AI-Accelerated Attacks, Slower Patching: Time for a New K-Security Playbook
IT DAILY ·
✦ AI Summary
It was pointed out that while the spread of AI has accelerated attack speeds, the response speed at the cybersecurity front line has not been able to keep up.
Even after a public vulnerability is identified, patch deployment and service availability verification take a long time, and the KEV patch deployment period was 43 days, up from 32 days the previous year.
At the forum, participants called for a response framework that goes beyond detection, common security standards for introducing AI into work, attack surface management, and securing cyber resilience.
It was pointed out that while the rise of AI has accelerated attack speeds, the pace of response in the cybersecurity field has not kept up. This is because responders must identify the systems affected during the response process and verify whether patch deployment could cause outages. In addition, there are cases in which vulnerabilities were discovered but could not be addressed because no staff were available to make code changes, and the difficulty of follow-up response was also cited as a problem on par with vulnerability detection.
That sense of urgency was also shared at a breakfast forum held by Computerworld/IT DAILY on the 9th at EL Tower in Yangjae-dong, Seoul. The event was organized as a side event for the '2026 Information Security Solutions Conference,' under the theme, 'In the AI agent era, what is the next growth strategy for K-Security?' Fourteen people from public and financial demand organizations, security companies and other related sectors attended.
Security experts from the public and financial sectors who attended the forum emphasized the importance of a response framework. They said the scope of response must go beyond detection to include patch deployment and post-incident recovery. They also expressed agreement on future tasks such as common security standards for introducing AI into work, attack surface management and securing cyber resilience.
A breakfast forum held as a side event of the 2026 Information Security Solutions Conference took place on the 9th at EL Tower in Yangjae-dong, Seoul.
The on-site photos were provided by reporter Kim Ho-jun.
Officials from the information security policy sector attended the breakfast forum.
Kim Wan-jip, chair of the National Information Security Policy Council, attended.
Son Kyung-ja, chair of the Government Informatization Council and a chief officer in charge of informatization at the Ministry of Agriculture, Food and Rural Affairs, attended.
Bae Jong-hyeon, head of the Information Security Division of Seoul Metropolitan Government, attended.
Officials from the information security industry also attended the breakfast forum.
Kim Jin-su, chair of the Korea Information Security Industry Association (KISIA) and CEO of Konicglory, attended.
Park Gi-dam, vice president of Winsoftnet, attended.
Bae Hwan-guk, CEO of SoftCamp, attended.
Choi Young-cheol, CEO of SGA Solutions and chair of the Korea Digital Document Platform Association, attended.
Jung Seung-woo, head of financial sales at AhnLab, attended.
Academics also attended the breakfast forum.
Kim Chang-hoon, a professor at Daegu University, attended.
Officials from the financial sector also took part in the breakfast forum.
Oh Im-gwon, head of the IT Division at Daol Investment & Securities, attended.
Won Chang-sun, executive vice president at ShinYoung Securities and CIO, attended.
Jo Hyeong-jin, vice president and CISO at NH NongHyup Non-Life Insurance, attended.
Choi Jin-su, executive vice president and CIO at Hana Non-Life Insurance, attended.
Officials from the public sector and committees also attended.
Lee Won-tae, chair of the Security Special Committee of the National AI Strategy Committee, attended.
In this way, officials from the policy, industry, academic, financial and public sectors attended the breakfast forum.
At the venue, the gap between attack speed and defense speed was raised as a practical concern.
The key issue cited on site was that even after a disclosed vulnerability is identified, a long time passes before a patch is actually deployed.
Applying patches for disclosed vulnerabilities took at least several days.
That trend was also confirmed in the figures presented.
Verizon's presentation material, the '2026 Data Breach Investigations Report (DBIR),' was cited.
The material presented the patch deployment period for known exploited vulnerabilities (KEV) in organizations.
The patch deployment period for known exploited vulnerabilities (KEV) in organizations was 43 days.
The 43-day figure was up by more than 10 days from 32 days the previous year.
The DBIR figures showed that the KEV patching period increased from the previous year.
The issues raised at the venue and the DBIR figures pointed in the same direction.
In other words, delays were confirmed even after disclosed vulnerabilities were identified and before actual response could begin.
That delay was felt as a gap between attack speed and defense speed.
It was linked to the problem of applying patches for disclosed vulnerabilities, which takes at least several days.
The 43-day KEV patch deployment period was also presented.
