Korea to Discipline Agency Heads Over Serious Data Leaks

Breaches of basic rules such as leaving default passwords unchanged will also draw penalties Minimum disciplinary level raised from reprimand to pay cut

Technology|
|
By Kim Ji-wonone@sedaily.com
||
Hwang Kyu-cheol, head of the Ministry of the Interior and Safety's AI Government Office, briefs reporters on measures to strengthen cybersecurity accountability in the public sector at the annex of the Government Complex Seoul in Jongno-gu, Seoul, on Nov. 1. Yonhap News - Seoul Economic Daily Technology News from South Korea
Hwang Kyu-cheol, head of the Ministry of the Interior and Safety's AI Government Office, briefs reporters on measures to strengthen cybersecurity accountability in the public sector at the annex of the Government Complex Seoul in Jongno-gu, Seoul, on Nov. 1. Yonhap News

The South Korean government will set standards allowing it to discipline public officials who fail to follow basic information security rules, such as leaving server default passwords unchanged or letting problems go unaddressed for long periods. It will also toughen penalties so that agency heads, not just working-level staff, are held accountable when a serious data leak occurs.

The government announced the "measures to strengthen cybersecurity accountability in the public sector" on the 1st, together with the Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission. From 2021 through May this year, there were 247 data leak incidents in the public sector, but only nine led to disciplinary action, and no agency head was ever disciplined.

Under the measures, the government will draw up processing guidelines so that officials can be disciplined for violating information security rules, including failing to change default passwords or leaving security problems unaddressed for extended periods. The move reflects a judgment that recent security incidents in the public sector — the data leak at the "Startup for All" platform and ransomware infections at national university hospitals — stemmed from a failure to observe basic rules. The minimum disciplinary level will also be raised from a reprimand to a pay cut.

When a serious data leak occurs in the public sector, managers including agency heads will also bear responsibility. Until now, disciplinary action has centered on working-level staff. The scope will be widened to cover ministry officials up to Grade 1 (the most senior career civil-service rank, just below political appointees), excluding political appointees such as ministers and vice ministers, and will extend beyond central and local administrative agencies to public corporations and state-run enterprises.

The government will also improve its evaluation system to encourage agencies to strengthen security at the institutional level. The "cybersecurity status assessment" overseen by the National Intelligence Service will be expanded sharply from 153 institutions this year to about 2,000 by 2028. Point deductions for data leak incidents and whether an agency responded promptly will also be factored into the assessment.

To prevent officials from avoiding such duties because of tougher penalties, the government is reviewing measures such as information security allowances and extra points in performance evaluations. It plans to reinforce cybersecurity staffing at central administrative agencies and metropolitan local governments and, over the medium to long term, to set up dedicated organizations headed by private-sector experts.

Hwang Kyu-chul, head of the Interior Ministry's AI Government Office, said the core of the measures is "not simply tougher discipline but a shift in perception that views security as a national mission," adding, "We will work to realize a safe, AI-driven democratic government that the public can use with confidence."

Original reporting by Kim Ji-won for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:17

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.