Industry and regulation
Public sources used in designing our services. As of 9 October 2026. Each item lists its source. This page is not legal advice.
Korea's amended Personal Information Protection Act, in force from 11 September 2026
- Notice duty: when a business learns of a personal information leak, or reasonably judges a leak highly likely, it must notify the people affected within 72 hours. Exceptions set by law apply.
- Fine: up to 10% of total revenue. Applies where a violation is repeated within 3 years through intent or gross negligence, harms 10 million people or more through intent or gross negligence, or falls under other cases set by law.
Deciding within 72 hours needs logs collected in advance and early detection of anomalies. That collection and detection is the part we do. Check the conditions and how they apply in the law and official notices. Ask your legal counsel whether a notice duty applies.
Sources: 개인정보 보호법 시행령 제39조 (in Korean) (Korea Law Information Center, Presidential Decree No. 36671), 내일부터 1000만명 개인정보 털리면 ‘매출 10%’ 징벌 과징금 (in Korean) (Seoul Shinmun, 10 September 2026), 개인정보 반복·대규모 유출 최대 매출 10% 과징금…내일부터 시행 (in Korean) (Aju Business Daily, 10 September 2026)
2026 information security support program for ICT small and medium-sized enterprises
- Operators: the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA)
- Eligible: small and medium-sized enterprises (SMEs) as defined under Korea's Framework Act on Small and Medium Enterprises
- Support rate: 80% of the supply price for IT security packages and security as a service (SECaaS)
- Government support limit per company: KRW 5 million for consulting
- Government support limit per company: KRW 4.8 million for an IT security package
- Government support limit per company: KRW 3.6 million for security as a service (SECaaS)
- Participant recruitment: by regional information security support centers. Each region sets its own call and eligibility
- Gyeonggi and Chungbuk: reported to close at the end of November 2026. May close early when the budget runs out
- Suppliers: recruited and selected through a separate notice
This notice does not mean that the cost of the monthly's services is subsidized. The program notice and regional operators decide which services and suppliers are covered. We can help you check whether your company can apply, and which regional center to apply to and when.
Sources: 충북 중소기업 사이버보안 지원…기업당 최대 980만원 (in Korean) (Chungcheong Domin Ilbo, 7 October 2026), 경과원, 중소기업 ‘디지털 방패’ 구축 지원… 최대 480만원 보조 (in Korean) (Segye Ilbo, 5 August 2026), 2026년 ICT 중소기업 정보보호 지원 사업 공급기업 모집 공고 (in Korean) (Ministry of Science and ICT notice No. 2026-0482, posted 23 April 2026)
Incidents confirmed by official investigations
Only facts confirmed by government investigations and regulators' announcements, grouped by type. Company names are partly masked in our sentences. Source links keep the original headlines. Figures carry their date and unit.
