This page was machine-translated and may differ from the original. View original
The Ministry of Science and ICT released the results of its 2018 Information Security Survey, stating, "Ransomware damage has increased significantly."
| Businesses Must Follow Ransomware Prevention Guidelines
| Individuals, invasion of privacy is considered the most serious
The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) announced the results of the 2018 Information Security Survey, which examined corporate and individual awareness of information security and the prevention and response to security breaches. 
2018 Information Security Survey
This survey was conducted through interviews with 9,000 businesses with one or more employees in the corporate sector and 4,000 internet users aged 12 to 69 in the individual sector.
According to a survey of the corporate sector, awareness of the importance of information security increased (2.8%), but budgeting and allocation decreased slightly. Only 36.2% of businesses have a budget for information security (personal information protection) (down 11.9 percentage points from the previous year), and only 1.7% of businesses (down 0.5 percentage points from the previous year) allocated more than 5% of their IT budget to this area.
This is interpreted as a rapid change in corporate information security policies due to the fact that no large-scale attacks (DDOS, system hacking, etc.) or personal information leaks occurred during the survey period, and the increased use of information security services (security control, maintenance, consulting, etc.) (22.5%) rather than direct purchase of information security products and personnel operation.
It is also estimated that the increase in corporate budget investment in cloud services has had some impact. Professional research on this matter will be conducted in the future by improving the questionnaire items during the actual survey.
The rate of business breaches was 2.3%, similar to the previous year's survey results (2.2%), and most breaches were minor (69.2%). However, among the types of experiences, damage caused by ransomware increased significantly (56.3%, up 30.8 percentage points).
By type of breach, the order was ransomware (56.3%) > malware (47.7%) > adware/spyware (12.1%) > hacking (4.4%).
Recently, new and variant ransomware threats are extending beyond personal and corporate PCs, causing widespread damage to diverse industries, including healthcare, transportation, and manufacturing. Therefore, strengthening information security is essential, including implementing vulnerability management systems, implementing ransomware prevention guidelines, and enhancing user security awareness.
The system and network security inspection rate for security breach prevention reached 90%, a 25.3% increase year-on-year. Other activities included applying security patches and implementing backup systems. Inspection cycles varied between irregular (67.1%) and regular (27.1%). Analysis by system and network type revealed a slight increase in the use of intelligent services, which provide insight into trends in the use of new information and communication technology (ICT).
As the number of products incorporating new technologies such as IoT and AI increases, the importance of security is increasingly emphasized. Considering that these products are connected to the Internet and thus pose a risk of network-based security incidents, it appears necessary to prepare for large-scale damage in the event of service disruption due to information leaks, resource sharing, and centralization.
According to the results of a survey on the personal sector, most Internet users consider information protection (96.2%, up 2.0% year-on-year) and personal information protection (97.3%, up 0.7% year-on-year) to be important.
Awareness of the importance of information protection and personal information protection was high for both men and women, and while awareness was high across all age groups, awareness of information protection was highest among those in their 30s (97.3%), and awareness of personal information protection was highest among those in their teens (98.5%).
Among the threats to information security, the areas considered most serious are 'personal information leaks and invasion of privacy' (88.9%) > malware infection (86.8%) > financial damage such as phishing/pharming/smishing (86.2%), in that order. Meanwhile, concerns about ransomware damage (76.5%) were relatively low.
The rate of breach incidents decreased by 5.7% year-on-year to 4.6%.
The detailed types of intrusion incidents include malware (3.4%), personal information leaks (1.9%), and financial damages such as phishing/pharming/smishing (0.6%), and overall, there has been a decrease compared to the previous year.
This appears to be the result of a reduction in large-scale personal information leaks and promotional activities by the government and public institutions to raise awareness and spread a culture of information protection.
By detailed type of security incident response activity, the most common actions were 'installation of security software' (41.4%), 'strengthening self-inspection and prevention activities' (41.1%), and 'password change' (40.4%).
This survey added mobile device items to the existing PC-based survey.In addition, the target age for the survey was raised (from 59 to 69 years old) in line with the increase in Internet use among the elderly.
To prevent security breaches, users were found to have implemented security measures such as anti-virus program updates (97.5% for PCs and 97.2% for mobile devices) and operating system security updates (93.5% for PCs and 90.1% for mobile devices).
Among those in their 60s who were surveyed for the first time, the most common reasons for not using information security products and not updating operating system security were ‘not knowing how to use them’ (73.1%) and ‘not knowing how to update or the procedure’ (54%), indicating the need for education and publicity on security measures to prevent security breaches.
Intelligent service usage rates are increasing across the board.
Measures to prevent damage from cloud services included 'encrypting important files before sharing' (50.3%), 'checking sharing functions and access rights' (50.0%), and 'regularly backing up to external devices' (46.6%).
Security concerns regarding the popularization of AI-based services included 'infringement due to illegal collection of personal information' (69.5%), 'illegal exploitation through hacking' (66.1%), and 'malfunction due to technical vulnerabilities and errors' (42.2%).
As IoT products and services proliferate, the respondents expressed concerns in the following order: 'increased threats to personal information due to the generation and processing of a large number of data' (56.9%), 'increased management vulnerabilities' (52.3%), and 'increased intensity and functionality of cyberattacks' (42.3%).
Oh Yong-su, Director of Information Protection Policy at the Ministry of Science and ICT, said, “Now, information protection awareness is very important for both companies and individual Internet users.“We have confirmed through the 2018 Information Security Status Survey that we are aware of this,” he said, adding, “It is expected that new cyber threats will increase due to the development and expansion of ICT technology.” He added that he would quickly prepare and implement countermeasures for the areas in need of improvement revealed in the survey.
| Individuals, invasion of privacy is considered the most serious
The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) announced the results of the 2018 Information Security Survey, which examined corporate and individual awareness of information security and the prevention and response to security breaches.

