As AI-Driven Hacking Threats Grow, Security Staff at GAs and Capital Firms Remains in Single Digits | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


[AI Targets the Weak Links in Finance] ①
Major Banks Average 91.9 Security Staff… GAs at 1.3, Capitals at 7
Even with Increased Security Budgets, Manpower and Overall Scale Are Limited
Low-Cost AI Boosts Attack Capabilities… Small Firms Face Security Asymmetry
Eased Network Separation Still Leaves Small Institutions Excluded from AI-Based Defenses

Editor’s Note
Recently, a series of card information leaks have occurred at electronic payment gateway (PG) companies such as Toss Payments and Coem Payments, highlighting the growing security threats within the financial sector. Last year, major security incidents took place at Lotte Card and SGI Seoul Guarantee, and more recently, hacking attacks have targeted a wide range of industries and organizations outside the financial sector, including Sogang University, the Korea National Diplomatic Academy, Tving, and Gangnam Eonni. As these attacks rapidly expand across all sectors, the financial industry is paying close attention to the possibility that generative artificial intelligence (AI) may have lowered the barriers to such attacks. There is a particular warning that small and micro-sized financial institutions with limited security investment capacity could become a new “weak link.” The recent PG company data leak incident demonstrated the “third-party risk,” where a breach at one entity connected to the financial network can sequentially spread risks to both major financial institutions and their customers. This article examines the security gap and blind spots in the financial sector during the age of AI, as well as potential response measures.

With the spread of generative AI, the capability for cyberattacks is rapidly being leveled up, but small and mid-sized financial institutions are unable to keep pace with defensive measures. In addition to having far fewer security personnel and significantly lower investment volumes compared to large financial institutions, the growing interconnectedness of the financial network is further amplifying the risk that vulnerabilities in these smaller institutions may escalate into sector-wide threats. As a result, there are growing calls to move beyond a model in which individual financial firms are solely responsible for security, and instead strengthen the overall defensive capabilities of small and micro-sized institutions to close the “security asymmetry” in the financial industry.

When Banks Have Nearly 100 Security Staff, GAs Have Just One… Even with Higher Investment Ratios, Absolute Scale is Limited




View original image

According to the Korea Internet & Security Agency (KISA) on September 14, this year’s information security disclosures show that the dedicated information security workforce at Shinhan Savings Bank was 6.1 people. Welcome Savings Bank reported 7.8, and Lotte Capital 7, all in the single digits. Financial companies are required or encouraged to disclose their information security investments and dedicated staff numbers to KISA.

Even taking into account differences in company size, the average number of dedicated security staff at the four largest commercial banks (KB Kookmin Bank, Shinhan Bank, Hana Bank, and Woori Bank) was 91.9. This is significantly higher not only than that of these smaller financial companies, but also than the overall finance and insurance industry average of 25.9.

Distinct differences were also seen in security investment amounts. This year, Shinhan Savings Bank invested 1,151,300,000 won, Welcome Savings Bank 3,751,800,000 won, and Lotte Capital 2,638,000,000 won. All of these fall far short compared to the finance and insurance industry average of 9,552,000,000 won and the four major banks’ average of 38,441,800,000 won.

On the other hand, the proportion of IT budgets allocated to information security was higher at Shinhan Savings Bank (9.8%), Welcome Savings Bank (15.8%), and Lotte Capital (9.4%) than the four major banks’ average of 8.5%. Nevertheless, even if a relatively high share of budget is assigned to security, the total IT budget and manpower are far more limited compared to large institutions, so the absolute amount of defense resources that can actually be secured has inherent limits.

The situation is even more concerning further down the line, such as among corporate insurance agencies (GAs). Even INCA Financial Service, a KOSDAQ-listed large GA, had only 1.3 dedicated security staff and an investment of 243,600,000 won this year. For three consecutive years, from 2023 to 2025, the company maintained a staff of just one dedicated person, with only a slight increase this year. Meanwhile, as of the first half of this year, the company had 24,725 affiliated insurance planners and, by contracting with multiple insurance firms, deals with huge volumes of customers’ personal and credit information.

Considering that a relatively sizable and publicly listed GA has only about one dedicated information security staff member, it is highly likely that the security conditions at smaller GAs, asset management firms, or lending companies are even more vulnerable. The problem is that as company size decreases, the resources available for security shrink, but the sensitivity of the personal and credit information they handle does not diminish.

Moreover, security expenses do not decrease in proportion to company size. Security equipment and solutions needed to defend against external intrusions, detect anomalies, and inspect for vulnerabilities all incur significant costs, and specialist personnel are required to operate them. Simply increasing the proportion of investment in security does not automatically translate to defense capabilities on par with large institutions.

An official from the financial sector commented, “The reality is that the smaller the company, the harder it is to secure security equipment and specialists in-house. In some asset management firms, when a ransomware attack occurs, they resort to directly paying hackers to resolve the matter themselves. There have even been cases where small virtual asset operators went bankrupt after North Korean hackers stole their assets.”


As AI-Driven Hacking Threats Grow, Security Staff at GAs and Capital Firms Remains in Single Digits


View original image

AI Levels Up Attack Capabilities… Widening Security Asymmetry

The proliferation of generative AI is emerging as a particularly significant threat to small and micro-sized financial institutions. Tasks that once required substantial expertise, such as vulnerability scanning or writing attack code, can now be aided by AI. This means attackers with moderate or even limited skills can quickly enhance their offensive capabilities. As the technical barriers for attackers decrease, it remains difficult for small firms to scale up their defenses in a short span, resulting in even greater security asymmetry.

AI-powered cyberattacks are also rapidly increasing. According to IBM, AI was used in one out of every four malicious data breach incidents investigated from March last year through February this year, a 56% increase from the previous year.

The recent information leak involving PG companies demonstrates that tightly interconnected financial networks can act as pathways for the spread of risk. Even without directly attacking the main systems of major card companies, attackers can exploit vulnerabilities in connected merchants during the payment process, exposing the card companies’ customer payment data. This shows why merely strengthening the security of individual major financial institutions is not enough to block risks across the entire financial ecosystem.

Financial regulators are also gradually easing network separation regulations to support the use of AI in security by financial companies. The Financial Services Commission and the Financial Supervisory Service have lowered the eligibility criteria for regulatory exemptions in the first stage from assets of 10 trillion won and 1,000 or more permanent employees, to 2 trillion won and 300 or more employees in the second stage. While this is a positive step, differential thresholds based on company assets and workforce remain, meaning that smaller companies lacking defense capacity are often excluded from access to AI defense tools—a clear mismatch.

Given that the risk of cyberattacks does not scale proportionally with company assets, there are clear limits to the current “every company for itself” approach, which leaves security to the investment capacity of individual institutions.

Professor Chae Sang Mi of Ewha Womans University School of Business emphasized, “The financial ecosystem is tightly knit through APIs and open banking, so if the weakest link is breached, the risk can spread to major institutions. To strengthen security across the industry and guarantee survival-level defenses for small financial firms, we need to harness AI-based defense solutions and close these security blind spots.”

This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.



Click Here For The Original Source.

——————————————————–

..........

.

.