Invest1 publisher3 min readPublished
Korean savings banks match commercial banks' security share of IT spending with a fraction of the staff
Korea's 79 savings banks serve 10.17 million clients, while Shinhan Savings Bank and Welcome Savings Bank each run security with fewer than eight staff. Both already give security a commercial bank's share of IT spending, and industry officials say the harder shortage to fix is people.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Shinhan Savings Bank spent 1.15 billion won and Welcome Savings Bank 3.75 billion won on information protection last year, far below the tens of billions commercial banks invest.
- Of the 79 savings banks, 67, or 84.8%, run on the federation's integrated computing system, according to data released in April.
- About 18% of life insurers and only 6% of capital finance companies hold ISMS-P certification, a gap officials attribute to cost and staffing.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision A government package that funds vulnerability tools alone would repeat Welcome's year, so support has to pay for the people who review findings and fix systems.
- constraint Savings banks hire after banks, insurers, brokerages and card firms, so a bigger budget buys a place at the back of the security hiring queue.
- exposure The 12 banks outside the shared system, and every bank's own external access services, would still fall to thin in-house teams under a pooled check.
Divide each bank's security bill by the share of IT spending it accounts for, and the scale gap shows up in won. Shinhan Savings Bank's 1.15 billion won at 9.8% implies a total IT budget of about 11.7 billion won. Welcome Savings Bank's 3.75 billion won at 15.8% implies about 23.7 billion [3][4][1]. Neither share is lower than a commercial bank's, according to Seoul Economic Daily's tally of Korea Internet & Security Agency disclosures [4]. Commercial banks' security spending alone runs to tens of billions of won [3].
The staffing gap is wider. Commercial banks have nearly 100 dedicated security staff, roughly 13 times Welcome's 7.8 and 16 times Shinhan's 6.1 [5][6]. Money has not closed that gap at Welcome, whose security spending rose 43.2% last year from about 2.62 billion won, an increase of about 1.13 billion won, while its dedicated headcount fell to 7.8 from 8.3 [7][2]. The disclosure does not show where the extra money went. Welcome now spends about 481 million won per dedicated staffer, against about 189 million won at Shinhan [3].
"If security professionals are coming to the financial sector, wouldn't they go to the banks first?" an official in the savings bank industry said, according to Seoul Economic Daily. "Once you take out the insurers, brokerages and card companies, hardly anyone wants to come all the way down to savings banks and mutual finance." [8] Lotte Card's figures fit that queue. It reported 12.57 billion won of security spending and 36.5 dedicated staff, about 344 million won a head, while Lotte Capital reported 2.64 billion won and 7 staff [6][5].
If Seoul pays for vulnerability-assessment tools and stops there, it buys more years like Welcome's. "Even if you bring in artificial intelligence tools that help analyze vulnerabilities, you still need people to review the findings and fix the systems," a financial industry official said [9]. Officials want support to run from tool adoption through remediation, with assessment tools and specialists shared across firms [10]. If nothing is done, certification rates show where small firms stall. About 18% of life insurers and 6% of capital finance companies hold ISMS-P certification, a gap officials put down to cost and staffing [11].
The 79 banks had 6.47 million depositors and 3.70 million borrowers at the end of June, 10.17 million clients in all [1][2]. Of those banks, 67, or 84.8%, already run on the federation's integrated computing system [12]. I think pooled inspection through the federation is the cheapest route, because one team can check the shared core for all 67 at once. The counter-case is at the edges. Twelve banks sit outside that system [4], and each bank's own external access services sit outside any shared check. "Reorganizing the scope of support so that checks extend beyond the shared computing system to each company's own external access services is another approach," a financial industry official said [13]. Industry officials say the load on those systems is growing as firms expand through non-face-to-face channels [14].
The view that people are scarcer than money is wrong if headcount follows budget once budgets grow large enough. Lotte Card is the one firm in the report whose numbers point that way, and card companies sit ahead of savings banks in the hiring queue the savings bank official described [6][8].
What to watch
- Whether any government support for non-bank security covers remediation staff and shared specialists, or stops at assessment tools.
- Whether the savings bank federation extends joint checks beyond its integrated computing system to each bank's external access services.
- Next year's KISA disclosures, to see whether Welcome's security headcount recovers above 8.3 as spending grows.