FINANCE

'The more AI you use, the less you can afford to cut security staff and budgets'

by
Jeong Ho-won
Published : Aug. 29, 2026 - 13:47:00
    • Copy Completed!

View Korean Original

Interview with Kim Sung-woong, inaugural director of the Financial Security Institute's Financial AI Security Research Center

Financial AI security research center established in June; support center launched early

Mythos sparked a dilemma — over 200 inquiries flood in from financial firms

Network separation easing strains CISOs; calls for stronger authority and budgets

Kim warns: continuous monitoring will determine who stays ahead of AI-driven attacks

Kim Sung-woong, director of the Financial Security Institute's Financial AI Security Research Center, poses before an interview at the institute's Yeouido office in Seoul on Thursday.
Kim Sung-woong, director of the Financial Security Institute's Financial AI Security Research Center, poses before an interview at the institute's Yeouido office in Seoul on Thursday.

"Hundreds of patches are being released every day — where do we even begin?"

That is the question South Korean financial firms have been putting to the Financial Security Institute since Anthropic gave limited access to its frontier AI model Claude Mythos Preview in April. More than 200 such inquiries have poured into the institute's AI Security Support Center, which opened in late May. Unlike large institutions with their own research and technology teams, small and mid-sized firms with fewer internal resources have been particularly overwhelmed.

The sense of urgency had already been building inside the Financial Security Institute. Anticipating a tipping point at which AI would transform how work is done across every sector, the institute set up an AI Innovation Division in 2024 and drew up its own AI promotion strategy by the end of 2025. As it began rolling out that strategy in the first half of this year, the arrival of Mythos accelerated the scale and speed of attacks. Against that backdrop, the Financial AI Security Research Center was established in June. With inquiries from financial firms arriving faster than the center could handle, the support center launched on May 27 — about three weeks before the research center formally opened.

Kim Sung-woong, the center's inaugural director, sat down with The Herald Business on Thursday at the Financial Security Institute's Yeouido office in Seoul to discuss where financial security stands amid a rapidly shifting AI landscape, and what conditions are needed for a smooth transition as network separation regulations are eased.

The anxiety triggered by Mythos — "skip the patch and get hacked; apply it and it's physically impossible" — reflects how AI is shaking the foundations of security. "It's impossible to say 'this attack was definitely carried out using Mythos,'" Kim said, "but the fact that attacks have grown in scale, speed and scope is already a confirmed signal."

Financial firms have been asking questions such as: what threats come with deploying a new AI model in a service, and how should they be addressed; where should a company start building its internal governance framework to counter frontier AI security threats; and, with hundreds of patches being released every day, where should they begin applying them.

The patch problem has been particularly acute. During Anthropic's Project Glasswing, in which Mythos was involved, running AI across open-source software and existing systems to scan for vulnerabilities reportedly surfaced tens of thousands of issues almost instantly — including vulnerabilities that humans had failed to find over decades. More vulnerabilities mean an explosion in required patches. "If you don't patch, you'll get hacked — but patching at this scale is physically impossible," Kim said. "Financial firms were at a loss."

The Financial Security Institute responded by providing a prioritization framework. After conducting risk assessments and evaluating asset criticality, it developed and distributed a decision guide that sorts patches into three tiers: apply immediately, apply next, and apply later.

Many firms also asked what to automate first, given the common refrain that AI attacks must be countered with AI. Kim said tasks such as analyzing large volumes of logs, reviewing code and summarizing security events for human review are well suited to AI — but that final decisions, accountability for those decisions, and judgment calls on ambiguous data must remain with people.

Those principles were incorporated into a response guide for frontier AI security threats in the financial sector, jointly released with the Financial Services Commission in July. The guide covers six areas: strengthening executive accountability, vulnerability and patch management, asset and supply chain management, AI-based defense automation, coordinated sector-wide response and resilience, and breach-containment frameworks. It will be revised continuously to keep pace with technological change.

Kim Sung-woong, director of the Financial Security Institute's Financial AI Security Research Center, speaks during an interview at the institute's Yeouido office in Seoul on Thursday.
Kim Sung-woong, director of the Financial Security Institute's Financial AI Security Research Center, speaks during an interview at the institute's Yeouido office in Seoul on Thursday.

The era in which AI cannot be avoided has arrived, and that shift has reached financial firms without exception — even those surrounded by the heavy walls of network separation, the regulatory requirement that financial institutions keep their internal and external networks physically apart. Financial regulators began the first phase of easing those restrictions in June, selecting 10 financial firms to participate. The relaxation is not a full lift; it opens the door only to security software-as-a-service and AI used for security purposes.

The Financial Security Institute has spent roughly two months completing security assessments for all 10 firms. Kim said the institute saw both strong examples and cases where preparation fell short, and that it plans to share anonymized, generalized findings within one to two months. Specific vulnerabilities will not be disclosed, but the goal is to give firms in the second wave of easing something concrete to reference.

