the monthly 한국어

Industry and regulation

Public sources used in designing our services. As of 9 October 2026. Each item lists its source. This page is not legal advice.

Korea's amended Personal Information Protection Act, in force from 11 September 2026

  • Notice duty: when a business learns of a personal information leak, or reasonably judges a leak highly likely, it must notify the people affected within 72 hours. Exceptions set by law apply.
  • Fine: up to 10% of total revenue. Applies where a violation is repeated within 3 years through intent or gross negligence, harms 10 million people or more through intent or gross negligence, or falls under other cases set by law.

Deciding within 72 hours needs logs collected in advance and early detection of anomalies. That collection and detection is the part we do. Check the conditions and how they apply in the law and official notices. Ask your legal counsel whether a notice duty applies.

Sources: 개인정보 보호법 시행령 제39조 (in Korean) (Korea Law Information Center, Presidential Decree No. 36671), 내일부터 1000만명 개인정보 털리면 ‘매출 10%’ 징벌 과징금 (in Korean) (Seoul Shinmun, 10 September 2026), 개인정보 반복·대규모 유출 최대 매출 10% 과징금…내일부터 시행 (in Korean) (Aju Business Daily, 10 September 2026)

2026 information security support program for ICT small and medium-sized enterprises

  • Operators: the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA)
  • Eligible: small and medium-sized enterprises (SMEs) as defined under Korea's Framework Act on Small and Medium Enterprises
  • Support rate: 80% of the supply price for IT security packages and security as a service (SECaaS)
  • Government support limit per company: KRW 5 million for consulting
  • Government support limit per company: KRW 4.8 million for an IT security package
  • Government support limit per company: KRW 3.6 million for security as a service (SECaaS)
  • Participant recruitment: by regional information security support centers. Each region sets its own call and eligibility
  • Gyeonggi and Chungbuk: reported to close at the end of November 2026. May close early when the budget runs out
  • Suppliers: recruited and selected through a separate notice

This notice does not mean that the cost of the monthly's services is subsidized. The program notice and regional operators decide which services and suppliers are covered. We can help you check whether your company can apply, and which regional center to apply to and when.

Sources: 충북 중소기업 사이버보안 지원…기업당 최대 980만원 (in Korean) (Chungcheong Domin Ilbo, 7 October 2026), 경과원, 중소기업 ‘디지털 방패’ 구축 지원… 최대 480만원 보조 (in Korean) (Segye Ilbo, 5 August 2026), 2026년 ICT 중소기업 정보보호 지원 사업 공급기업 모집 공고 (in Korean) (Ministry of Science and ICT notice No. 2026-0482, posted 23 April 2026)

Incidents confirmed by official investigations

Only facts confirmed by government investigations and regulators' announcements, grouped by type. Company names are partly masked in our sentences. Source links keep the original headlines. Figures carry their date and unit.

Long detection failures and missing logs

Weak infrastructure authentication

Infections found but not reported

Missing patches and missing encryption

Our reading

  • Issues these investigations identified: missing logs, late detection, unreported infections, and weak certificate and patch management
  • Our approach: collect logs first, raise anomalies early, and run risky actions only after a person approves them under HITL (Human In The Loop)

For a table of how we close each gap, see our company page.

Where Korean businesses stand on security

Figures from news coverage of the 2025 Information Security Survey by the Ministry of Science and ICT and the Korea Information Security Industry Association (KISIA). Survey scope: businesses with a network and 10 or more employees.

  • Businesses with an information security policy or rulebook: 52.6%
  • Top difficulty in security work: securing a budget, 49.1%
  • Second difficulty: running and managing systems and processes, 45.7%
  • Third difficulty: finding the products and services they need, 42.6%

Purpose of our monthly managed operation: to ease the second difficulty, running and managing systems and processes.

Source: 기업 80.6% “정보보호 중요”…정책 보유는 52.6% (in Korean) (Byline Network, 27 March 2026). The difficulty figures are the values reported in this article.

Where security operations are heading

Main restraint on adopting AI-driven security operations, according to market research: distrust of autonomous blocking and response. The proposed answer: graduated autonomy. Agents investigate and recommend, and people approve high-impact actions. We work the same way, under HITL (Human In The Loop).

Source: Agentic AI Security Operations Center (SOC) Market Growth, Trends & Forecast to 2032 (MarketsandMarkets, checked 9 October 2026)

Anthropic announcement (November 2025): in mid-September 2025, Anthropic detected a cyber espionage campaign that manipulated its AI coding tool. This is Anthropic's own announcement.

Source: Disrupting an AI-orchestrated cyber espionage campaign (Anthropic, 13 November 2025)

For what we leave to agents and what waits for a person, see HITL (Human In The Loop).

Ask us what applies to you

Write to contact@themonthly.tech. If something needs attention now, send a technical support request.

Request technical support