Saturday, October 3, 2026

Officials Up to Level 1 to Face Accountability for Major Public-Sector Data Leaks; Minimum Penalty Raised to Pay Reduction

Input
2026-10-01 11:52:48
Updated
2026-10-01 11:52:48
Hwang Gyu-cheol, head of the Ministry of the Interior and Safety's AI Government Office, gives a joint briefing on measures to strengthen accountability for cybersecurity in the public sector with relevant ministries, including the Ministry of the Interior and Safety (MOIS), the National Intelligence Service (NIS), the Ministry of Personnel Management and the Personal Information Protection Commission (PIPC), at the annex of the Seoul Government Complex in Jongno-gu, Seoul, on the morning of the 1st. Newsis

[Financial News] Going forward, when a major information leak occurs in the public sector due to hacking or other causes, even senior officials, including Level 1 officials in the relevant ministry, may be held disciplinarily accountable for neglecting their supervisory duties. When information is leaked through the exposure of classified or personal information, or through hacking caused by poor security management, the minimum disciplinary penalty will be raised from a reprimand to a pay reduction. The measure follows 247 public-sector information leak incidents over the past five years or so, despite only nine disciplinary actions and no cases in which an agency head was disciplined.
The relevant ministries, including MOIS, NIS and the Ministry of Personnel Management, announced the "Measures to Strengthen Cybersecurity Accountability in the Public Sector" on the 1st.
Hwang Gyu-cheol said, "Incidents that could have been prevented by following only very basic rules are recurring," adding, "This is not simply a mistake but an absence of security awareness." Last year saw the hacking of the On-nara System and a data leak, as well as a ransomware infection at Hanmaeum Blood Center. This year, ransomware infections at Kangwon National University Hospital and Chonnam National University Hwasun Hospital, along with a personal information leak from the Korea National Diplomatic Academy (KNDA) training system, followed one after another.
The government will revise the Enforcement Rules of the Disciplinary Decree for Public Officials this year to codify that supervisors concerned will be held strictly accountable when a serious information leak occurs.
Kim Jae-seon, head of the Ministry of Personnel Management's Public Service Management Division, said, "Managers can already be held responsible for general misconduct, but there has been no explicit provision in the law," adding, "We are specifying that managers can be held strictly accountable if they neglect their supervisory responsibilities."
The scope of accountability will extend to Level 1 officials in ministries. Ministers and vice ministers, who are political appointees, are excluded from the scope of disciplinary action under the State Public Officials Act, so disciplinary measures cannot be imposed on them under the Disciplinary Decree for Public Officials. Kim explained that if there is a problem involving the head of an institution who is a political appointee, it is handled as "a matter concerning the President's personnel authority."
The minimum disciplinary level will also be raised. Under current rules, breaches of confidentiality caused by hacking or negligence in managing personal information can already result in dismissal, depending on the circumstances. However, when information is leaked through the exposure of classified or personal information, or through hacking resulting from inadequate security management, the minimum disciplinary penalty is currently a reprimand.
The government will raise this by one level, to a pay reduction. Kim said, "We will raise the minimum disciplinary standard from a reprimand to a pay reduction," adding, "We will prepare to revise and implement the enforcement rules within this year."
Violations of basic security rules will also be designated as specific grounds for disciplinary action. By the end of the year, the government will establish disciplinary handling criteria covering the omission of security reviews before a service goes live, poor management of firewalls and other security equipment, repeated violations of security rules, and the prolonged neglect of identified security vulnerabilities.
The criteria will also cover using the 'default password' configured on a server or piece of equipment without changing it. This is not a password an individual normally uses, but one set by the manufacturer as the default when a server or piece of equipment is shipped. Kim Gyeong-jik, director of MOIS's Digital Security Policy Division, explained, "The default password is set identically on every device when products leave the factory, so anyone can know it," adding, "It is a basic security rule that must be changed when a system is installed."
Institutional evaluations will also be expanded. The NIS's current cybersecurity status assessment covers 153 institutions, only 7.1% of the 2,160 national and public institutions eligible for assessment.
Next year, the government will add other public institutions, local public corporations and city and provincial offices of education, increasing the number to 868. Starting in 2028, the assessment will expand to all 2,160 institutions. From next year, major information leak incidents will result in points being deducted from central administrative agencies' Government Innovation Assessment scores, while a cybersecurity indicator will be newly added to local public enterprise management evaluations beginning with the 2028 assessment.
Starting next year, the government will pursue the establishment of dedicated organizations at the department or team level in central administrative agencies and metropolitan local governments. It will also consider having private-sector information security experts lead these organizations. The government plans to create a separate allowance for information security duties and award additional points in performance evaluations.
Hwang stressed, "The core of this plan is not simply tougher disciplinary action," adding, "It is a shift in perception to view security not as a 'burdensome regulation' but as a 'national mission.'"

[email protected] Lee Bo-mi Reporter