Tving Adopts Zero Trust Security Framework With AI Monitoring

Steps include access verification, least privilege, assumed breach and continuous validation Upgrades cover AI-based security monitoring and cloud permission diagnostics

Technology|
| Updated 2026.09.23. 09:47:40
|
By Lee Jin-seokljs@sedaily.com
||
Tving CEO Choi Joo-hee (second from right) and other executives apologize for the company's personal data breach at the Koreana Hotel in Seoul's Jung district on Nov. 3. Yonhap News - Seoul Economic Daily Technology News from South Korea
Tving CEO Choi Joo-hee (second from right) and other executives apologize for the company's personal data breach at the Koreana Hotel in Seoul's Jung district on Nov. 3. Yonhap News

Tving is applying zero-trust security principles across its services and cloud environment, an approach that trusts no access by default and continuously verifies users, devices and privileges.

The streaming platform said on the 23rd that it is rebuilding its security framework around zero trust and devoting full resources to strengthening protection of customer information. Tving said it has set four core principles — strict access verification, least privilege, assume breach and continuous validation — and is reinforcing its security framework across the board.

For strict access verification, the company has applied authentication token checks across all segments of its app and website and has forced updates of older app versions. It is also reviewing technology that detects and blocks tampered apps.

Under the least privilege principle, Tving is strengthening access controls by breaking down access rights to systems and services by job function and systematically managing the scope and validity period of each privilege.

Based on the assume-breach principle, the company reviewed its incident response framework by scenario and made response procedures more specific. For continuous validation, it built a system that detects abnormal activity in the cloud environment in real time and sends alerts when irregular access occurs.

Tving is also pursuing follow-up measures to further upgrade its zero-trust security framework. It plans to assess the adoption of credential management tools and source code analysis and vulnerability management solutions, and to expand the scope of penetration testing and vulnerability assessments to cloud accounts and privilege areas. The company will also upgrade its scenario-based incident response framework and is reviewing the introduction of a bug bounty program.

Work on a next-generation security framework is accelerating as well. Tving said it will strengthen integrated cloud security inspection and apply AI-based technology to detect and block security threats, continuously raising its capacity to respond to threats in real time.

The company has also carried out reinforcement work in core security areas. It moved secrets embedded in code to a dedicated management system and built a framework that automatically blocks secrets at the source code storage stage and detects irregular access. Next-generation endpoint detection and response (EDR) solutions have been installed on all employee PCs.

To protect customer information, Tving replaced its app signing keys and digital rights management keys. It is upgrading its login and session verification structure and switching its password storage algorithm to one based on bcrypt.

A joint public-private investigation team under the Ministry of Science and ICT earlier announced that its probe into the Tving breach found that information affecting 39.54 million accounts had been leaked, a figure that counts active, dormant and closed accounts separately and may include duplicate users.

A Tving official said the company places the protection of customer information as its top priority and is continuously reviewing its security framework to ensure that measures are actually implemented. The official said Tving will upgrade access and privilege management and its breach response framework based on zero-trust principles, and will continue investing in next-generation security technology such as AI-based threat detection to build a safer service environment.

Original reporting by Lee Jin-seok for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
2:02
World News Day 2026 — Know the facts. Understand what matters. #ChooseTrustedJournalism

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.