
Heads of public institutions in South Korea could face disciplinary action if their organizations fail to follow basic cybersecurity rules, under a new government plan aimed at curbing breaches caused by lapses such as leaving initial passwords unchanged or letting known security flaws go unaddressed for long periods.
The government announced the plan, titled measures to strengthen cybersecurity accountability in the public sector, on the 1st in a joint effort by the Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission. The move follows a string of cybersecurity incidents in the public sector, including a data breach at a government startup support platform and a ransomware infection at a national university hospital.
A total of 247 data breaches occurred in the public sector between 2021 and May this year, according to the government. Many of those incidents stemmed from failures to observe basic cybersecurity rules, the government said.
Despite that, no institution head has ever been disciplined directly over a data breach, and disciplinary action against responsible officials and managers has been rare. Under the existing framework, disciplinary measures focused on breaches of personal information or classified material and on deliberate misconduct, with no clear guidelines for violations of basic security rules. Sanctions imposed over data breaches consisted of 29 penalty surcharges, 182 administrative fines and 19 disciplinary recommendations, of which only six resulted in actual action. None involved an institution head.
The government will therefore set disciplinary standards that can be applied to violations of basic information protection rules, such as continuing to use unchanged initial passwords or leaving identified security problems unaddressed for extended periods. It will write into the enforcement rules on disciplinary action for public officials provisions allowing supervisors to be held accountable when a serious data breach occurs, and will raise the level of disciplinary penalties. It will also establish standards for handling cybersecurity violations, breaking down and specifying categories that are currently classified only in broad terms.
Institutional responsibility for cybersecurity management will also be tightened, based on an assessment that institutions have had little incentive to build up their cybersecurity capabilities. In last year's cybersecurity assessment, not a single central government ministry or metropolitan local government earned a top rating. Although 2,160 state and public institutions were eligible for evaluation, only about 150, or 7.1%, were actually assessed.
The government will expand the cybersecurity assessment overseen by the National Intelligence Service from 153 institutions this year to about 2,000 state and public institutions by 2028. It will introduce new indicators that deduct points when a data breach occurs and that measure how quickly an institution responds after an incident. The assessment results will be reflected in the performance evaluation of central administrative agencies, and cybersecurity indicators will be added to management evaluations of local public enterprises.
To prevent officials from avoiding cybersecurity work because of the tougher penalties, the government will also introduce personnel incentives for those assigned to it. It is reviewing options including a new information protection allowance, extra points in performance reviews for information protection staff and the inclusion of information protection work among criteria for designating key positions.
Cybersecurity staffing will be expanded as well. Only 11 of 49 central administrative agencies, or 22%, currently run a dedicated cybersecurity division or team. Among the 152 institutions assessed last year, 37, or 24%, failed to meet a requirement that cybersecurity personnel account for at least 10% of staff handling information technology work.
The government will reinforce cybersecurity staffing at central administrative agencies and metropolitan local governments and, over the medium to long term, set up dedicated units headed by private-sector experts to raise expertise. It will also map out the basic budget needed for information protection activities, including replacing outdated software, applying security patches, checking for vulnerabilities, conducting penetration tests and introducing security equipment and solutions, to encourage steady investment in cybersecurity.
"We will work with the relevant ministries to ensure that the existing policy of allocating 15% of information technology budgets to information protection is implemented as far as possible," said Hwang Kyu-chul, head of the Interior Ministry's AI Government Office.






