Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

Reporting to the FSS Under the EFTA A financial institution or electronic financial business operator must notify the FSC without delay upon the occurrence of an incident (Article 21-5) and must report certain electronic financial incidents to the FSS (Article 37-5 of the Regulations on Supervision of Electronic Financial Transactions and Article 7-4 (1) of its Detailed Enforcement Rules). For further details, see 3.3 Key Operational Resilience Obligations . Concurrent Reporting Obligations Even where a single hacking incident occurs, the affected entity is, in principle, required to comply with reporting and notification obligations under each applicable statute, depending on the type and scope of the incident. While reporting under the Network Act may be deemed satisfied if reporting under another statute has been completed, differences in deadlines and required content mean that separate reporting is typically carried out in practice. Given that each stat - ute prescribes different reporting timelines, content requirements and reporting channels, it is critical to promptly identify and simultaneously fulfil all appli - cable reporting obligations at the initial stage of an incident. 2.4 State Responsibilities and Obligations National Cyber Crisis Management System The Korean government operates a four-tier national cyber crisis alert system – Attention, Caution, Alert and Severe – based on the seriousness of cyber threats (Article 15 of the NIS Cybersecurity Regulations). Depending on the alert level, the response posture and emergency working arrangements of government agencies are adjusted accordingly. The MSIT (for the private sector) and the NIS (for the public sector) are responsible for issuing alerts within their jurisdictions. The government’s role extends beyond threat detec - tion and information sharing to include recovery sup - port following incidents. As discussed in 2.2 Critical Infrastructure Cybersecurity Requirements , under the Act on the Protection of Information and Com - munications Infrastructure, in the event of an inci - dent affecting critical information and communica - tions infrastructure, the head of the relevant central administrative agency or the director of the NIS may order necessary measures for restoration and protec -

tion (Article 14 (2)). Where incidents occur on a wide - spread basis, the Information and Communications Infrastructure Protection Committee may establish an incident response headquarters for a specified period to implement emergency measures, provide technical support and facilitate damage recovery, and may sec - ond relevant public officials to respond to the incident (Article 15). Threat Intelligence Sharing KISA operates C-TAS, a platform that collects, analy - ses and shares cybersecurity threat information in real time in the private sector. Through C-TAS, companies may voluntarily share and utilise malware samples, IP block lists, vulnerability information and similar data. In addition, pursuant to Article 16 of the Act on the Protection of Information and Communications Infra - structure, sector-specific information sharing and analysis centres (ISACs) have been established and are in operation. ISACs collect and analyse informa - tion on vulnerabilities and incidents relating to criti - cal information and communications infrastructure in their sectors and provide such information to relevant institutions. ISACs are currently operating in multiple sectors, including finance, telecommunications and public administration. Public-Private Co-Operation In the event of a large-scale incident, a joint public- private investigation task force may be established, comprising the MSIT, KISA, the National Police Agen - cy and relevant companies, to analyse the causes of the incident and formulate response measures (Article 48-4 of the Network Act). In addition, MSIT and KISA regularly conduct cybersecurity drills involving private companies to strengthen cyber-incident response capabilities in the private sector. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation EFTA In Korea, cybersecurity regulations within the financial sector are primarily anchored by the EFTA, while its

310 CHAMBERS.COM

Powered by