This page was machine-translated and may differ from the original. View original
77% of Companies Say They Have No Plans to Adopt Zero Trust... Reason is 'Lack of Information'
Need to Raise Awareness Among Korean Zero Trust Demand Companies
Ministry of Science and ICT Announces Two Zero Trust Models for Different Work Environments
Implementing Zero Trust is a long journey, not a solution for replacing infrastructure or procedures.
Experts have suggested that long-term investment is necessary to adopt Zero Trust security suitable for the domestic environment, involving the setting of strategies and goals tailored to corporate circumstances and maturity levels. To this end, emphasis is being placed on establishing policies to raise overall awareness of Zero Trust security and ensuring compatibility with existing security products when building models.
At the Zero Trust security model demonstration results sharing meeting held by the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) at the Fairmont Ambassador on the 11th, the results and strategies for the introduction and demonstration of Zero Trust security were discussed.
'Zero Trust' is a security strategy that enhances security by gaining reliability through continuous verification based on the assumption that an internal infection already exists. Recently, the concept has expanded from traditional network security to all core elements of the enterprise network.
The Zero Trust security concept expanded rapidly following the 2014 data breach involving 20 million people at the U.S. Office of Personnel Management, and it began to gain attention in Korea as well, amidst digital transformation, the increase in remote work, and the sophistication of cyber threats following the COVID-19 pandemic.
In October 2022, the domestic Zero Trust Forum was launched to establish a strategy for the introduction of Zero Trust in the public and private sectors, and Zero Trust Guidelines 1.0 were released in July 2023 to strengthen the competitiveness of domestic companies.
However, despite the importance of such Zero Trust security, it is currently predicted that it will take time for Zero Trust to flourish in Korea.
According to Professor Yoo Jin-ho of Sangmyung University, more than half of the companies seeking Zero Trust—62.5%—answered that they “do not know.” Additionally, the majority—77%—answered that they “have no plans to adopt it.”
Among these, 'lack of information' regarding Zero Trust was identified as the main problem preventing adoption, accounting for 62%. The ultimate limitation is that demand-side companies do not recognize the necessity of adoption and therefore do not see it as worthwhile to invest.
Accordingly, 78.3% of client companies considered "raising awareness of the necessity of Zero Trust" to be the most important policy. This suggests that, given the security model is still in its early stages, the government needs to raise awareness regarding incentives for adoption and its differentiation from existing security systems. To this end, a detailed implementation roadmap that client companies can accept across various sectors is emphasized.
Professor Yoo argued, “The task in the first stage is to consider what the adoption of zero-trust security can offer to client companies.” Furthermore, they argued that “global Zero Trust providers must ensure compatibility between solutions and establish a trusted environment among companies by opening APIs,” and that “best practices for Zero Trust models suitable for the domestic environment must be disseminated through continuous demand-supplier pilot projects.”
■ Ministry of Science and ICT Announces K-Zero Trust Security Model
On this day, the Ministry of Science and ICT announced two types of 'Zero Trust Basic Models' applicable to domestic corporate network environments: cloud-based and on-premise models. It also established scenarios to verify security effectiveness.
The demonstration project for the domestic Zero Trust (K-Zero Trust) security model broke ground this July following the publication of the guidelines.
First, by applying a cloud-based Zero Trust security model, services, servers, applications, and data can be logically separated and protected. This makes it easier to apply Zero Trust security to SaaS applications in the future.
In the telecommunications sector as well, vulnerabilities that could lead to DDoS attacks on domestic networks have been improved. Problems in the wireless communication network environment can be blocked at the source by developing and applying a dedicated router equipped with a PEP (Policy Enforcement Point).
In addition, we confirmed the potential to enhance security from the connection stage during virtual private network-based remote and work-from-home environments, even in on-premises settings, and to provide a customized Zero Trust security model.
In 2024, the Ministry of Science and ICT plans to expand the scope of support for demonstration projects through a new budget of 6.2 billion won and publish Guideline 2.0 in the first half of next year.
Jeong Eun-su, Head of the Information Security Industry Division at the Ministry of Science and ICT, said, “In Guideline 2.0, we will consider ways to drive expansion from a legal and institutional perspective, while making it more specific based on demonstration cases and maintaining connectivity with existing security systems.”
