Interior ministry tightens cybersecurity penalties for public officials
South Korea will raise disciplinary standards for agencies that leak information and expand the national cybersecurity assessment to 2,000 public bodies by 2028.

The interior ministry said Thursday it will raise disciplinary standards for public-sector cybersecurity failures, holding agency heads accountable for serious data leaks after a string of breaches that traced back to basic security rules being ignored.
The plan, drawn up jointly with the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission, also expands the national cybersecurity assessment from 153 institutions this year to about 2,000 state and public bodies by 2028. The government attributed the failures to staff skipping routine safeguards, from failing to change default passwords to leaving identified vulnerabilities unfixed for long periods.
Minimum penalties for cybersecurity violations will be raised through a revision of the enforcement rules of the Public Officials Disciplinary Decree, with explicit processing standards set for breaches of basic information-protection rules. Serious leaks that expose large amounts of data will be written into the same rules as grounds for holding senior supervisors strictly responsible, a provision that currently covers only bribery, dereliction of duty and financial losses. Those changes are due by November and December.
Of about 247 information leak accidents between January 2021 and May 2026, only nine led to disciplinary action, and a non-political agency head has never been directly punished. Even the share of cases passing down to managers or supervisors stayed near 1 percent.
The Personal Information Protection Commission imposed 239 million won ($175,787) per leak in 2024, 274 million won ($201,530) in 2025, and 411 million won ($302,295) per case in the first five months of 2026. Public institutions face a fixed fine capped at 5 billion won.
Officials will review a new information-protection allowance, extra credit in promotion evaluations, and inclusion of information-security duties among critical posts. A critical-post designation pays 150,000 won ($110) a month at grades four and five and 100,000 won ($74) at grade six and below.
Deductions for leaks and credit for rapid response will be added to the cybersecurity assessment, cybersecurity indicators will be introduced into a specific central-government evaluation from 2027 and into the management evaluation of local public enterprises from 2028. Central ministries and regional governments will also add cybersecurity staff, with 100 positions including data-protection roles already filled on Aug. 28, and dedicated security departments headed by private-sector experts planned from next year.
The interior ministry's digital security policy division, led by Kim Kyung-jik, is handling the measures together with the personnel ministry and the privacy commission.
What this article is based on
Every fact in this article can be checked against the primary documents below.
- Government행정안전부 재난안전 보도자료· Ministry of the Interior and Safety· accessed Oct. 4, 2026
- Government발표 주체·성격· korea.kr· accessed Oct. 4, 2026
- Government방안 마련 배경· korea.kr· accessed Oct. 4, 2026
© New Era Korea Daily. All rights reserved.