2018 Information Security Survey
This survey was conducted through interviews with 9,000 businesses with one or more employees in the corporate sector and 4,000 internet users aged 12 to 69 in the individual sector.
According to a survey of the corporate sector, awareness of the importance of information security increased (2.8%), but budgeting and allocation decreased slightly. Only 36.2% of businesses have a budget for information security (personal information protection) (down 11.9 percentage points from the previous year), and only 1.7% of businesses (down 0.5 percentage points from the previous year) allocated more than 5% of their IT budget to this area.
This is interpreted as a rapid change in corporate information security policies due to the fact that no large-scale attacks (DDOS, system hacking, etc.) or personal information leaks occurred during the survey period, and the increased use of information security services (security control, maintenance, consulting, etc.) (22.5%) rather than direct purchase of information security products and personnel operation.
It is also estimated that the increase in corporate budget investment in cloud services has had some impact. Professional research on this matter will be conducted in the future by improving the questionnaire items during the actual survey.
The rate of business breaches was 2.3%, similar to the previous year's survey results (2.2%), and most breaches were minor (69.2%). However, among the types of experiences, damage caused by ransomware increased significantly (56.3%, up 30.8 percentage points).
By type of breach, the order was ransomware (56.3%) > malware (47.7%) > adware/spyware (12.1%) > hacking (4.4%).
Recently, new and variant ransomware threats are extending beyond personal and corporate PCs, causing widespread damage to diverse industries, including healthcare, transportation, and manufacturing. Therefore, strengthening information security is essential, including implementing vulnerability management systems, implementing ransomware prevention guidelines, and enhancing user security awareness.
The system and network security inspection rate for security breach prevention reached 90%, a 25.3% increase year-on-year. Other activities included applying security patches and implementing backup systems. Inspection cycles varied between irregular (67.1%) and regular (27.1%). Analysis by system and network type revealed a slight increase in the use of intelligent services, which provide insight into trends in the use of new information and communication technology (ICT).
As the number of products incorporating new technologies such as IoT and AI increases, the importance of security is increasingly emphasized. Considering that these products are connected to the Internet and thus pose a risk of network-based security incidents, it appears necessary to prepare for large-scale damage in the event of service disruption due to information leaks, resource sharing, and centralization.
According to the results of a survey on the personal sector, most Internet users consider information protection (96.2%, up 2.0% year-on-year) and personal information protection (97.3%, up 0.7% year-on-year) to be important.
Awareness of the importance of information protection and personal information protection was high for both men and women, and while awareness was high across all age groups, awareness of information protection was highest among those in their 30s (97.3%), and awareness of personal information protection was highest among those in their teens (98.5%).
Among the threats to information security, the areas considered most serious are 'personal information leaks and invasion of privacy' (88.9%) > malware infection (86.8%) > financial damage such as phishing/pharming/smishing (86.2%), in that order. Meanwhile, concerns about ransomware damage (76.5%) were relatively low.
The rate of breach incidents decreased by 5.7% year-on-year to 4.6%.
The detailed types of intrusion incidents include malware (3.4%), personal information leaks (1.9%), and financial damages such as phishing/pharming/smishing (0.6%), and overall, there has been a decrease compared to the previous year.
This appears to be the result of a reduction in large-scale personal information leaks and promotional activities by the government and public institutions to raise awareness and spread a culture of information protection.
By detailed type of security incident response activity, the most common actions were 'installation of security software' (41.4%), 'strengthening self-inspection and prevention activities' (41.1%), and 'password change' (40.4%).
This survey added mobile device items to the existing PC-based survey.In addition, the target age for the survey was raised (from 59 to 69 years old) in line with the increase in Internet use among the elderly.
To prevent security breaches, users were found to have implemented security measures such as anti-virus program updates (97.5% for PCs and 97.2% for mobile devices) and operating system security updates (93.5% for PCs and 90.1% for mobile devices).
Among those in their 60s who were surveyed for the first time, the most common reasons for not using information security products and not updating operating system security were ‘not knowing how to use them’ (73.1%) and ‘not knowing how to update or the procedure’ (54%), indicating the need for education and publicity on security measures to prevent security breaches.
Intelligent service usage rates are increasing across the board.
Measures to prevent damage from cloud services included 'encrypting important files before sharing' (50.3%), 'checking sharing functions and access rights' (50.0%), and 'regularly backing up to external devices' (46.6%).
Security concerns regarding the popularization of AI-based services included 'infringement due to illegal collection of personal information' (69.5%), 'illegal exploitation through hacking' (66.1%), and 'malfunction due to technical vulnerabilities and errors' (42.2%).
As IoT products and services proliferate, the respondents expressed concerns in the following order: 'increased threats to personal information due to the generation and processing of a large number of data' (56.9%), 'increased management vulnerabilities' (52.3%), and 'increased intensity and functionality of cyberattacks' (42.3%).
Oh Yong-su, Director of Information Protection Policy at the Ministry of Science and ICT, said, “Now, information protection awareness is very important for both companies and individual Internet users.“We have confirmed through the 2018 Information Security Status Survey that we are aware of this,” he said, adding, “It is expected that new cyber threats will increase due to the development and expansion of ICT technology.” He added that he would quickly prepare and implement countermeasures for the areas in need of improvement revealed in the survey.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













