Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

subordinate statute, the Regulations on the Supervi - sion of Electronic Financial Transactions, establishes the specific, granular compliance standards. Entities subject to the EFTA are broadly categorised into “financial companies” and “electronic financial businesses”. “Financial companies” encompass banks, financial investment businesses, insurance companies, credit card companies and mutual sav - ings banks. “Electronic financial businesses” include electronic funds transfer providers, issuers and man - agers of debit and prepaid electronic payment means, and electronic payment gateway (PG) providers (Arti - cle 2 of the EFTA). Comprehensive 2025 Amendment to the Regulations on the Supervision of Electronic Financial Transactions On 5 February 2025, the Regulations on the Supervi - sion of Electronic Financial Transactions underwent a comprehensive revision, marking a fundamental paradigm shift in the financial security regulatory land - scape. A central feature of this overhaul is the transi - tion from a rigid, prescriptive “rule-based” regime to a flexible, “principle-based” framework. The previously sprawling 293 detailed conduct rules were stream - lined to 166. Excessively micro-level and specific reg - ulations were abolished in favour of a structure that presents overarching goals and principles (FSC, Press Release on the Resolution of the Proposed Amend - ment to the Regulations on the Supervision of Elec - tronic Financial Transactions, 5 February 2025). This amendment aims to shift financial institutions away from a passive mindset of “compliance equals immu - nity”, driving them towards an “autonomous security and result accountability” system where they inde - pendently construct security frameworks and bear full responsibility for the outcomes. Notably, this amendment introduced regulations spe - cifically designed to bolster financial cyber resilience against disasters and electronic intrusions. Previous - ly, the mandatory establishment of disaster recovery centres applied only to banks, financial investment businesses and insurance companies. Under the new rules, this obligation has been expanded to include specialised credit finance companies and electronic

financial businesses that meet specific scale thresh - olds. Extraterritorial Application As a general rule, the EFTA and the Regulations on the Supervision of Electronic Financial Transactions apply to all financial companies and electronic finan - cial businesses conducting electronic financial trans - actions within Korea. Domestic branches and offices of foreign financial institutions are expressly included within this jurisdictional scope. 3.2 ICT Service Provider Contractual Requirements Regulations on Electronic Financial Auxiliary Businesses and Outsourcing Under the EFTA An “electronic financial auxiliary business” refers to an entity that assists or performs a portion of electronic financial transactions on behalf of a financial company or an electronic financial business, or an operator of a payment brokerage system, as designated by the FSC (Article 2 (5) of the EFTA). Examples include compre - hensive IT outsourcing providers handling electronic financial tasks and cloud computing providers pro - cessing data related to electronic financial transac - tions. When a financial company or electronic financial busi - ness partners with, entrusts or outsources opera - tions to an electronic financial auxiliary business, it must strictly adhere to robust regulatory controls. For instance, the physical workspaces and computing facilities utilised for outsourced IT system develop - ment must be installed and operated entirely separate from the institution’s internal business networks. The firm must comply with security management proto - cols prescribed by the FSS across all phases of the outsourcing life cycle – including bidding, contracting, execution and completion. Furthermore, the financial entity must evaluate the financial soundness and ser - vice quality of the auxiliary business at least annually and formally report these findings to the FSS (Article 40 of the EFTA; Article 60 of the Regulations on the Supervision of Electronic Financial Transactions).

311 CHAMBERS.COM

Powered by