Long detection failures and missing logs
- S* Telecom: Attacks continued from 2021. Infected servers found in February 2022. On a server with signs of abnormal sign-in attempts, the company checked only 1 of 6 log records, so the attacker's access was not identified (government investigation, July 2025). Source: 과기정통부 “유심정보 유출 SKT 귀책사유…위약금 면제 해당” (in Korean) (Seoul Shinmun, 4 July 2025)
- K*: Kept only 1 to 2 months of logs. Investigators confirmed the server hacking but could not determine whether data had leaked (government investigation, December 2025). Source: 정부 “KT, 전 고객 위약금 면제해야”…조사 방해한 LG유플러스는 수사 의뢰 (in Korean) (Kyunghyang Shinmun, 29 December 2025)
Weak infrastructure authentication
- K*: All femtocells (small base stations) used the same certificate. A copied certificate let an illegal femtocell join the network (government investigation, December 2025). Source: 정부 “KT, 전 고객 위약금 면제해야”…조사 방해한 LG유플러스는 수사 의뢰 (in Korean) (Kyunghyang Shinmun, 29 December 2025)
- K*: That certificate was valid for 10 years (interim government investigation, November 2025). Source: KT, 작년 서버 해킹 알고도 은폐 정황…정부 "엄중 조치" 예고 (in Korean) (Korea Economic Daily, 6 November 2025)
- K*: An illegal device built with a copied certificate went in and out of the internal network for about 11 months, from October 2024 to September 2025 (Personal Information Protection Commission decision, July 2026). Source: 개보위, KT '정보유출' 과징금 540억 부과 (in Korean) (Money Today, 31 July 2026)
Infections found but not reported
- S* Telecom: Found a malware-infected server in February 2022. Did not meet its reporting duty under the Network Act (government investigation, July 2025). Source: 과기정통부 “유심정보 유출 SKT 귀책사유…위약금 면제 해당” (in Korean) (Seoul Shinmun, 4 July 2025)
- K*: Identified malware-infected servers itself between March and July 2024. Did not report them to the authorities (interim government investigation, November 2025). Source: KT, 작년 서버 해킹 알고도 은폐 정황…정부 "엄중 조치" 예고 (in Korean) (Korea Economic Daily, 6 November 2025)
Missing patches and missing encryption
- L* Card: A 2025 hack leaked the credit information of 2.97 million customers (Financial Services Commission decision, July 2026). Source: '해킹사고' 롯데카드 제재 감경…업무정지 4.5개월→1.5개월 (in Korean) (MTN, 31 July 2026)
- L* Card: Inspection results announced by the Financial Services Commission. Security patches were not applied on time to the online payment system. Duties such as encrypting resident registration numbers and passwords were violated (Financial Services Commission decision, July 2026). Source: '해킹사고' 롯데카드 제재 감경…업무정지 4.5개월→1.5개월 (in Korean) (MTN, 31 July 2026)
- L* Card: The Financial Services Commission ordered a 1.5-month business suspension. Scope: card issuance to new members. Ended on 15 September 2026 (Financial Services Commission decision, 31 July 2026). Source: '해킹사고' 롯데카드 제재 감경…업무정지 4.5개월→1.5개월 (in Korean) (MTN, 31 July 2026)
Our reading
- Issues these investigations identified: missing logs, late detection, unreported infections, and weak certificate and patch management
- Our approach: collect logs first, raise anomalies early, and run risky actions only after a person approves them under HITL (Human In The Loop)
For a table of how we close each gap, see our company page.
Where Korean businesses stand on security
Figures from news coverage of the 2025 Information Security Survey by the Ministry of Science and ICT and the Korea Information Security Industry Association (KISIA). Survey scope: businesses with a network and 10 or more employees.
- Businesses with an information security policy or rulebook: 52.6%
- Top difficulty in security work: securing a budget, 49.1%
- Second difficulty: running and managing systems and processes, 45.7%
- Third difficulty: finding the products and services they need, 42.6%
Purpose of our monthly managed operation: to ease the second difficulty, running and managing systems and processes.
Source: 기업 80.6% “정보보호 중요”…정책 보유는 52.6% (in Korean) (Byline Network, 27 March 2026). The difficulty figures are the values reported in this article.
Where security operations are heading
Main restraint on adopting AI-driven security operations, according to market research: distrust of autonomous blocking and response. The proposed answer: graduated autonomy. Agents investigate and recommend, and people approve high-impact actions. We work the same way, under HITL (Human In The Loop).
Source: Agentic AI Security Operations Center (SOC) Market Growth, Trends & Forecast to 2032 (MarketsandMarkets, checked 9 October 2026)
Anthropic announcement (November 2025): in mid-September 2025, Anthropic detected a cyber espionage campaign that manipulated its AI coding tool. This is Anthropic's own announcement.
Source: Disrupting an AI-orchestrated cyber espionage campaign (Anthropic, 13 November 2025)
For what we leave to agents and what waits for a person, see HITL (Human In The Loop).
Ask us what applies to you
Write to contact@themonthly.tech. If something needs attention now, send a technical support request.