Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

on the Protection of Information and Communications Infrastructure and the Framework Act on the Manage - ment of Disasters and Safety. 2.2 Critical Infrastructure Cybersecurity Requirements Obligation to Establish Protection Measures The head of the management institution responsible for critical information and communications infra - structure must establish and implement annual pro - tection measures for the relevant facilities (Act on the Protection of Information and Communications Infrastructure, Article 5). Such protection measures must include risk management based on the results of vulnerability analyses and assessments, physical, technical and organisational safeguards, and incident response plans. Implementation of these protection measures is subject to inspection by MSIT, the NIS, and the Ministry of National Defense (Article 5-2). Vulnerability Analysis and Assessment Vulnerability analyses and assessments of critical information and communications infrastructure must be conducted periodically (at least once per year) (Article 9). The MSIT has published the “Standards for Vulnerability Analysis and Assessment of Critical Infor - mation and Communications Infrastructure”, which set forth detailed methods and procedures. These standards were amended on 24 December 2025 to reflect changes in the information and communication technology (ICT) environment, including the addition of inspection items relating to cloud and web services. Compliance With Protection Guidelines Central administrative agencies may promulgate sec - tor-specific protection guidelines for critical informa - tion and communications infrastructure and mandate that the heads of managing agencies strictly adhere to them (Article 10). These guidelines include technical and organisational matters relating to infrastructure protection and are applied in a differentiated manner reflecting sector-specific characteristics. Recovery Measures in the Event of an Incident Where a critical information and communications infra - structure facility is disrupted, paralysed or destroyed due to an electronic intrusion, the head of the man - agement institution must promptly take the necessary

measures for restoration and protection. The head of the relevant central administrative agency may issue orders to this effect, and if such orders are not issued, the NIS may do so in lieu thereof (Article 14). ISMS Certification Separately from the protection obligations under the Act on the Protection of Information and Communi - cations Infrastructure, Article 47 of the Network Act requires certain ICSPs above a specified size to obtain ISMS certification. For further details, see 5.1 Key Cybersecurity Certification Legislation . 2.3 Incident Response and Notification Obligations Reporting Obligations Under the Act on the Protection of Information and Communications Infrastructure Where an electronic intrusion (eg, hacking, malware infections or DDoS) occurs in relation to critical infor - mation and communications infrastructure, the head of the management institution must report the incident to the relevant authorities and to KISA (Article 13 (1)) [TJK1.1][LK1.2]. While the Act does not specify a pre - cise deadline, the report must be made as promptly as reasonably practicable. Incident Reporting under the Network Act An ICSP must report an incident to the MSIT or KISA within 24 hours from the time it becomes aware of the incident (Article 48-3). The report must include an overview of the incident, the extent of the damage and response measures taken. Notification and Reporting of Data Breaches Under PIPA Where a data handler becomes aware of a data breach, it must notify the affected data subjects within 72 hours (Article 34 (1)). In addition, where personal information is leaked due to unlawful external access to a personal information processing system, the data handler must report the breach to the PIPC or KISA within 72 hours (Article 34 (3) of PIPA and Article 40 of its Enforcement Decree). For further details, see 6.1 Cybersecurity and Data Protection .

309 CHAMBERS.COM

Powered by