smaller financial firms must extend from the adoption of vulnerability assessment tools through to the actual remediation work. The cost of adopting new security technology is only part of the burden; hiring and training people to operate it weighs heavily as well. The government and the industry should create conditions for firms to share both assessment tools and specialists, and expand technical support to cover the process of fixing the weaknesses those checks uncover, the officials said.
Costs and staffing burdens are also why smaller insurers and mutual finance firms are absent from the list of companies certified under the Personal Information and Information Security Management System, known as ISMS-P. About 18% of life insurers hold the certification, and only 6% of capital finance companies do.
Others say joint inspections and technical support through the federation would ease the burden on individual savings banks. Of the 79 savings banks, 67, or 84.8%, use the federation's integrated computing system, according to data it released in April. "Joint diagnostics and technical support may be necessary for small and mid-sized non-bank firms that face severe budget and manpower constraints," a financial industry official said. "Reorganizing the scope of support so that checks extend beyond the shared computing system to each company's own external access services is another approach."






