
South Korea is the only major economy without a cybersecurity control tower, with response authority fragmented across the public, private and financial sectors, according to an expert assessment. Hacking attacks using artificial intelligence are mounting across industries including finance, but the domestic response system makes rapid action at the national level difficult, the assessment said.
Lee Hae-won, a professor at Kangwon National University School of Law, prepared a report titled "A Comparative Study of Domestic and International Legislation and Policy on New Security Risks Posed by AI and Responses to Them" and submitted it to the National Assembly Research Service last month, according to information technology industry sources on the 6th.
In the United States, the control tower role falls to the Cybersecurity and Infrastructure Security Agency (CISA) under the Department of Homeland Security (DHS). In Britain, it is the National Cyber Security Centre (NCSC) under Government Communications Headquarters (GCHQ), and in Japan, the National Cyber Office (NCO) reporting directly to the Cabinet Secretariat. In South Korea, by contrast, cybersecurity response duties are split: the National Intelligence Service (NIS) covers the public sector, the Korea Internet & Security Agency (KISA) under the Ministry of Science and ICT handles the private sector, and the Financial Security Institute under the Financial Services Commission oversees finance, each under its own governing statute.
"Unlike major advanced economies such as the United States, the European Union, Britain and Japan, Korea shows a governance structure that is somewhat fragmented along ministerial lines," the report said. "Given the nature of cyber intrusion incidents, such a structure inevitably exposes clear limits to unified information sharing and incident response at the national level."
The report also raised the limits of the National Security Office at the Presidential Office. "The Presidential Office is essentially an advisory body to the president and lacks executive functions," it said. "Without a specialized executive organization or staff, it has little choice but to depend heavily on the NIS and others to carry out policy."
The sharp rise in AI-driven hacking has made building a rapid response system more urgent than anything else. Under its AI Action Plan, the United States established an AI Information Sharing and Analysis Center (AI-ISAC), led by the Department of Homeland Security, to let the government and the private sector share information on security threats. It is also strongly encouraging voluntary threat-information sharing by the private sector through legal liability protections.
Lee stressed the importance of legislation to build a preemptive defense system. "There is a need to impose an obligation on AI operators above a certain threshold to maintain cybersecurity response capacity and resilience," the professor said, recommending that "measures to overhaul the national cybersecurity framework should be pursued."






