
The South Korean government will set standards allowing it to discipline public officials who fail to follow basic information security rules, such as leaving server default passwords unchanged or letting problems go unaddressed for long periods. It will also toughen penalties so that agency heads, not just working-level staff, are held accountable when a serious data leak occurs.
The government announced the "measures to strengthen cybersecurity accountability in the public sector" on the 1st, together with the Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission. From 2021 through May this year, there were 247 data leak incidents in the public sector, but only nine led to disciplinary action, and no agency head was ever disciplined.
Under the measures, the government will draw up processing guidelines so that officials can be disciplined for violating information security rules, including failing to change default passwords or leaving security problems unaddressed for extended periods. The move reflects a judgment that recent security incidents in the public sector — the data leak at the "Startup for All" platform and ransomware infections at national university hospitals — stemmed from a failure to observe basic rules. The minimum disciplinary level will also be raised from a reprimand to a pay cut.
When a serious data leak occurs in the public sector, managers including agency heads will also bear responsibility. Until now, disciplinary action has centered on working-level staff. The scope will be widened to cover ministry officials up to Grade 1 (the most senior career civil-service rank, just below political appointees), excluding political appointees such as ministers and vice ministers, and will extend beyond central and local administrative agencies to public corporations and state-run enterprises.
The government will also improve its evaluation system to encourage agencies to strengthen security at the institutional level. The "cybersecurity status assessment" overseen by the National Intelligence Service will be expanded sharply from 153 institutions this year to about 2,000 by 2028. Point deductions for data leak incidents and whether an agency responded promptly will also be factored into the assessment.
To prevent officials from avoiding such duties because of tougher penalties, the government is reviewing measures such as information security allowances and extra points in performance evaluations. It plans to reinforce cybersecurity staffing at central administrative agencies and metropolitan local governments and, over the medium to long term, to set up dedicated organizations headed by private-sector experts.
Hwang Kyu-chul, head of the Interior Ministry's AI Government Office, said the core of the measures is "not simply tougher discipline but a shift in perception that views security as a national mission," adding, "We will work to realize a safe, AI-driven democratic government that the public can use with confidence."






