Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Korea weighs size-tiered security rules that would ease network separation first for big banks

Korea is weighing bank security rules tiered by size, under which banks that earned 13.8 trillion won in six months would loosen network separation first. Savings banks, credit unions and community co-ops lost about 99.9 billion won between them, and for them the idea on the table is a pooled security service.

The Investor · Invest desk

How we use AISend a correction

Photograph accompanying Korea weighs size-tiered security rules that would ease network separation first for big banks
Photo: yna.co.kr
Banks made 13.8 trillion won; co-ops lost 676.8 billion First-half net profit by Korean financial sector this year, in billion won. Credit unions and community credit co-ops posted losses.

First-half net profit: banks 13.8 trillion won, non-life insurers 5.0884 trillion, life insurers 3.9254 trillion, card firms 1.2934 trillion, savings banks 765.8 billion; credit unions lost 188.9 billion and community co-ops 676.8 billion.

Banks made 13.8 trillion won; co-ops lost 676.8 billion (Net profit, first half of this year, by sector)
RankItemValueClaim
1Banks13,800 billion won5
2Non-life insurers5,088.4 billion won6
3Life insurers3,925.4 billion won6
4Credit card companies1,293.4 billion won6
5Savings banks765.8 billion won7
6Credit unions−188.9 billion won8
7Community credit cooperatives−676.8 billion won9

What happened

  • KB Kookmin Bank budgeted about 86.075 billion won for information protection this year, while large US banks spend roughly 940 billion to 1.34 trillion won, per 2022 House hearing minutes.
  • Security took 9.6% of IT investment at 31 Korean finance and insurance firms in 2024, according to KISA, compared with a 12% average in a US and Canadian survey.
  • For mid-sized firms, industry associations or central federations pooling funds for shared monitoring and vulnerability checks is being floated as an alternative.

Why it matters

  • cost A pooled security service for smaller firms would draw on a tier that lost about 99.9 billion won net in the half, so how costs are split decides whether the service gets built at all.
  • exposure Easing separation first puts the big banks in direct contact with attackers while their in-house security staff share is roughly a fifth to a quarter of the Citi and Bank of America level.
  • constraint Unless the per-project AI sandbox changes too, a bank granted lighter network separation would still need sandbox approval for each AI deployment it introduces.
  • decision Regulators have to choose whether lighter rules come with spending conditions, since even a 16% rise to 100 billion won leaves KB 9.4 times below a large US bank's low-end budget.

Size tiering follows the profit split. Korean banks earned 13.8 trillion won in the first half [5], about 18 times the 765.8 billion won that savings banks made [7][25]. Life insurers earned 3.9254 trillion won, non-life insurers 5.0884 trillion won and card companies 1.2934 trillion won [6]. Credit unions lost 188.9 billion won [8] and the Korean Federation of Community Credit Cooperatives lost 676.8 billion won [9]. Taken together, the savings-bank and co-operative tier lost about 99.9 billion won net [24]. The whole savings-bank sector's half-year profit comes to about 81% of 940 billion won, the low end of what one large US bank spends on security in a year [3][23].

A tiered rule could go three ways. Regulators could ease network separation for the big banks with no strings, tie the easing to budgets and staffing, or keep smaller firms behind separation and rely on a shared service. The prevailing industry view, as Seoul Economic Daily reports it, is that large banks go first, with separation eased further and investment sharply increased [2]. We think the easing happens and the investment lags. Korea's four largest banks keep information security staff at 0.69% of headcount, against 1.5% to 1.6% at Citi and Bank of America [13]. Count in-house staff only and the Korean figure is 0.3% to 0.4% [14].

The counter-case is the US record. JPMorgan Chase, Bank of America, Citi and Wells Fargo built their security capability by facing hackers without network separation, using zero-trust models that keep verifying users even on internal networks [20]. On that record, easing the rule may be what forces Korean banks to hire.

Budgets show the same lag. KB Kookmin Bank set aside about 86.075 billion won for information protection this year [10], and large US banks spend roughly 11 to 16 times that [3][21]. Lifting KB's figure to 100 billion won next year would be a rise of about 16%, and the US low end would still be 9.4 times larger [22]. Woori Bank is reviewing plans to raise its security-systems budget by more than 20% and its specialist staff by more than 10% [15]. Security took 9.6% of IT investment at 31 Korean finance and insurance companies in 2024, according to the Korea Internet & Security Agency [11]. A survey by IANS Research and Artico Search put the US and Canadian average at 12% [12]. Matching it means raising the Korean share by a quarter [26]. An official in the financial industry said the latest incident happened "because financial firms have been passive about investing in information security, trusting network separation alone" [19].

The AI case rests on a separate rule. Korean firms must go through a regulatory sandbox each time they introduce AI into their operations [4]. The report attributes the tiering push to growing calls within the industry [2] and does not say whether a tiered regime would replace that per-project sandbox.

For mid-sized firms, the idea being floated is that industry associations or central federations pool funds for shared monitoring and vulnerability assessment [16]. An official in the financial sector said smaller firms "should handle this on their own to begin with, but they lack the manpower and other resources, so joint support is needed" [17]. Two terms are unsettled: how much the service covers and who pays for it. The Financial Security Institute, a nonprofit, would find it hard to support non-member firms for free [18]. We'd expect tiering to widen the security gap between Korea's big banks and everyone else, because the pool would be funded by a tier that lost money in the half [24]. If security spending at savings banks and co-operatives rises as a share of IT investment anyway, that view is wrong.

What to watch

  • Whether a Korean regulator publishes a tiered network-separation rule, and whether it lifts the per-project AI sandbox for the top tier.
  • KB Kookmin's information-protection budget for next year against the 100 billion won mark, and whether Woori approves its planned 20%-plus rise.
  • Whether the Financial Security Institute and industry associations agree a cost split for monitoring firms outside FSI membership.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption15
Hype gap+25
Incentives60
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Seoul Economic Daily headlined its report 'Korea Weighs Three-Tier Bank Security Rules by Size'.

    ReportedSupportedSource: Seoul Economic Daily headline2 sources— create a free account to open themView cited source
  2. [2]

    There are growing calls within the Korean financial industry for security requirements to be differentiated by institution size; the prevailing view is that, as a first step, large Korean banks should see network separation rules eased further and sharply increase their investment.

    ReportedSupportedSource: Seoul Economic Daily2 sources— create a free account to open themView cited source
  3. [3]

    U.S. banks spend roughly $700 million to $1 billion, about 940 billion to 1.34 trillion won, on security, according to minutes of a September 2022 U.S. House hearing.

    ReportedSupportedSource: Seoul Economic Daily, citing September 2022 US House hearing minutes2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. en.sedaily.com

    1 article · October 11, 2026

    Korea Weighs Three-Tier Bank Security Rules by Size

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories