AI-Era Security Is a Speed Race: Financial Institutions Must Respond Faster
IT DAILY ·
✦ AI Summary
Kim Ki-woong, team leader of the Security Strategy Response Team at KB Kookmin Bank's Information Security Department (P), presented "AI Attack Simulation and Response Strategies for the Financial Sector" at the "2026 Information Security Solution Conference." He said that in responding to AI attacks in the financial sector, organizations should avoid using vulnerability risk scores as the sole criterion and should set priorities based on actual attack likelihood. He also said AI is shortening the time from vulnerability disclosure to attack, and that continuous verification and repeated operations of inspection, verification, detection, policy changes, and retesting are needed.
At the "2026 Information Security Solution Conference" held by this paper on the 9th at the L Tower in Yangjae, Seoul, Kim Ki-woong, team leader of the Security Strategy Response Team at KB Kookmin Bank's Information Security Department (P), took the stage. Kim's presentation was titled "AI Attack Simulation and Response Strategies for the Financial Sector."
At the conference that day, Kim argued that financial institutions need to change their security response systems in the AI era. On how the financial sector should respond to AI attacks, he said the industry should avoid relying solely on vulnerability risk scores, as it has done before.
He went on to explain a security principle: response priorities should be set based on actual attack likelihood, and defense systems should be continuously tested. The on-site photo that day was taken by reporter Yang Seung-gap.
Kim pointed to speed as the key change brought by AI attacks. He said that in the past, time was needed after a vulnerability was disclosed to analyze the PoC and produce attack code, but now AI agents are automating that process. As a result of this automation, the time it takes for a real attack to arrive has also been shortened, he said.
Kim said AI has changed not the attack techniques themselves, but attack speed and productivity. He said this shift requires a reexamination of existing security operations.
In line with that view, KB Kookmin Bank verified the extent to which AI can conduct attack simulations and vulnerability checks in a financial-sector environment. The verification involved a step-by-step process of AI-based automated web vulnerability checks and attack simulations.
The verification results showed that AI-based automated web vulnerability checks reduced the time needed for URL, API, and parameter discovery. Time savings were also seen in repetitive tasks such as identifying vulnerability candidates. However, limitations became apparent in judging financial business logic, handling complex authentication procedures, and assessing the impact on actual transactions.
Kim said human judgment is important for distinguishing false positives from actual vulnerabilities and determining business impact. As areas that still require such judgment remain, he pointed to the problem of the speed gap between attackers and defenders.
Attackers can use AI to shorten the time from vulnerability disclosure to actual exploitation. Financial firms, by contrast, need to analyze vulnerable assets and business impact, and must go through consultation procedures with relevant departments, change-approval procedures, patching procedures, and retesting procedures.
Kim explained that while attackers may operate in units of hours or days, defenders need more time because they must consider business impact and stability. He also noted that the core issue is not the number of vulnerabilities, but the gap between attackers' speed and defenders' available response time.
As a way to narrow that speed gap, he stressed that organizations should avoid treating all vulnerabilities the same and should instead select and address first those with a high likelihood of real-world exploitation. Criteria for prioritization included actual exploitability, the availability of public attack code, whether the asset is exposed to the internet, and its relationship to critical assets.
Kim said that when prioritizing vulnerability response, actual exploitability by attackers should be valued more than the risk score itself. Regarding vulnerability assessment criteria, he said simple scoring should be avoided and that priority setting needs to be linked to actual remediation.
He also said a shift in security inspection methods is needed. Rather than a one-time process carried out at a specific point in time, organizations should move to a continuous verification system. Kim noted that the old approach ended after inspection and remediation, and said that in the AI era, security operations need to repeat without end. He explained that the repetitive process should begin with inspection and continue through verification, detection, policy changes, and retesting.
Finally, Kim said the key benchmark is not the scale of AI adoption. He said the capability organizations need is a verification and response operating system that moves faster than the speed changes in attacks driven by AI.
Source: IT DAILY · Yang Seung-gap
Original: https://www.itdaily.kr/news/articleView.html?idxno=241503
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.