This page was machine-translated and may differ from the original. View original
When Industrial Security Requires 'Skilled Experts' and 'Management Attention'
The current state of domestic security, which focuses solely on the introduction of equipment and technology, must be rectified.
Need to foster specialized personnel through the development of members' security awareness, knowledge, and behaviors
In April 2011, Hyundai Capital had customer information amounting to a total of 1.75 million people hacked. Then, in July of the same year, 35 million records were leaked from Nate, and in January 2014, a combined total of 100 million personal records from the three companies—KB Card, Lotte Card, and NH Card—were leaked.
While there are various reasons for hacking, it has been revealed to be due to negligence in management and the actions of employees. Information leaks caused by internal employees occur frequently. Financial companies focused on preventing hacking of their computer networks, neglecting to inspect and control internal employees or security managers.
Professor Jang Hang-bae of Chung-Ang University explained, “Through these cases, we can learn the lessons regarding the importance of people in security and the paradigm shift toward a people-centered approach. However, we are still at risk from diverse and multi-dimensional threats because we have prepared only unified countermeasures without considering the specific circumstances.”
.JPG)
Hacking incidents and security issues at companies and government agencies have been ongoing for a long time. There is no institution or company that has not installed security equipment to protect critical information. Along with industrial development, cyber attacks are also becoming more complex and sophisticated. Accordingly, Limelight Networks, Seagate, and domestic companies are preparing to technically respond to various threats by combining artificial intelligence and security.
According to a paper by the Korea Information Security Society, development in the security field has focused solely on technology, and research in the social sciences has also been conducted with a focus only on law. The government proposed "i-Korea," a people-centered plan for responding to the Fourth Industrial Revolution, and focused on addressing these shortcomings. It is time to respond to internal and external security threats while forming a balanced, people-centered security ecosystem that combines security engineering and security management, and to formulate and execute strategies.
The fact that security to date has been skewed toward technology and equipment rather than people is also evident in a survey conducted by the global security conference Black Hat among its participants. More than 30% of respondents cited a "lack of skilled professionals" and "executive indifference to security" as the main factors causing cybersecurity strategies to fail in the Asian region.
To address this, it is necessary to assign responsibilities and authority based on trust in employees rather than coercive and prevention-oriented controls, and to enhance security awareness and capabilities through training. At the same time, the importance of an approach that rapidly detects and responds to anomalies through continuous monitoring must be recognized.

To improve members' security awareness, tangible efforts to raise awareness of the importance of industrial security are necessary. Additionally, specialized training based on security knowledge is required. This includes environmental analysis capabilities, legal reasoning skills, technical knowledge and proficiency in security, understanding and communication skills regarding people, and practical skills. Finally, members' security behaviors must be monitored. Continuous monitoring through practical training is required regarding the knowledge acquired.
As mentioned above, the areas requiring security experts will expand due to the increasing threats arising from the expansion of converged environments, such as the difficulties in introducing and applying traditional security systems, the difficulty in verifying incidents like hacking when they occur, and the diverse penetration paths caused by complex network structures.
Furthermore, the organizational culture's perspective on security must change. First and foremost, security must be viewed as an investment, not a cost. In most SMEs, as well as in large corporations, the Chief Information Security Officer (CIO) often serves as the Chief Information Officer, leading to conflicts that hinder swift responses. Yoon Jong-rok, President of the Korea Information & Communication Technology Industry Promotion Agency (KIPA), stated, "Many companies must move away from viewing security as a cost and build a nation where security becomes a livelihood." Assets must be protected by integrating business technology and mindset into security.
Professor Jang Hang-bae of the Department of Industrial Security at Chung-Ang University stated, “Generally, companies are proactive in adopting expensive security solutions but are stingy when it comes to investing in security services and treating engineers well.” He continued, “Ultimately, it is people, not solutions, that prevent security attacks,” emphasizing, “It is necessary to raise security standards and cultivate specialized personnel through continuous security education as much as introducing security equipment, and it is time for management’s mindset to change as well.”
