FSS chief visits Financial Security Institute's monitoring center; pilot security assessment for AI agents in financial sector planned
Financial Supervisory Service chief Lee Chan-jin personally inspected the financial sector's cybersecurity posture Thursday and urged executives to take a more active role in safeguarding their institutions.
The FSS said Lee visited the Financial Security Institute's Financial Security Operations Center in Jukjeon, Gyeonggi Province, on Thursday to review the progress of the "2026 First-Half Financial Sector Blind Penetration Test."
The blind penetration test is a live-fire drill in which white-hat hackers launch unannounced attacks — without disclosing the timing or targets in advance — to assess financial firms' ability to detect and repel intrusions and to evaluate their emergency response systems. This year, in line with a "proactive digital risk supervision plan" announced April 7, the FSS expanded the range of attack types and doubled the number of participating firms to 40, up from 20 last year. The exercise runs from May through June.
The site visit followed Lee's oversight of an internal FSS emergency response drill on May 7. By also inspecting the blind penetration test targeting financial firms, Lee sought to underscore the importance of cybersecurity across the financial sector and encourage executives to strengthen their institutions' security capabilities.
At the drill site, Lee received briefings on the financial sector's security operations status and the progress of the blind penetration test. He also reviewed how financial firms are responding to major cyber threats — including DDoS attacks, server hacking and simulated intrusions — as well as emerging threats arising from the rapid spread of AI services.
"Financial firms must continuously review and improve their cyber threat response posture and do their utmost to prevent breaches before they occur," Lee said. "If an incident does happen, restoring core services quickly and minimizing consumer harm must be the top priority, with consumer protection front and center."
He particularly urged CEOs and other executives to take the lead in personally verifying on site whether their incident response systems can function in a real crisis, and to actively expand the budgets, personnel and organizational structures needed to build sufficient security capacity. He also called on firms to prepare proactively by auditing and patching security vulnerabilities, setting patch priorities and reviewing emergency response plans.
The Financial Security Institute addressed the growing cyber threats posed by ultra-high-performance frontier AI models — including Claude and Mythos — as a key agenda item at this year's financial sector AI seminar. In response, the institute plans to develop a financial AI safety and reliability framework and AI agent security standards, and to launch a pilot assessment program for financial firms.
The FSS plans to require firms to immediately address the individual vulnerabilities identified during the drill, while distributing common weaknesses and areas requiring improvement as advisories to strengthen the overall cyber threat response posture across the financial sector.
psj@heraldcorp.com
