
As it happens, the second round of selections falls on the 7th — just after a simultaneous wave of AI-driven hacking attacks on banks, savings banks and capital firms from late last month through early this month.
Experts agree that easing network separation rules for AI security in the financial sector, including the second round of selections, must be accelerated. KB Kookmin Bank, the country's largest lender, was left out of the first round. Security industry officials say the thresholds of 2 trillion won in total assets and 300 employees remain too high a hurdle.
That has prompted calls to speed up follow-up selections and make the arrangement permanent to widen participation. "Even if firms want to run AI to block AI-driven hacking, the financial sector's distinctive network separation rules make that difficult," a security industry official said on the 5th. "Circumstances differ by company, but the selection process needs to move faster to enable AI-based defense."
Some argue the scope of privacy verification and AI security inspections should be broadened as well, with greater security investment to allow close scrutiny of business-support websites and applications. One or two life insurers were also reportedly scanned on the same day in reconnaissance ahead of possible hacking attempts. Toss Bank was found to have fended off hacking attempts from the same IP address used by the attacker who struck Shinhan Bank.
"Financial authorities appear to have focused their AI diagnostics on major systems and failed to examine business-support services closely enough," another security industry official said. "Had they found and patched vulnerabilities in those services, they could have blocked leaks through the same route." The point is that diagnostics should extend to any externally accessible service that holds personal data.
Critics also say individual financial companies must sharply expand investment and hire more specialists. According to information security disclosures compiled by the Korea Internet & Security Agency, Shinhan Bank spent 36.9 billion won last year, down 0.4% from a year earlier, while Woori Bank spent 36.4 billion won, down 18.1%. KB Kookmin Bank spent 43.3 billion won, up 1.9%, and Hana Bank spent 37.2 billion won. "Deregulation needs to come with a sharp increase in information security spending," a financial industry official said.
The small number of financial firms certified under the Personal Information & Information Security Management System (ISMS-P) reflects the same problem. "The financial sector has built its security framework around network separation," said Lee Sang-geun, a professor in the School of Smart Security at Korea University's Graduate School of Information Security. "It's an approach of digging a big moat to keep enemies out, and the belief that they were cut off from the outside led them to relatively neglect internal defenses."
Others note that extending AI hacking defenses across financial IT systems will require stronger capabilities to diagnose and patch legacy systems. "In many cases, functions have been bolted onto aging legacy programs for decades, so even when a vulnerability is known it is hard to fix," a senior financial industry official said. "Not only is it hard to find experts who understand and can overhaul these systems, but years of patchwork updates mean the risk of cascading failures can't be ruled out."
According to financial authorities and the Financial Security Institute, some financial companies are still using old programming languages such as COBOL. Longstanding business processes and data linkage structures make switching languages difficult, so firms stick with the old approach. KB Kookmin Bank went so far as to recruit staff last December to automate the conversion of COBOL to Java using AI.
Within the financial industry, there are calls to translate certifications and AI security tools into real improvements in defense capability — meaning the continuous monitoring of systems that handle personal data and the patching of vulnerabilities must become routine management practice.






