Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

including conducting research, providing technical support and operating the intake system for data breach incident reports. Financial Services Commission (FSC), Financial Supervisory Service (FSS) and Financial Security Institute (FSI) The FSC is the authority responsible for overall finan - cial policy and serves as the competent authority for the EFTA in relation to cybersecurity in the financial sector. The FSS, while not a central government agen - cy, is a specialised supervisory body subject to the direction and supervision of the FSC and exercises authority delegated by the FSC. In connection with the EFTA, the FSS conducts inspections of and impos - es sanctions on financial institutions and electronic financial business operators. Measures that the FSS may take include corrective orders, recommendations for the dismissal of officers, suspension of business operations and the imposition of administrative penal - ties (Articles 39 and 51 of the EFTA). NIS The NIS is the national agency responsible for coun - terintelligence and national security, and its duties include the prevention of and response to cyber- attacks. Pursuant to the NIS Cybersecurity Regula - tions, the NIS implements preventive cybersecu - rity measures for state agencies, public institutions, schools and government-funded research institutes, including security reviews of information system pro - jects and the establishment of security measures for the use of cloud computing (Article 9 of the NIS Cybersecurity Regulations), and evaluates the overall state of cybersecurity (Article 13 of the NIS Cyberse - curity Regulations). 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation In Korea, cybersecurity regulation for critical infra - structure is primarily governed by the Act on the Protection of Information and Communications Infra - structure.

Under this Act, “information and communications infrastructure” refers to electronic control and manage - ment systems and information and communications networks related to national security, public adminis - tration, national defence, public safety, finance, tel - ecommunications, transportation, energy and similar functions (Article 2 (1)). The heads of central admin - istrative agencies may designate, from among the information and communications infrastructure under its jurisdiction, certain facilities as “critical information and communications infrastructure” where protection from electronic intrusion is deemed necessary, taking into account: • the national and social importance of the functions performed by the institution managing the infra - structure; • the degree of dependence of such functions on the infrastructure; • interconnectivity with other information and com - munications infrastructure; • the scale and scope of potential damage to national security and the economy and society in the event of an incident; and • the likelihood of an incident occurring or the ease of recovery (Article 8 (1)). In addition, the Information and Communications Infrastructure Protection Committee is established under the Prime Minister to deliberate on matters concerning the protection of critical information and communications infrastructure (Article 3 (1)). The Act sets forth various regulatory requirements for the pro - tection of such critical infrastructure. Designation of critical information and communica - tions infrastructure is made on a facility-by-facility basis by the head of the relevant central administra - tive agency. In addition to the foregoing, a separate protection regime for national critical infrastructure exists under the Framework Act on the Management of Disasters and Safety. This Act establishes a management frame - work for national critical infrastructure in sectors such as energy, information and communications, transpor - tation and finance. As a result, certain facilities may be subject to overlapping regulation under both the Act

308 CHAMBERS.COM

Powered by