DistantNews

SK Telecom's Hacking Anniversary: Security Upgraded, But Victim Compensation Stalls

From Hankyoreh · (11m ago) Korean Mixed tone

Translated from Korean, summarized and contextualized by DistantNews.

TLDR

  • A year after a large-scale personal information leak, South Korean telecom companies have strengthened security measures, with CEOs personally overseeing efforts.
  • The government has announced comprehensive information security measures, and companies are implementing their own safeguards, leading to some improvements in corporate security.
  • However, consumer protection and compensation systems remain slow to progress, with limitations still evident in incident response and compensation.

A year has passed since SK Telecom's massive personal data leak, an incident that has heightened public awareness and sensitivity to information security. This event, alongside similar breaches at KT, LG Uplus, Lotte Card, and Coupang, has underscored the vulnerability of services integral to daily life. In response, the government has unveiled a comprehensive plan for information security, and companies are actively developing their own countermeasures. While these efforts have led to some improvements in corporate security, the path to effective consumer protection and compensation remains slow and fraught with challenges.

Our company's security status is okay, right?

— Founder of a game companyDescribing the increased involvement of top executives in security matters.

Industry insiders note a significant shift in corporate priorities, with CEOs now directly involved in overseeing information security. This hands-on approach signifies a departure from the past, where security was often relegated to a lower priority. This heightened executive attention has translated into increased budget allocations for security investments and a growing emphasis on security awareness training for employees. Companies are restructuring, elevating Chief Information Security Officer (CISO) roles to report directly to the CEO, signaling a commitment to embedding security at the highest levels of management.

It has become much easier to secure departmental budgets than before, as the need for security investment has grown.

— Information security manager at a game companyHighlighting the increased willingness to invest in security.

The government's revised ISMS-P certification system aims to bolster security by mandating audits and shifting from paper-based assessments to practical, hands-on verification, including simulated hacking tests. However, a critical shortage of qualified auditors poses a significant challenge to the effective implementation of these enhanced standards. With approximately 600 companies subject to mandatory certification, the existing pool of security personnel may struggle to meet the demand. Experts caution that ensuring audit quality while simultaneously expanding the auditor workforce is a complex task, and the timeline for full implementation remains uncertain.

Some leaders are creating an atmosphere where they prioritize security when proceeding with work.

— E-commerce company security practitionerIllustrating the shift in workplace culture towards prioritizing security.

Despite these advancements, consumer recourse remains a significant concern. SK Telecom's refusal to comply with the Korea Consumer Agency's mediation ruling for compensation highlights the inadequacy of current consumer protection mechanisms. The limited scope of collective action lawsuits in South Korea, primarily confined to the securities sector, leaves many individuals vulnerable. While discussions around expanding collective litigation are gaining momentum, the current system often forces victims to pursue individual legal battles, a daunting prospect for many. This situation starkly contrasts with other OECD nations, where broader collective redress mechanisms are more established, underscoring the urgent need for reform in South Korea to better protect citizens from the fallout of large-scale data breaches.

Given that there are about 600 companies subject to certification as of February this year, it is questionable whether the existing security personnel can handle this.

— Industry officialExpressing concerns about the shortage of auditors for the enhanced certification system.
DistantNews Editorial

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.