Four best practices stood out. The first was a phased adoption strategy — rather than applying the relaxed rules to all staff and systems at once, firms that built out the change in a limited area first and then expanded gradually while analyzing risk at each step were recognized as models. "Just because the door is open doesn't mean you should rush through all at once," Kim said. "If something goes wrong, there's no way to roll it back. Even the best solution can have side effects."

Financial firms that developed cloud-specific incident response manuals also received high marks. These were cases where firms created separate response procedures for incidents occurring in cloud and SaaS environments, distinct from their internal system protocols. Also recognized were firms that built security features not provided by default in cloud platforms and those that extended their integrated account management systems to cover SaaS and cloud accounts alongside internal systems, enabling centralized control from a single point.

The most common shortcoming across the 10 firms was insufficient self-assessment of which security SaaS solutions they actually needed. "There were cases where firms simply adopted whatever solutions others were using, without asking why they needed a particular solution, what it would improve, or what additional risks and side effects it would introduce," Kim said, adding that individual consulting appeared necessary. The Financial Security Institute conducted on-site coaching sessions to clarify each solution's role and the risks it introduced, and firms went through a process of strengthening their plans accordingly.

Easing network separation changes the very architecture of security. The existing regime was built on perimeter security — the assumption that everything inside the internal network was relatively safe. Once that boundary is opened, the perimeter disappears. Under the new model, the assumption must be that attackers may already be inside, which means systems must be segmented into fine-grained zones and all movement and data flows within them must be monitored and controlled.

"Going out has become easier, but internal controls actually have to become stricter," Kim said. "Authentication steps must increase when information passes laterally between systems, and monitoring must become more granular."

He identified small fintech companies and mid-sized secondary financial institutions — where the appetite for AI adoption is high but structural capacity for security investment is limited — as the sector he is most concerned about.

Financial firms' use of AI has already reached a considerable level. "Large financial institutions are adopting AI agents at a very rapid pace," Kim said.

The problem is that defensive frameworks are not keeping up with the pace of adoption. The typical pattern is to run a diagnostic — either internally or through an outside agency — at the time of a service launch, patch the identified gaps, and move on. Systems and attacks keep evolving, but the response stops at one point in time. The guidance the Financial Security Institute provides is a minimum baseline; stopping there leaves firms exposed.

Attack techniques, meanwhile, are evolving daily. Early jailbreak attempts — blunt instructions to "ignore all previous instructions" — are now blocked. What still works are multi-turn conversations that gradually steer an AI model in a desired direction, and poisoning the knowledge database itself. "Filtering for specific words is not enough," Kim said. "You have to read the intent behind the context of a question — to detect what someone is trying to manipulate the system into doing." He added that firms that have only just adopted AI, or that rely on simple filtering, are routinely found to have exploitable gaps when the institute conducts on-site reviews.

There are leading examples worth following. Kim pointed to IT-native firms as being more aggressive in building security measures, singling out Kakao Bank. "They don't stop at 'this should be enough,'" he said. "They assume attacks will come in through angles they haven't thought of yet, and they keep monitoring, analyzing, responding and improving." It was a warning that the gap between financial firms with continuous monitoring capabilities and those without will widen as AI-driven financial security threats intensify.

Asked what makes the difference, Kim pointed to organizational mindset. "If you move only because a regulation requires it, because a law mandates it, or because a vendor says you need to adopt something, you won't get there," he said. "You have to ask yourself what you need to do to be safe, what factors threaten the security of your systems — and maintain the vigilance to keep watching, on the assumption that there may be threats you have not identified yet."

For that reason, AI security can no longer be left to the security department alone. "Because AI systems are spreading across every business function, security becomes an enterprise-wide responsibility," Kim said. "The existing security team, the AI development and operations team, and the risk management team all have to work as one."

The sharpest message Kim delivered in the interview was directed at senior executives. The easing of network separation has sharply increased the burden on chief information security officers. "There are CISOs who did not want network separation eased," he said. "They had drawn a perimeter to reduce their worries, and now that perimeter is being removed and they are being told to identify and block threats on their own." In the past, holding the perimeter was enough and the solutions were straightforward; now, every firm has its own internal circumstances, structure and operations, and each must find its own answers.

Kim said the reality, however, is moving in the opposite direction. "CFOs and CEOs are looking first at how much they can cut — thinking that if security work can be automated with AI, one person can do what two used to do," he said. "Whether it is network separation easing or AI security, this is a moment when unpredictable new risks are emerging, which means security teams' headcount and budgets must not be cut under any circumstances — if anything, this is the time to invest more." Kim added that if AI adoption creates capacity gains, those gains should be reinvested in the kind of deep security work and risk management that only humans can do.


won@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