Thursday, October 1, 2026

Public institution heads to face accountability after major hacking incidents... "Failure to change initial passwords also subject to discipline"

Input
2026-10-01 10:04:29
Updated
2026-10-01 10:04:29
[Financial News]  
Ministry of the Interior and Safety building (provided by MOIS) / Photo: News1

When a major data breach occurs at a public institution, senior supervisors, including the head of the institution, will also be held accountable. The measure follows 247 public-sector data breaches since 2021, despite not a single case in which an institution head was disciplined.
Disciplinary standards for basic security violations, such as failing to change initial passwords, will also be clarified.
Hwang Gyu-cheol, director of the AI Government Office at the Ministry of the Interior and Safety (MOIS), said at a briefing on the 'Measures to Strengthen Cybersecurity Accountability in the Public Sector' held at Government Complex Seoul on the 1st, "Incidents that could have been prevented simply by following very basic rules are recurring in the public sector." He added, "This is not merely a simple mistake but a lack of security awareness." He continued, "Guided by the principle of 'starting with the basics,' we will build a robust security system from the ground up."
Security incidents have indeed continued to occur in the public sector. The On-nara System was hacked and data were leaked in July last year, while Hanmaeum Blood Center was hit by a ransomware attack in November of the same year. This year, ransomware infections occurred at Kangwon National University Hospital and Hwasun Chonnam National University Hospital. Other incidents included a personal information leak from the Korea National Diplomatic Academy's education system, the leak of nonpublic information on successful applicants to 'Startup for Everyone,' and a personal information leak at the Institute for Information and Communications Technology Planning and Evaluation.
Although incidents have continued to recur, few have led to disciplinary action against those responsible. Of the 247 data breach incidents resulting from cyberattacks, including hacking, between 2021 and May this year, only nine resulted in disciplinary measures. No institution head was disciplined.
The government has decided to clearly extend the scope of accountability to senior officials. Hwang said, "In the event of a serious incident, we will codify that supervisors must bear responsibility commensurate with the scope of their authority." He added, "We will establish a security culture in which 'authority without responsibility' is not tolerated."
By November, the government will revise the Enforcement Rule of the Disciplinary Decree for Public Officials to add a provision imposing serious accountability on relevant supervisors when a severe data breach occurs. It is also considering raising the minimum level of disciplinary action for violations of cybersecurity regulations.
Accountability for violations of security rules will also be strengthened. Current administrative rules list security-related violations only as general examples. The government will establish separate handling standards by December, detailing cases such as failing to conduct a security review before launching a service, neglecting to manage security equipment such as firewalls, repeatedly violating regulations and rules, and leaving identified security problems unresolved for an extended period.
Institution-level evaluations will also be strengthened. The National Intelligence Service (NIS) can assess 2,160 national and public institutions, but only 153 institutions, or 7.1%, are actually undergoing cybersecurity assessments this year. In last year's evaluation, not a single central government ministry or metropolitan local government received an 'excellent' rating.
The number of institutions subject to evaluation will rise to 868 next year, including other public institutions, local public enterprises, and city and provincial offices of education. It will expand to all 2,160 institutions starting in 2028. Institutions will lose points when data breaches occur, and evaluations will also assess whether prompt action was taken afterward. Starting next year, deductions for serious data breaches will be reflected in the central government's government innovation evaluation. A cybersecurity indicator will be added to local public enterprise management evaluations beginning with the 2028 evaluation.
The government will also expand organizations and staffing. Only 11 of the 49 central government agencies, or 22%, currently have dedicated cybersecurity departments. Starting in 2027, the government will seek to establish dedicated divisions or teams within central government agencies and metropolitan local governments. It is also considering putting private-sector information security experts in charge of these organizations to secure greater expertise.
Hwang said, "Security work is avoided because those responsible face a burden of accountability when incidents occur, while it is difficult to demonstrate their achievements." He announced that the government would consider preferential measures, including introducing allowances for information security work and awarding bonus points in performance evaluations. Information security duties will be included in the criteria for selecting important positions and in the bonus-point criteria applied when preparing promotion candidate lists.
The government will organize this month the basic funding needs for regular vulnerability checks, including simulated hacking tests, emergency measures, replacement of outdated software that is no longer supported, and subscriptions to security services required when using commercial cloud services. It will then discuss budget investment plans with the relevant ministries.
Hwang said, "The core of these measures is not simply stronger disciplinary action." He added, "It is a shift in perception—from viewing security as an 'annoying regulation' to seeing it as a 'national mission.'"

[email protected] Lee Bo-mi Reporter