He also stated, “In the future, we will analyze specific characteristics by industry domain and implement practically necessary models to expand in line with actual market demand.”
Experts have suggested that long-term investment is necessary to adopt Zero Trust security suitable for the domestic environment, involving the setting of strategies and goals tailored to corporate circumstances and maturity levels. To this end, emphasis is being placed on establishing policies to raise overall awareness of Zero Trust security and ensuring compatibility with existing security products when building models.
At the Zero Trust security model demonstration results sharing meeting held by the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) at the Fairmont Ambassador on the 11th, the results and strategies for the introduction and demonstration of Zero Trust security were discussed.
'Zero Trust' is a security strategy that enhances security by gaining reliability through continuous verification based on the assumption that an internal infection already exists. Recently, the concept has expanded from traditional network security to all core elements of the enterprise network.
The Zero Trust security concept expanded rapidly following the 2014 data breach involving 20 million people at the U.S. Office of Personnel Management, and it began to gain attention in Korea as well, amidst digital transformation, the increase in remote work, and the sophistication of cyber threats following the COVID-19 pandemic.
In October 2022, the domestic Zero Trust Forum was launched to establish a strategy for the introduction of Zero Trust in the public and private sectors, and Zero Trust Guidelines 1.0 were released in July 2023 to strengthen the competitiveness of domestic companies.
However, despite the importance of such Zero Trust security, it is currently predicted that it will take time for Zero Trust to flourish in Korea.
According to Professor Yoo Jin-ho of Sangmyung University, more than half of the companies seeking Zero Trust—62.5%—answered that they “do not know.” Additionally, the majority—77%—answered that they “have no plans to adopt it.”
Among these, 'lack of information' regarding Zero Trust was identified as the main problem preventing adoption, accounting for 62%. The ultimate limitation is that demand-side companies do not recognize the necessity of adoption and therefore do not see it as worthwhile to invest.
Accordingly, 78.3% of client companies considered "raising awareness of the necessity of Zero Trust" to be the most important policy. This suggests that, given the security model is still in its early stages, the government needs to raise awareness regarding incentives for adoption and its differentiation from existing security systems. To this end, a detailed implementation roadmap that client companies can accept across various sectors is emphasized.
Professor Yoo argued, “The task in the first stage is to consider what the adoption of zero-trust security can offer to client companies.” Furthermore, they argued that “global Zero Trust providers must ensure compatibility between solutions and establish a trusted environment among companies by opening APIs,” and that “best practices for Zero Trust models suitable for the domestic environment must be disseminated through continuous demand-supplier pilot projects.”
■ Ministry of Science and ICT Announces K-Zero Trust Security Model
On this day, the Ministry of Science and ICT announced two types of 'Zero Trust Basic Models' applicable to domestic corporate network environments: cloud-based and on-premise models. It also established scenarios to verify security effectiveness.
The demonstration project for the domestic Zero Trust (K-Zero Trust) security model broke ground this July following the publication of the guidelines.
First, by applying a cloud-based Zero Trust security model, services, servers, applications, and data can be logically separated and protected. This makes it easier to apply Zero Trust security to SaaS applications in the future.
In the telecommunications sector as well, vulnerabilities that could lead to DDoS attacks on domestic networks have been improved. Problems in the wireless communication network environment can be blocked at the source by developing and applying a dedicated router equipped with a PEP (Policy Enforcement Point).
In addition, we confirmed the potential to enhance security from the connection stage during virtual private network-based remote and work-from-home environments, even in on-premises settings, and to provide a customized Zero Trust security model.
In 2024, the Ministry of Science and ICT plans to expand the scope of support for demonstration projects through a new budget of 6.2 billion won and publish Guideline 2.0 in the first half of next year.
Jeong Eun-su, Head of the Information Security Industry Division at the Ministry of Science and ICT, said, “In Guideline 2.0, we will consider ways to drive expansion from a legal and institutional perspective, while making it more specific based on demonstration cases and maintaining connectivity with existing security systems.”
He also stated, “In the future, we will analyze specific characteristics by industry domain and implement practically necessary models to expand in line with actual market demand.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















