“Going forward, hacking incidents in the financial sector utilizing artificial intelligence (AI) are bound to increase. This is why network separation regulations must be boldly eased, especially for small and micro-sized financial companies that cannot afford expensive security equipment and personnel, so they can use external AI to identify vulnerabilities and respond accordingly.”
This is according to a financial industry source I spoke with recently. Although the easing of network separation regulations is being expanded from major financial companies to secondary financial institutions, the small and micro-sized firms that need AI defense the most are being left behind. In Korea, the separation of internal and external networks within financial companies has long been used to block security breaches, but the advent of AI is prompting a shift in regulatory direction.
The recent hacking incident targeting payment gateway (PG) companies exposed the dangers of the industry’s “weakest links.” Attacks on PG firms such as Toss Payments and CoM Payments led to the leakage of tens of thousands of records of payment information, including credit card details. Simply strengthening the defenses of major financial firms will not solve the problem. Because financial companies, PG firms, and merchants are deeply interconnected, a vulnerability in a single entity can provide an infiltration route that threatens the entire financial ecosystem.
AI has also changed the dynamic between offense and defense. The barrier to entry for identifying vulnerabilities and writing attack code, both of which previously required significant technical skill, has been drastically lowered. Financial authorities, who are currently investigating the PG company hacking, also believe that hackers utilized AI. When attackers are armed with AI, but defensive systems remain restricted by existing regulations, the outcome will inevitably be lopsided.
In May, financial authorities allowed exceptions to network separation for the use of AI in security purposes. While the scope for regulatory relaxation is being expanded to secondary financial institutions and electronic financial business operators, the standard, although reduced from 10 trillion won to 2 trillion won in assets, is still primarily determined by the “size” of the company.
It is now time to look beyond assets and focus on “risk and connectivity.” Factors such as the volume of sensitive data handled, the extent of external system connectivity, and the amount of data exchanged via APIs must all be considered in concert. Even small companies, if strategically placed within the financial network, become attractive targets for hackers seeking to access personal information from major financial firms.
This is not to suggest relaxing regulations for small and micro-sized companies without any safety mechanisms. If a company lacks internal security capabilities, it should instead build infrastructure to safely leverage external AI. One option is to have institutions with professional expertise, such as the Financial Security Institute, create a “joint shield” by analyzing small and medium-sized firms’ financial systems with external AI in a controlled environment to proactively identify and block potential vulnerabilities before hackers exploit them. The authorities should revise regulations to enable financial companies not currently eligible for eased network separation to utilize external AI for security in such ways.
Hot Picks Today
In the age of AI, merely aiming to block hacking attempts at all costs is not enough to counter the threats. The ability to identify vulnerabilities before hackers do and to rapidly detect intrusions to prevent damage from spreading is vital. The financial authorities’ principle of “AI must be countered with AI” should start with the weakest links—those for whom AI defense is most desperately needed and most effective.
This content was produced with the assistance of AI translation services.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.
Click Here For The Original Source.

