56 employees left last year, 55 more by September this year
Mass departures threaten investigative expertise in cyber breach probes
Corporate obstruction, including by KT, under scrutiny
More than 50 key personnel at the Korea Internet & Security Agency, or KISA, have left the agency this year, following a similar exodus last year.
KISA, along with the Ministry of Science and ICT, is responsible for investigating cyber breach incidents. The mass departures raise concerns not only about a decline in investigative expertise but also about the agency's ability to properly probe cyber breaches involving companies.
An analysis of KISA workforce data obtained from Kim Jang-gyeom, a lawmaker with the People Power Party, showed that 56 employees left the agency last year. Another 55 left through September this year. The departures amount to more than 10 percent of KISA's roughly 500-member workforce, with most moving on to jobs at companies.
Most of those who left worked in teams that play key roles during investigations. They included the Forensic Analysis, Leak Investigation, Information Security, Vulnerability Analysis, Detection Investigation, Physical Security and Personal Information Policy teams.
KISA serves as the backbone of joint public-private investigation teams formed with the Ministry of Science and ICT whenever a major corporate cyber breach occurs. Under the enforcement decree of the Act on Promotion of Information and Communications Network Utilization and Information Protection, such a joint team must be formed whenever a cyber breach occurs. The team comprises about 20 members from the ministry, KISA and other agencies. The ministry leads the team, while a KISA division director serves as deputy head.
The problem is that such frequent, large-scale departures could erode the expertise needed to investigate cyber breaches. As more former employees move into corporate jobs, concerns are mounting over whether investigations into cyber breaches at companies can be carried out properly.
Former KISA staff with investigative expertise could end up playing a role in downplaying the scale of incidents once they move to companies.
Concerns have grown particularly acute after companies were found to have obstructed investigations into cyber breaches.
In practice, the Ministry of Science and ICT determined in October 2025 that KT Corp had intentionally obstructed a government probe into the company's unauthorized micropayment and hacking case. The ministry referred the case to police for investigation. It marked the first time the government had requested a criminal investigation over a telecom carrier's security probe.
The joint investigation team found that KT had submitted false data regarding the timing of its server disposal. KT also failed to inform the joint investigation team that backup logs from the discarded servers still existed. Concerns are growing that former KISA employees who moved to companies could be mobilized in similar cases.
"As cyber breaches grow more sophisticated and larger in scale, it is critical to prevent the loss of personnel with accumulated experience and expertise," Kim said. "The government is calling for stronger AI and cybersecurity measures, yet it cannot even retain the core personnel on the front lines."
He continued, "If former KISA employees end up helping companies downplay cyber breaches, weakening the nation's cyber investigation capabilities, then no countermeasure will be meaningful." He added, "We need effective institutional measures to ensure that the repeated loss of core personnel does not weaken the nation's cyber response capabilities."
ko@heraldcorp.com
