South Korea to Discipline Agency Heads for Public-Sector Hacking Incidents, Raising Minimum Penalty from Reprimand to Pay Cut — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


South Korea’s government is overhauling its system to move beyond holding only working-level staff accountable for hacking and information leak incidents at public institutions, extending disciplinary measures to managers including non-political agency heads. The plan also includes allowances and promotion credits for security personnel to prevent the role from becoming an undesirable assignment.

The Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management, and the Personal Information Protection Commission held a joint interagency briefing on October 1 at the Seoul Government Complex annex in Jongno-gu, Seoul, where they announced the “Public Sector Cybersecurity Accountability Enhancement Plan.”

Hwang Kyu-cheol, head of the Artificial Intelligence Government Office at the Ministry of the Interior and Safety, said, “We will ensure that agency heads bear responsibility for security first,” adding, “We will establish a security culture where authority without accountability does not prevail.” He described the core of the plan as “not simply strengthening punishment, but a shift in perception that views security as a national mission rather than a burdensome regulation.”

The government’s decision to revise the system stems from the disciplinary record on public-sector security incidents. According to interagency tallies, 247 public-sector information leak incidents occurred through hacking and other means from 2021 through May of this year, yet only 9 resulted in disciplinary action. Not a single non-political agency head was directly disciplined.

The government’s assessment is that, excluding personal information or classified data breaches and intentional incidents, there were no adequate processing guidelines for basic security rule violations, and responsibility was concentrated on working-level staff rather than managers when incidents occurred.

Supervisor Accountability Codified… Political Appointees Excluded

The government plans to amend the Civil Service Disciplinary Decree Enforcement Rules by next month to explicitly designate serious information leak incidents as grounds for strict supervisor accountability. Among violations of confidentiality obligations, the government will pursue raising the disciplinary standard for negligence cases from the current reprimand or pay reduction to a minimum of pay reduction.

The scope of agency head accountability has also been specified. Kim Jae-seon, head of the Service Discipline Division at the Ministry of Personnel Management’s Ethics and Service Bureau, explained, “Political appointees such as ministers and vice ministers are excluded from disciplinary action under the State Public Officials Act, but Grade 1 officials below political appointees are subject to discipline.” The scope extends beyond central and local administrative agencies to include public corporations, state-owned enterprises, and local public enterprises.

Actual disciplinary standards will also be refined. Failure to change initial passwords, negligence in managing security equipment such as firewalls, and prolonged neglect of identified security vulnerabilities will all become grounds for discipline. The government will establish detailed processing standards for these basic information protection rule violations and incorporate them into the State Public Officials Service and Discipline Regulations by December.

Hwang said, “Currently, incidents that could have been prevented by following very basic rules are recurring in the public sector,” adding, “This is not a simple mistake but an absence of security awareness.”

Assessment Scope to Expand 14-Fold… Dedicated Organizations to Be Established

Institution-level security management will also face pressure through assessments, staffing, and budgets. The National Intelligence Service’s cybersecurity status assessment scope will expand from the current 153 entities—including central ministries, metropolitan and provincial governments, public corporations, and quasi-governmental institutions—to 868 next year and 2,160 by 2028. The current assessment covers only 7.1% of all eligible entities.

New assessment indicators will include penalty points for information leak incidents and whether rapid response measures were taken after incidents. The government plans to incorporate cybersecurity indicators into central administrative agency evaluations and local public enterprise management evaluations to ensure agency heads are directly accountable for security.

The plan also reflects concerns that strengthening discipline alone could make information security work even more undesirable. Only 11 of 49 central administrative agencies—approximately 22%—have dedicated security organizations. The government will bolster security staffing at central administrative agencies and metropolitan and provincial governments, and will pursue establishing dedicated organizations headed by private-sector information security experts starting in 2027.

When asked about the effectiveness of support measures for information security personnel, Kim said, “There is currently no separate allowance paid directly to information security staff,” adding, “We will consider establishing a new information security work allowance separate from the existing technical information allowance.” He continued, “We also plan to finalize measures for granting credits in performance evaluations and promotions by December.”

The key elements of the government’s plan are as follows:

CategoryKey Details
Supervisor AccountabilityNon-political agency heads and Grade 1 officials subject to discipline for serious information leaks
Disciplinary LevelMinimum standard for basic rule violations raised from reprimand to pay reduction (reflected in regulations by December)
Status AssessmentScope expanded from 153 entities to 2,160 by 2028; new indicators for incident penalty points and rapid response
Personnel SupportNew information security work allowance under review; promotion and performance evaluation credits
Organization & StaffingSecurity staffing reinforcement at central agencies and metropolitan/provincial governments; dedicated organizations led by private-sector experts

Note: Compiled from the joint announcement by the Ministry of the Interior and Safety, National Intelligence Service, Ministry of Personnel Management, and Personal Information Protection Commission.

Hwang added, “We will finalize budget standards this month for vulnerability assessments through simulated hacking and replacement of outdated software whose security support has ended, and discuss them with relevant ministries.” Through this plan, the government presented its goal of realizing a safe AI-enabled democratic government that citizens can use with confidence.



Click Here For The Original Source.

——————————————————–

..........

.

.