Survey of 256 financial firms finds ISMS certification gaps
75% of banks certified, but none cover internal support systems
Commercial banks cite voluntary nature of certification
80% of non-bank financial firms hold no certification at all
None of the internal business support systems targeted in recent bank hacking attacks hold information security management system (ISMS) certification, even as major banks have concentrated their ISMS and ISMS-P coverage on customer-facing services such as internet banking, an investigation has found.
Amid growing scrutiny of the financial sector's cybersecurity posture following a wave of AI-assisted hacking, critics say banks have focused their defenses on the "front door" — customer-facing services — while leaving the "side entrance" of internal support platforms dangerously exposed.
The situation is even more serious among non-bank financial firms. About 80 percent of the 236 companies surveyed held no ISMS certification at all — not even for customer-facing services. The firms from which data was leaked in the recent attacks were also found to lack ISMS certification.
ISMS serves as a benchmark for how systematically a financial company has built and operates its information security policies and management framework. The recent hacking incidents have drawn sharp criticism that South Korea's financial sector harbors significant security blind spots.
An investigation surveyed ISMS certificate issuance records held by the Korea Internet & Security Agency for 256 financial companies — banks, insurers (excluding foreign branches), securities firms (excluding foreign branches), capital companies (installment and lease), savings banks and mutual finance cooperatives — registered in the Financial Supervisory Service's financial statistics information system as of Wednesday.
Among the 20 banks surveyed, 15 held ISMS certification. Of those, 12 had also obtained ISMS-P, the expanded certification that incorporates personal data protection. Setting aside institutions with limited retail operations such as the Export-Import Bank of Korea and Korea Development Bank, Sh Suhyup Bank, Citibank Korea and SC First Bank were among those without ISMS certification.
Even among the 15 certified banks, ISMS coverage was concentrated on direct customer touchpoints — primarily internet and mobile banking — rather than internal operations. Of the 35 total ISMS certificates held by those 15 banks, 17 covered internet and mobile banking services, three covered certificate services, two covered mobile virtual network operator services and two covered MyData services. The remaining 10 related to IT data centers and local government treasury operations.
The AI-assisted hacking attacks, believed to have been carried out by a group known as Artex, targeted platforms that support the internal sales operations of bank employees — variously named loan originator support services, business support systems and sales support systems. Sensitive customer data including names, phone numbers, resident registration numbers and addresses was leaked through these platforms, yet none of them were included in any bank's ISMS certification scope.
ISMS is a government-level baseline certification framework that evaluates an organization's information security measures. ISMS-P extends that framework to include personal data protection. Under the current Act on Promotion of Information and Communications Network Utilization and Information Protection, information and communications service providers above a certain scale are required to obtain ISMS certification — but financial companies regulated under the Electronic Financial Transactions Act are explicitly exempted.
As a result, banks and other financial firms are not obligated to obtain ISMS certification even if they meet the scale or user thresholds that would trigger the requirement for other businesses. Financial companies are instead subject to separate financial security regulations under the Electronic Financial Transactions Act and the Regulation on Supervision of Electronic Financial Transactions, making ISMS largely a voluntary certification for the sector. It is, however, widely regarded within the industry as a key indicator of a financial firm's commitment to information security.
The voluntary nature of the certification means its scope can be shaped around whichever services a company chooses to include. An official at one commercial bank said the bank had no choice but to prioritize customer-facing services given limited resources. "ISMS is not mandatory, so which services to certify is entirely up to the bank's discretion," the official said. "With limited resources, we had no choice but to focus on customer-facing services, which are relatively more important."
Complying with information security obligations under financial laws and supervisory regulations alone does not guarantee that a firm's internal security framework is functioning as an integrated whole. ISMS goes beyond mere regulatory compliance — it evaluates whether an organization's information security response system is actually operating effectively from within.
Financial industry officials and security experts say the pattern reflects the sector's longstanding focus on securing the "front door" of customer-facing services. In the recent attacks, AI-driven programs specifically targeted internal business support systems, which tend to have comparatively weaker security controls.
While ISMS certification alone cannot guarantee airtight defenses — particularly as AI-powered hacking techniques grow more sophisticated — experts say the mandatory certification scope should be broadened. Over the long term, they argue, financial firms need to invest in protecting internal support platforms at a level comparable to their customer-facing services.
"Even if you score 100 points by guarding the front door perfectly, what does that score mean if the whole structure starts to crumble from a weak point?" said Kang Kyung-hoon, a professor at Dongguk University's School of Business Administration. "A comprehensive system-wide review is needed." Kwon Tae-kyung, a professor at Yonsei University's Graduate School of Information, said internal support systems should have been secured to the same standard as public-facing ones. "The failure to catch this may be a problem with the current regulatory regime," he said.
Among non-bank financial firms, the number of companies with no certification at all was striking. Of the 236 firms surveyed, 189 — about 80 percent — lacked ISMS certification. Among insurers, 30 of 43 companies were uncertified; among securities firms, 30 of 49. In the capital sector, 46 of 51 companies held no certification. Among savings banks, 77 of 79 were uncertified. Yegareum Savings Bank, from which data on 40,000 customers was leaked, was also among the uncertified firms.
hyuk@heraldcorp.com
rim@heraldcorp.com
