State Financial Firms Face Staffing Caps as Banks Outsource 45% of Security Jobs

[Severe Shortage of Cyberattack Response Staff] Industrial Bank of Korea Faced 860,000 Attacks Last Year Adding Security Staff Means Cutting Other Departments Wider Outsourcing at Commercial Banks Raises Third-Party Risk

Finance|
|
By Do Hye-won and Lee Seung-baedohye1@sedaily.com, bae@sedaily.com
||

IBK, the Industrial Bank of Korea, had 17.12 million individual customers and 2,250,422 corporate clients as of the end of last year. Because the lender specializes in small and mid-sized companies while also running a retail business, its total customer base reaches roughly 20 million — comparable to that of a major commercial bank.

The Korea Development Bank, which focuses on corporate banking, has about 2 million business clients. Industry officials say that these two state-run banks alone show how critical information security is for state financial institutions.

State Financial Firms Face Staffing Caps as Banks Outsource 45% of Security Jobs - Seoul Economic Daily Finance News from South Korea

As a result, state-run financial institutions, not just commercial banks, have become targets for hackers. Beyond personal data and transaction records, they hold income and asset information, family relationships and other sensitive details. The Industrial Bank of Korea alone faced more than 860,000 cyberattacks last year, including 370,000 hacking attempts, 410,000 distributed denial-of-service attacks and 80,000 malicious emails. Despite exposure to nearly 900,000 attacks a year, the bank had just 46 information security staff last year — less than half the levels at commercial banks such as NH NongHyup Bank, with 118, and Woori Bank, with 101.

State-run financial institutions say they face far greater difficulty than private financial firms such as commercial banks and brokerages in securing information security budgets and expanding staff. The Industrial Bank of Korea, the Korea Inclusive Finance Agency and the Korea Housing Finance Corporation are subject to annual government controls on headcount, like other public institutions, and their total payroll is capped under the government's total labor cost system. An official at a state-run financial institution said on the 6th that "when the organization's total headcount and structure are controlled by the government, increasing dedicated information security staff means cutting staff in other departments."

Officials explain that there are limits to competing on pay at a time when rising hacking risks driven by artificial intelligence have intensified competition for IT specialists across all industries. The difficulty is especially acute for public institutions located outside the capital region.

What matters is that commercial banks are also struggling to find staff. Their situation is better than that of state financial firms, but they have not secured enough personnel overall.

In fact, about half of the dedicated information security staff at the four largest commercial banks turned out to be external workers. An analysis of information security disclosures compiled by the Korea Internet & Security Agency showed that KB Kookmin, Shinhan Bank, Hana Bank and Woori Bank had a combined annual average of 367.4 dedicated information security staff last year. Of those, 202 were in-house and 165.4 were external, meaning outside workers accounted for 45% of the total.

By bank, 52 of Woori Bank's 101 information security staff were external, putting its outsourcing ratio at 51.5%. At Hana Bank, 36.6 of 71.9 staff were external, a share of 50.9%. Shinhan Bank followed at 44.5%, or 43.5 staff, and KB Kookmin at 34.4%, or 33.3 staff. In-house information security staff as a share of total employees stood at 0.43% at Shinhan Bank, 0.42% at KB Kookmin, 0.36% at Woori Bank and 0.30% at Hana Bank.

Internet-only banks, by contrast, have built their information security organizations largely around their own staff. Of Toss Bank's 30 information security staff, 28.4 were in-house, or 94.7%, with external workers accounting for just 1.6, or 5.3%. At KakaoBank, 52.2 of 78.5 staff were in-house, a share of 66.5%. In-house information security staff as a share of total employees also ran higher than at the four largest banks, at 3.73% for Toss Bank and 2.99% for KakaoBank.

Commercial banks that staff branch networks and internet-only banks without branches have different workforce structures, but some argue that securing in-house staff is essential to the continuity of security operations. An official at an internet-only bank said that "this does not mean external staff are less skilled, but because their work presumes a move after the contract ends, there are inevitable differences from in-house employees in terms of continuity and accountability."

Using external staff does not in itself amount to a security weakness, but the market has consistently warned that the wider financial firms' IT outsourcing becomes, the greater the third-party risk. After Toss Bank, there were attempts from early this year to access servers at KakaoBank and K bank using internet protocol addresses linked to attackers involved in hacking incidents at major financial firms, but the internet-only banks fended them off. Lim Jong-in, professor emeritus at Korea University's Graduate School of Information Security, said that "security staff should be hired as permanent employees wherever possible," adding that "the country needs to train security specialists who can make skilled use of AI."

Companies in this story

Original reporting by Do Hye-won and Lee Seung-bae for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:39

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.