Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Scaled for assets, US banks' cybersecurity staffing lead over Korea's big four drops from 47 times to under 5

Citibank and Bank of America each have about 3,400 dedicated cybersecurity staff, 34 to 47 times the headcount at Korea's four largest banks. Scaled for the 10-to-12-fold asset gap, the lead is 2.8 to 4.7 times on staff and 1.8 to 3.7 times on spending.

The Investor · Invest desk

How we use AISend a correction

Photograph accompanying Scaled for assets, US banks' cybersecurity staffing lead over Korea's big four drops from 47 times to under 5
Photo: en.sedaily.com
Citibank's 3,400 security staff dwarf Korea's 71.9 to 101 Dedicated cybersecurity staff at Citibank (SEC filings) and information security staffing at Korean banks, raw headcount before any adjustment for asset size.

Bar comparison of security staffing per bank: Citibank about 3,400; Woori Bank 101; KB Kookmin Bank 96.7; Hana Bank 71.9. The Citibank bar towers over all three Korean banks.

Citibank's 3,400 security staff dwarf Korea's 71.9 to 101 (Security staff headcount per bank, unadjusted for asset size)
ItemValueClaim
Citibank3,400 staff1
Woori Bank101 staff2
KB Kookmin Bank96.7 staff2
Hana Bank71.9 staff2

What happened

  • Korea's four largest banks reported security staffing of 96.7 at KB Kookmin, 97.8 at Shinhan, 71.9 at Hana and 101 at Woori.
  • Major US banks such as JPMorgan Chase and Bank of America are estimated to put $700 million to $1 billion into cybersecurity each year, about 940 billion to 1.34 trillion won.
  • US banks built on firewalls and continuous authentication such as zero trust, while Korean firms rely on network separation rules that sever external and internal networks.

Why it matters

  • contradiction Raw staffing puts Korea 47 times behind, while security's share of IT budgets puts it 1.25 times behind, so the urgency of the case depends on which gauge a regulator adopts.
  • decision Large Korean banks are asked to move first: the three-tier discussion ties their higher security spending to further easing of network separation rules, so the spending hangs on a rule change.
  • exposure Credit unions lost 188.9 billion won and community credit cooperatives 676.8 billion won in the first half while banks earned 13.8 trillion won, so any spending requirement falls hardest on firms with no profit to fund it.

According to en.sedaily.com, the staffing disparity stays substantial after accounting for a 10- to 12-fold gap in asset size between banks in the two countries [4]. Dividing the lowest multiple, 34, by the widest asset gap, 12, and the highest, 47, by the narrowest, 10, gives a lead of 2.8 to 4.7 times [15]. Spending shrinks the same way. The raw gap is 22 to 37 times [16] (the low end is the 940 billion won bottom of the US range [5] over KB Kookmin's 43.3 billion won, the high end the 1.34 trillion won top over Woori's 36.4 billion won [6]), and scaled for assets it is 1.8 to 3.7 times [17].

Two measures need no asset adjustment, and both come out lower. Security staff are 1.5% to 1.6% of employees at Citi and Bank of America against an average 0.69% at the four Korean banks [7], a ratio of 2.2 to 2.3 [18]. The Korea Internet & Security Agency puts security at 9.6% of IT investment across 31 Korean financial and insurance firms in 2024, against a 12% average in a survey of US and Canadian financial firms that year [9], a ratio of 1.25 [19]. That sample spans banks and insurers and the comparison group is North American, so it does not test Citi and Bank of America directly.

The report adds that counting only in-house staff, with outsourced personnel excluded, the share falls to 0.3% to 0.4% [8]; it does not say which group that describes. If it is the Korean banks, the share gap widens to 3.8 to 5.3 times [20], overlapping the 2.8 to 4.7 from headcount.

KB Kookmin has budgeted about 86.075 billion won for security this year [10], 1.99 times the 43.3 billion won it invested last year [22], so the two figures may not count the same things. Analysts cited in the report say that even raising it above 100 billion won next year would leave a considerable gap with large US banks [14]. At 100 billion won the gap to the US range is 9.4 to 13.4 times [21], about the size of the asset gap itself. Woori is considering a budget increase of more than 20% and more than 10% more specialist staff [11]. A 10% rise takes its 101 staff [2] to about 111, and Citibank's 3,400 [1] would still be 30.6 times that [23].

In our view the evidence supports an underinvestment of roughly 2 to 5 times on staff and spending once size is counted [15][17], and about 1.25 times on share of IT budget [19], not 34 to 47 times. It does not support the AI part of the thesis. The report says calls are growing to move past network separation as AI-powered hacking intensifies [26], but it does not describe the incident it calls the latest or any AI-driven attack. Its explanation comes from an unnamed industry official, who attributed the incident to financial firms depending on network separation by itself while being passive about information security investment [25].

Two things would move that view in opposite directions. If security work has fixed costs (a monitoring team is needed whatever the balance sheet), scaling by assets overcorrects and the true shortfall exceeds 2.8 to 4.7 times. If network separation cuts the staff a bank needs, the shortfall is smaller: major US banks built their frameworks on firewalls and continuous authentication, with zero trust the best-known example, while Korean firms reduced risk by severing links between external and internal networks [24]. Bank-level incident and loss figures would show which case holds.

What to watch

  • KB Kookmin's final security budget for next year against the 100 billion won analysts cite as the threshold.
  • Whether Woori Bank approves the budget rise of more than 20% and staff rise of more than 10% it is considering.
  • Whether Korean regulators agree to ease network separation rules for large financial firms in exchange for higher security spending.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Citibank and Bank of America each had about 3,400 dedicated cybersecurity staff as of the end of last year, according to filings with the U.S. Securities and Exchange Commission.

    ReportedSupportedSource: en.sedaily.com, citing SEC filingsView cited source
  2. [2]

    Information security staffing at Korea's four largest banks stood at 96.7 at KB Kookmin Bank, 97.8 at Shinhan Bank, 71.9 at Hana Bank and 101 at Woori Bank.

    ReportedSupportedSource: en.sedaily.comView cited source
  3. [3]

    The Korean banks' information security staffing is between one-34th and one-47th of the U.S. levels.

    ReportedSupportedSource: en.sedaily.comView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. en.sedaily.com

    1 article · October 11, 2026

    U.S. Banks Employ Up to 47 Times More Cybersecurity Staff Than Korean Peers

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories