FSS holds virtual meeting with 491 electronic finance firms
Shares first-half inspection results and second-half priorities
Voluntary remediation supported; sanctions relief considered for firm-wide efforts
The Financial Supervisory Service has moved to strengthen the financial sector's ability to respond to electronic finance incidents and improve IT resilience amid the growing use of generative AI and increasingly sophisticated cyberattacks.
The FSS said Sunday it held a virtual "Financial IT Risk Response Meeting" with 491 financial companies and other entities engaged in electronic finance operations. Participants included firms from the banking, insurance, financial investment, savings banking, credit finance, credit information, mutual finance and electronic finance sectors.
As computer system failures and security breaches continue to occur, the expanding use of generative AI and increasingly sophisticated cyberattacks have heightened the need for financial companies to strengthen their incident response capabilities and IT internal controls. At a financial supervision briefing on the digital and IT sector held in March, the FSS said a significant share of financial sector incidents stemmed not from advanced hacking techniques but from failures to observe basic security principles and internal controls.
At Sunday's meeting, the FSS shared the results of its first-half on-site inspections and ongoing monitoring, as well as its priorities for second-half inspections, and discussed measures to improve the safety of computer systems and service continuity. The first-half review of IT basic control implementation found numerous cases where fundamental IT controls — including program change management and performance management — were inadequate.
In response, the FSS outlined five key areas of concern: patching vulnerabilities in computer equipment and strengthening access control management; clarifying the scope and criteria for security vulnerability analysis and assessment; reinforcing power supply safety through measures such as replacing aging storage batteries; blocking the misuse of wireless networks through inspections for unauthorized wireless connections; and ensuring compliance with reporting procedures when electronic finance incidents occur.
The FSS particularly urged vigilance against a new type of security threat in which miniature wireless spy chips are covertly embedded in computer equipment to penetrate internal systems or steal data via radio frequency communications. The FSS said financial companies should verify whether wireless backdoors have been installed when introducing or bringing in computer equipment, and should strengthen monitoring for anomalies in servers and terminals.
In the second half of the year, the FSS plans to focus its inspections on IT basic control implementation and will also examine the operational status of power facilities to prevent fires at data centers. The FSS said many recent electronic finance incidents were caused by inadequate impact analysis before program changes, equipment failures and communication line disruptions, and carelessness during system changes such as firewall modifications.
The FSS also plans to inspect compliance with information security obligations for cloud-based office management and business support software, or SaaS, which was conditionally permitted following an amendment to the detailed rules of the Electronic Financial Supervision Regulation on April 20.
The FSS said that as regulations are eased amid the shift toward AI, it becomes even more important for financial companies to build IT internal control systems that proactively identify and address vulnerabilities. It said companies should establish a three-tier framework in which the IT organization develops and implements internal control measures, an in-house auditor within the IT organization reviews their adequacy, and an IT auditor from the audit organization examines high-risk areas. With numerous voluntary self-assessments by financial companies scheduled for the second half of the year, the FSS urged firms to establish a firm-wide voluntary remediation system under the responsibility of the CEO and senior management.
psj@heraldcorp.com