Need to foster specialized personnel through the development of members' security awareness, knowledge, and behaviors
In April 2011, Hyundai Capital had customer information amounting to a total of 1.75 million people hacked. Then, in July of the same year, 35 million records were leaked from Nate, and in January 2014, a combined total of 100 million personal records from the three companies—KB Card, Lotte Card, and NH Card—were leaked.
While there are various reasons for hacking, it has been revealed to be due to negligence in management and the actions of employees. Information leaks caused by internal employees occur frequently. Financial companies focused on preventing hacking of their computer networks, neglecting to inspect and control internal employees or security managers.
Professor Jang Hang-bae of Chung-Ang University explained, “Through these cases, we can learn the lessons regarding the importance of people in security and the paradigm shift toward a people-centered approach. However, we are still at risk from diverse and multi-dimensional threats because we have prepared only unified countermeasures without considering the specific circumstances.”
Hacking incidents and security issues at companies and government agencies have been ongoing for a long time. There is no institution or company that has not installed security equipment to protect critical information. Along with industrial development, cyber attacks are also becoming more complex and sophisticated. Accordingly, Limelight Networks, Seagate, and domestic companies are preparing to technically respond to various threats by combining artificial intelligence and security.
According to a paper by the Korea Information Security Society, development in the security field has focused solely on technology, and research in the social sciences has also been conducted with a focus only on law. The government proposed "i-Korea," a people-centered plan for responding to the Fourth Industrial Revolution, and focused on addressing these shortcomings. It is time to respond to internal and external security threats while forming a balanced, people-centered security ecosystem that combines security engineering and security management, and to formulate and execute strategies.
The fact that security to date has been skewed toward technology and equipment rather than people is also evident in a survey conducted by the global security conference Black Hat among its participants. More than 30% of respondents cited a "lack of skilled professionals" and "executive indifference to security" as the main factors causing cybersecurity strategies to fail in the Asian region.
To address this, it is necessary to assign responsibilities and authority based on trust in employees rather than coercive and prevention-oriented controls, and to enhance security awareness and capabilities through training. At the same time, the importance of an approach that rapidly detects and responds to anomalies through continuous monitoring must be recognized.
To improve members' security awareness, tangible efforts to raise awareness of the importance of industrial security are necessary. Additionally, specialized training based on security knowledge is required. This includes environmental analysis capabilities, legal reasoning skills, technical knowledge and proficiency in security, understanding and communication skills regarding people, and practical skills. Finally, members' security behaviors must be monitored. Continuous monitoring through practical training is required regarding the knowledge acquired.
As mentioned above, the areas requiring security experts will expand due to the increasing threats arising from the expansion of converged environments, such as the difficulties in introducing and applying traditional security systems, the difficulty in verifying incidents like hacking when they occur, and the diverse penetration paths caused by complex network structures.
Furthermore, the organizational culture's perspective on security must change. First and foremost, security must be viewed as an investment, not a cost. In most SMEs, as well as in large corporations, the Chief Information Security Officer (CIO) often serves as the Chief Information Officer, leading to conflicts that hinder swift responses. Yoon Jong-rok, President of the Korea Information & Communication Technology Industry Promotion Agency (KIPA), stated, "Many companies must move away from viewing security as a cost and build a nation where security becomes a livelihood." Assets must be protected by integrating business technology and mindset into security.
Professor Jang Hang-bae of the Department of Industrial Security at Chung-Ang University stated, “Generally, companies are proactive in adopting expensive security solutions but are stingy when it comes to investing in security services and treating engineers well.” He continued, “Ultimately, it is people, not solutions, that prevent security attacks,” emphasizing, “It is necessary to raise security standards and cultivate specialized personnel through continuous security education as much as introducing security equipment, and it is time for management’s mindset to change as well.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













