Invest1 publisher3 min readPublished
South Korea moves to discipline agency heads over unchanged passwords and ignored flaws
South Korea plans to discipline public-agency heads for basic cyber lapses after 247 public-sector breaches since 2021 led to no head being disciplined. The penalties are headed into the rules now, while the staff incentives and the security budget are still being worked out.
The Investor · Invest desk

What happened
- The government will add provisions to the disciplinary enforcement rules for public officials so that supervisors can be held accountable for serious data breaches, and it will raise penalty levels.
- Breach sanctions so far came to 29 penalty surcharges, 182 administrative fines and 19 disciplinary recommendations, and only six of those recommendations led to actual discipline.
- Of the 2,160 state and public institutions eligible for last year's cybersecurity assessment, only about 150, or 7.1%, were actually assessed.
- The National Intelligence Service will expand that assessment from 153 institutions this year to about 2,000 by 2028.
- Only 11 of 49 central administrative agencies, or 22%, run a dedicated cybersecurity division or team.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Agency heads now carry career risk for password and patch failures inside their organizations, so they have a reason to ask their IT teams for evidence of basic hygiene before an assessor or an attacker finds the gap.
- constraint Someone has to find a basic lapse before anyone can be disciplined for it, so enforcement can move no faster than the NIS assessment program grows.
- decision Officials offered a security posting now take on more personal risk, so whether the allowance and review points are approved will decide whether agencies can fill the security jobs the plan depends on.
Add up those sanctions and 211 of the 230 [1], about 92%, turn out to be surcharges or fines [2]. Only 19, about 8%, were recommendations to discipline a person [3], and about one in three of those was acted on [4]. In my view a fine on a public body mostly moves money from one government account to another. The old framework aimed discipline at leaks of personal information or classified material and at deliberate misconduct, and it had no clear guideline for a failure of basic security practice [7].
The plan comes from the interior and personnel ministries, the National Intelligence Service and the Personal Information Protection Commission [2]. It names the lapses: an initial password never changed, an identified security problem left open for an extended period [8]. Violation categories that are now defined only broadly would be broken into specific ones [20]. The supervisor provision turns on a serious breach [9], so the most clearly defined exposure for an agency head comes after an incident. The plan itself followed two of them, a breach at a government startup support platform and ransomware at a national university hospital [3].
Reaching about 2,000 institutions by 2028 means assessing roughly 13 times as many as this year [5], or about 93% of the 2,160 eligible [6]. New indicators would dock points for a breach and measure how fast an institution responds [13]. The scores would feed central agencies' performance evaluations and local public enterprises' management evaluations [14]. The government also plans to map out a basic budget for replacing outdated software, applying security patches and checking for vulnerabilities [18]. The report does not include a won figure for it [18].
If the assessments scale on schedule, discipline should start to follow lapses that assessors find before anyone is breached. If the penalties instead push officials away from security work, agencies lose the staff the plan depends on. The government sees that risk. It is reviewing an information protection allowance, extra performance-review points and key-position status for security staff [15]. The starting point is weak: 37 of 152 institutions assessed last year missed the rule that security staff make up at least 10% of IT staff [17]. A third outcome is breadth without depth, with 2,000 scores and the same grades as last year, when no central ministry or metropolitan government earned a top rating [10].
I think the penalties land first. They are going into the enforcement rules [9], while the incentives are still under review [15] and dedicated units led by private-sector experts are a medium- to long-term aim [19]. The counter-case is that the evaluation link [14] matters more than any single disciplinary file, because a breach would cost a ministry points in its own grading. I am wrong if an institution head is disciplined over a basic lapse before the assessment gets anywhere near 2,000 bodies.
What to watch
- The text of the revised disciplinary enforcement rules, including how a 'serious' breach is defined and how much the penalty levels rise.
- Whether the information protection allowance and performance-review points move from review into personnel rules, and with what budget line.
- The NIS assessment count for 2027, which will show whether the path to about 2,000 institutions by 2028 is on schedule.