In the event of significant cybersecurity incidents such as hacking or data breaches in public institutions, supervisory officials, including those at the first level of government, will now face disciplinary action. The minimum penalty will be raised from a reprimand to a suspension.
The government announced this 'Strengthening Accountability for Cybersecurity in the Public Sector' plan on October 1, involving collaboration among the Ministry of the Interior and Safety, the National Intelligence Service, the Personnel Management Office, and the Personal Information Protection Commission.
According to the government, there were 247 incidents of data breaches due to cyberattacks on public institutions from January 2021 to May 2023. Of these, only nine resulted in disciplinary actions. Out of 19 cases where the Personal Information Protection Commission recommended penalties, only six were actually implemented.
Under the current 'Regulations on the Disciplinary Actions for Public Officials,' breaches of confidentiality or negligence in personal information management due to hacking can lead to dismissal, but there has been no case of a head of an institution receiving such a penalty.
Data breaches in public institutions have been ongoing. In July last year, the government’s work management system, 'Onnara,' was hacked, leading to data leaks. In November, the Hanmaeum Blood Center was infected with ransomware. This year, incidents included ransomware infections at Gangwon National University Hospital and Hwasun Jeonnam National University Hospital in January, a data breach in the National Diplomatic Academy's education system in February, the leak of confidential information regarding 'Everyone's Startup' candidates in June, and a data breach at the Korea Information and Communication Technology Planning and Evaluation Agency in July.
During the briefing, Hwang Gyu-cheol, head of the Ministry of the Interior and Safety's Artificial Intelligence Government Office, stated, "Many incidents that could have been prevented with basic security protocols are recurring in the public sector. This is not just a simple mistake but a lack of security awareness."
The government identified that the lack of disciplinary actions for violations of basic security protocols, and the tendency to hold staff rather than managers accountable, are major reasons for the recurrence of these incidents.
In response, the government plans to amend the disciplinary regulations this year to include strict accountability for supervisors in the event of serious data breaches. The definition of 'serious accountability' will now explicitly include 'serious data breach incidents' alongside issues like corruption or negligence leading to harm to public interests or financial losses. The minimum disciplinary standard for breaches of confidentiality or negligence in security management due to hacking will be raised from a reprimand to a suspension.
Additionally, by the end of the year, the government will establish guidelines that specify disciplinary reasons for failures such as neglecting security reviews before service launches, poor management of security equipment like firewalls, failure to change default passwords, and long-term neglect of identified vulnerabilities.
The government will also revise the evaluation system to encourage institutions to strengthen cybersecurity beyond individual employees. The number of institutions subject to the National Intelligence Service's 'Cybersecurity Status Evaluation' will be significantly expanded from 153 this year to 2,160 by 2028, covering all national and public institutions. The evaluation will introduce new metrics, such as penalties for data breach incidents and assessments of how quickly incidents are addressed.
Starting next year, the 'Specific Evaluation of Central Administrative Agencies' will penalize evaluation scores for serious data breach incidents, and cybersecurity evaluation indicators will be added to the 'Management Evaluation of Local Public Enterprises' to enhance the effectiveness of evaluations.
Plans for preferential treatment in personnel matters are also being developed. Among 49 central administrative agencies, only 11 (22%) have dedicated security teams. Additionally, 24% of agencies failed to meet the standard of having more than 10% of their workforce dedicated to cybersecurity. In August, the government reinforced cybersecurity personnel by 100 in central administrative agencies, and local governments will also increase their personnel by the end of the year. A dedicated organization led by private experts is also planned.
Furthermore, a new cybersecurity allowance will be established, and performance evaluations for cybersecurity personnel will include bonus points. The criteria for selecting important positions will also consider cybersecurity responsibilities.
Hwang stated, "We will closely discuss with relevant agencies, including the National Intelligence Service and the Planning Office, stable funding for basic cybersecurity measures such as vulnerability assessments through simulated hacking and replacing outdated software that no longer receives security support."
He added, "The core of this plan is not just to strengthen penalties but to shift the perception of security from a 'burdensome regulation' to a 'national mission.' We will strive to realize a safe AI democratic government that the public can use with confidence."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.