Thursday, October 1, 2026

Repeated Hacking Incidents to Trigger Punitive Surcharge of Up to 3% of Revenue... Starting in October

Input
2026-09-30 16:14:49
Updated
2026-09-30 16:14:49
[Financial News] Starting October 1, companies that repeatedly experience serious cyber incidents or are found to have been grossly negligent in a cyber incident investigation will face punitive surcharges of up to 3% of related revenue.
Companies classified as mid-sized or larger must also designate a Chief Information Security Officer (CISO) as an executive. Previously, it was sufficient to appoint an employee, but the move is intended to elevate the CISO's status and strengthen corporate security accountability.
The Ministry of Science and ICT said the revised Act on Promotion of Information and Communications Network Utilization and Information Protection (Information and Communications Network Act) and its Enforcement Decree will take full effect on October 1. / Photo=Newsis

The Ministry of Science and ICT announced that the revised Information and Communications Network Act and its Enforcement Decree will take effect on October 1, strengthening information security measures across the board—from cyber incident prevention to post-incident response and sanctions.
The changes establish the institutional foundation for a comprehensive, pan-government information security strategy as major incidents have occurred successively at leading companies and in the public sector, while threats from AI-driven cyber incidents have also grown.
Surcharges and Information Security Committee Operations... Corporate Information Security Obligations Expanded

Under the revised law, companies that intentionally or through gross negligence cause repeated cyber incidents will face punitive surcharges of up to 3% of related revenue, depending on the severity of the incidents. The aim is to strengthen sanctions, increase companies' practical accountability for information security, and encourage them to improve their incident prevention systems.
Companies classified as mid-sized or larger must elevate the CISO's status from an employee to an executive. Companies required to report a CISO must also establish and operate an Information Security Committee. The committee will be chaired by the CISO and composed of the heads of key departments, including IT development, personal information protection, human resources, and finance. The corporate Information Security Committee must report the results of its deliberations, including decisions on securing information security budgets and personnel, to the chief executive officer (CEO). Major matters must also be reported to the board of directors.
Incident Investigation Review Committee to Formally Operate for Cyber Incident Investigations and Sanctions

The government's Information Security Management System (ISMS) certification program will introduce enhanced certification. The enhanced certification will apply to the following: major information and communications service providers and integrated information and communications facility providers with previous-year revenue of at least KRW 1 trillion; information and communications service providers with previous-year revenue of at least KRW 3 trillion; and companies that have undergone a joint public-private investigation or been subject to a surcharge within the past three years.
Companies subject to enhanced certification and those where incidents occur will undergo technical reviews, including vulnerability assessments, to ensure that the process is conducted substantively and on-site.
The Incident Investigation Review Committee under MSIT, which will lead cyber incident investigations and sanctions, will begin full operations. It will consist of 15 members from the private and public sectors, including the chairperson, and private-sector members will serve two-year terms. Meetings will be convened when the chairperson deems it necessary or at the request of the minister of Science and ICT.
Businesses that fail to comply with the government's corrective orders or requests to submit materials will be charged an enforcement penalty equivalent to 0.02% of their average daily revenue for each day of noncompliance.
Bae Kyung-hoon, Deputy Prime Minister and Minister of Science and ICT, said, "We hope companies will recognize security not simply as a cost but as an essential element of management and follow that recognition with active investment. The government, too, will actively support the successful implementation of these measures to create a digital environment that people can use with confidence."
[email protected] Lee Gu-soon Reporter