Skip to content
New Era Korea Daily한국어로 보기

Korea tightens cyber discipline rules as agency heads escape penalties

The Personal Information Protection Commission and three other government bodies will hold agency chiefs accountable for serious data leaks and expand security evaluations to 2,160 institutions by 2028.

By New Era Daily AIAI-writtenPublished
Illustration: Korea tightens cyber discipline rules as agency heads escape penalties
Science and technology — Illustration: New Era Korea Daily · AI-generated

The Personal Information Protection Commission said Thursday that South Korea will hold agency heads directly accountable for serious information leaks, tightening disciplinary standards after a review found that almost no one had been punished for the public sector's worst security failures.

Under the measures drawn up jointly with the Ministry of the Interior and Safety, the National Intelligence Service and the Ministry of Personnel Management, supervisors will be named in the enforcement rules of the public official disciplinary decree as responsible for grave leaks, with minimum disciplinary levels raised from their current settings. The rules are to be revised by November.

The decision follows an official review of roughly 247 information leak incidents between 2021 and May 2026. Only nine resulted in any disciplinary action, and in none of those cases was an agency head personally punished. Officials attributed the gap largely to weak enforcement of basic security practices rather than to sophisticated attacks, citing a recent leak at startup data provider Modu and a ransomware infection at a national university hospital.

Basic violations that carried no clear handling guidance until now will also fall under the disciplinary framework, including failing to change an initial password and leaving identified security flaws unaddressed for extended periods.

Because expanded discipline risks driving officials away from security posts, the government will pair the crackdown with incentives: a new information protection allowance under review, bonus points in performance evaluations for promotion, and inclusion of security work in the criteria for designating key positions.

The National Intelligence Service's cyber security assessment, which covered 153 organizations this year, will expand to 868 next year and to all 2,160 state and public institutions from 2028, with new indicators deducting points for leak incidents while crediting rapid responses.

The government plans to add cyber security staff at central agencies and metropolitan governments, and to establish dedicated units headed by private-sector experts over the medium and long term.

Only 11 of 49 central government agencies, or 22 percent, run a dedicated security division or team, and 37 agencies, or 24 percent, fall short of required personnel levels. The average public-sector fine per case has climbed sharply, from 23 million won ($16,917) in 2023 to 239 million won ($175,787) in 2024 (274 million won, or $201,530, in 2025), reaching 411 million won ($302,295) in the first five months of 2026.

What this article is based on

Every fact in this article can be checked against the primary documents below.

  1. Government개인정보보호위원회 개인정보 보도자료· Personal Information Protection Commission· accessed Oct. 4, 2026
  2. Government방안 마련 배경· korea.kr· accessed Oct. 4, 2026
  3. Government공동 발표 주체· korea.kr· accessed Oct. 4, 2026
  4. Government기관장 징계 실태· korea.kr· accessed Oct. 4, 2026
  5. Government주요 담당 부서· korea.kr· accessed Oct. 4, 2026

© New Era Korea Daily. All rights reserved.