Large U.S. banks employ up to 47 times more dedicated cybersecurity staff than South Korea's four biggest lenders, with security budgets up to 37 times larger. As hacking threats powered by artificial intelligence intensify, calls are growing for Korean financial firms to move beyond a security framework centered on network separation and adopt differentiated responses based on their investment capacity and scale.
Citibank and Bank of America each had about 3,400 dedicated cybersecurity staff as of the end of last year, according to filings with the U.S. Securities and Exchange Commission released on the 12th.
By contrast, information security staffing at Korea's four largest banks stood at 96.7 at KB Kookmin Bank, 97.8 at Shinhan Bank, 71.9 at Hana Bank and 101 at Woori Bank — between one-34th and one-47th of the U.S. levels. Even accounting for the 10- to 12-fold gap in asset size between banks in the two countries, the staffing disparity is seen as substantial.
The gap in security budgets is equally stark. Major U.S. banks including JPMorgan Chase and Bank of America spend an estimated $700 million to $1 billion a year on cybersecurity, or roughly 940 billion to 1.34 trillion won. Korea's four largest banks invested far less in information security last year: 43.3 billion won at KB Kookmin Bank, 37.2 billion won at Hana Bank, 36.9 billion won at Shinhan Bank and 36.4 billion won at Woori Bank — a gap of up to 37 times.
Security staff as a share of total employees also diverges sharply. The figure stands at 1.5% to 1.6% at Citi and Bank of America, compared with an average of 0.69% at the four Korean banks. Counting only in-house staff and excluding outsourced personnel, the share falls to 0.3% to 0.4%. Information security accounted for 9.6% of information technology investment at 31 Korean financial and insurance companies in 2024, according to the Korea Internet & Security Agency, below the 12% average found in a survey of financial firms in the U.S. and Canada that year.

Behind the gap lie divergent regulatory environments. Rather than relying on network separation rules of the kind used in Korea, major U.S. banks have developed security frameworks built on firewalls and continuous authentication to counter external attacks. The best-known example is "zero trust," which verifies every user without exception, including those on internal networks.
Korean financial firms, by contrast, have reduced security risk through network separation rules that sever links between external and internal networks. But as AI adoption widens, critics say such rules constrain the use of new technology and the upgrading of security systems. One industry official said the latest incident occurred because financial firms had relied on network separation alone and been passive about investing in information security.
The difficulty is that investment capacity varies widely across firms. Korean banks posted net profit of 13.8 trillion won in the first half of this year, while life insurers earned 3.9254 trillion won and property and casualty insurers 5.0884 trillion won. Dedicated card companies also booked profit of 1.2934 trillion won. Credit unions, by contrast, recorded a net loss of 188.9 billion won and community credit cooperatives a loss of 676.8 billion won. Security staff and systems need to expand in step with advances in AI technology, but the scale of investment each sector can absorb differs.
As a result, industry officials are discussing a three-tier approach: large financial firms would increase their own security spending in exchange for further easing of network separation rules, mid-sized firms would build joint response systems, and small firms would tighten controls on external connections.
Large banks should focus first on strengthening their own capabilities, analysts say. KB Kookmin Bank has budgeted about 86.075 billion won for information security this year, and even raising that above 100 billion won next year would leave a considerable gap with large U.S. banks. Woori Bank is also considering increasing its security system budget by more than 20% from this year and expanding specialist staff by more than 10%.
For mid-sized firms with limited capacity for in-house investment, one option is to conduct security monitoring and vulnerability assessments jointly through industry associations or federations. Because individual companies find it hard to maintain both staff and systems on their own, shared services would lower the cost burden.
Setting up a joint response system, however, requires decisions on cost-sharing and the scope of support. The Financial Security Institute, a nonprofit body, would struggle to provide free support to non-member firms, and financial companies outside federation computer networks would also need to be covered. One proposal under discussion would have the government support the build-out of a joint security framework, with participating firms sharing costs on a sliding scale based on size. Rep. Park Min-kyu of the Democratic Party of Korea made a similar point on the 8th, when he urged the Financial Services Commission at a parliamentary audit of government agencies to support a joint AI security framework for small and mid-sized financial firms.
For small firms that lack security staff and systems, the priority is strict control of external connections, analysts say. Easing network separation without adequate defensive capacity could instead heighten security risk. One financial industry official said small and mid-sized firms should handle security themselves where possible but need joint support because they lack the staff and other resources.
