Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

the financial sector. Its subordinate regulation, the Regulations on the Supervision of Electronic Financial Transactions, establishes detailed security standards. Notably, the Regulations on the Supervision of Elec - tronic Financial Transactions was comprehensively amended on 5 February 2025, shifting financial secu - rity regulation from a rules-based approach to a more flexible principles-based framework. This amendment laid the groundwork for greater autonomy in security practices within the financial sector and strengthened the resilience of financial IT systems to ensure stable protection of the financial system against disasters and electronic intrusions. Act on the Protection of Information and Communications Infrastructure This Act governs the safeguarding of “critical infor - mation and communications infrastructure” (these are facilities designated for heightened protection against cyber-intrusions due to the socio-economic importance of the managing agency’s functions, as well as the potential scale of damage to national security and the broader economy in the event of a breach). The Act imposes stringent obligations on the heads of organisations managing such infrastructure, which include formulating comprehensive protection plans (Article 5), conducting vulnerability analyses and assessments (Article 9), and reporting any infringe - ment incidents (Article 13). NIS Cybersecurity Regulations The Cybersecurity Regulations are a Presidential Decree governing cybersecurity-related functions of the NIS. As they also regulate the prevention of and response to cyber-attacks and threats targeting state agencies, public institutions, schools and gov - ernment-funded research institutes, they constitute a key regulatory framework for cybersecurity in the public sector. Unfair Competition Prevention and Trade Secret Protection Act The Unfair Competition Prevention and Trade Secret Protection Act affords statutory protection to corpo - rate trade secrets. Where a company’s trade secrets are misappropriated through a cyber-intrusion inci - dent, the prohibitions against trade secret infringe -

ment under the Act (Article 2 (3), Article 18 (1)–(3)) and the related civil and criminal remedies may become applicable. 1.3 Cybersecurity Regulators Ministry of Science and ICT (MSIT) and Korea Internet & Security Agency (KISA) As the competent ministry overseeing the Network Act, the Act on the Protection of Information and Communications Infrastructure and the AI Framework Act, the MSIT directs cybersecurity policy across the private sector. While not a central government agency, KISA oper - ates as a statutory public institution playing a core operational role in national cybersecurity. Its primary functions include acting as the national computer emergency response team (CERT). In this capac - ity, KISA is responsible for receiving, analysing and responding to private-sector cyber-infringement inci - dents, maintaining a 24-hour rapid response system. Furthermore, KISA operates the Cyber Threat Analy - sis and Sharing (C-TAS) platform – a centralised sys - tem for collecting, analysing and disseminating cyber threat intelligence – to facilitate real-time information sharing among private enterprises. It also conducts ISMS certification audits, supports vulnerability analy - ses and assessments for critical information and com - munications infrastructure, and manages the internet of things (IoT) security certification framework. Personal Information Protection Commission (PIPC) As the primary regulatory authority responsible for enforcing PIPA, the PIPC conducts comprehensive research and support initiatives regarding data protec - tion, while concurrently exercising statutory authority to investigate and sanction PIPA violations. Specifically, the PIPC wields robust enforcement mechanisms under PIPA, including the authority to demand data submissions and conduct on-site inspections (Article 63), issue corrective orders (Article 64), and impose administrative penalties (Article 64-2) and administrative fines (Article 75). Notably, KISA is frequently entrusted with executing a portion of the PIPC’s cybersecurity-related mandates,

307 CHAMBERS.COM

Powered by