Compared with 32 days the previous year, the upward trend continued.
The forum that day was a place to share this sense of urgency.
Participants from the policy and industry sectors gathered in one place.
Participants from academia and the financial sector also joined.
Officials from the public sector were also included in the attendee list.
The participants formed a venue for discussion on pressing information security issues.
Among them, attention focused on the time issue in responding to disclosed vulnerabilities.
It was confirmed once again that the gap between attack speed and defense speed is felt on site.
The DBIR figure for KEV patch deployment period also supported that trend.
The breakfast forum was held on the 9th at EL Tower in Yangjae-dong, Seoul.
While the time from vulnerability disclosure to attack is becoming extremely short, defense-side patching and verification are said to take a long time. According to Fortinet's '2026 Cybersecurity Skills Gap Report,' the average TTE (Time to Exploit) is 24 to 48 hours, roughly half the about 5.4 days in 2023. In some cases, attackers successfully exploited vulnerabilities in less than half a day, and the time available for attacker exploitation was as short as half a day. By contrast, patching high-risk vulnerabilities took more than a month.
Jo Hyeong-jin, vice president and chief information security officer (CISO) at NH NongHyup Non-Life Insurance, said that after a vulnerability is disclosed, the scope of response available on site is limited. He explained that at the start of response, the assets running the relevant software version must be identified, and before applying a patch, it is necessary to verify the impact on service availability. He added that availability verification also takes time, creating constraints on immediate response.
Statistically, applying a single patch takes about 43 days, but AI attacks are completed in just 10 to 20 minutes, creating a time asymmetry between offense and defense. Concerns were also raised that this asymmetry makes it nearly impossible to sustain the game.
The public sector faces a similar situation. Bae Jong-hyeon, head of the Information Security Division of Seoul Metropolitan Government, said the city manages more than 400 to 500 public-facing websites and has thousands of servers. In such an environment, he explained, relying only on a handful of experts to inspect vulnerabilities and recommend patches has limits in responding to the expanding scale of attacks.
He also explained that there are cases in which response is impossible even after a vulnerability is recognized. For long-running systems, the vendor associated with the solution may no longer exist, and response may be disrupted by the resignation or reassignment of internal staff. Even after a patch is developed, many tasks remain before it can actually be applied to endpoints, so he said it is necessary to consider a system in which people visit the site in person to take action when needed.
As AI becomes essential in work environments, the scope of its use is also expanding to document writing, image generation, and direct service development and sharing by frontline staff. Such changes are especially visible in the public sector.
Earlier this year, an AI-based document and legal text processing tool developed by a public official with a background in business administration drew attention. Son Kyung-ja, chair of the Public Sector Procurement Council, said the spread of vibe coding has brought about an era in which frontline staff directly create programs.
Son Kyung-ja also explained that system operations may shift from labor-intensive structures to partial task automation using AI. However, concerns about data leakage due to AI use have been raised, and there are warnings that if public officials use commercial AI linked to the outside world, internal materials could be leaked.
Accordingly, there is also an option to build and use an on-premise small language model (sLLM). However, on-premise sLLMs lag behind external models in performance, and due to those performance issues, users are turning away from them. As a result, public institutions constrained by budgets are struggling between work efficiency and security.
As more public officials develop AI services and more cases emerge of public officials linking external functions through the Model Context Protocol (MCP), expansion of use and security concerns are being raised together. Lee Won-tae, chair of the Security Special Committee of the National AI Strategy Committee, said that while actively using AI is in itself welcome, security problems are to be expected.
Accordingly, Lee Won-tae said he is pushing to establish common security standards to apply to public officials' AI tool coding and is discussing the matter with the Ministry of the Interior and Safety. He said the process is at a stage of reviewing technical and institutional measures aimed at preemptively blocking risks that arise when internal materials are entered into prompts.
This issue is no exception in the financial sector. Oh Im-gwon, head of the IT Division at Daol Investment & Securities, said frontline staff have strong demand for direct AI development, but the IT department cannot fully verify the risks of AI-generated source code. He said that in such a situation, demand and security concerns continue to clash, and that it is still difficult to find a solution that offers a clear answer to this problem.
Choi Jin-su, executive vice president at Hana Non-Life Insurance, said the biggest concern for financial companies is internal information leakage. He explained that while the performance of external large language models (LLMs) is excellent, they are difficult to allow because of the possibility of data leakage.
Choi requested that the government provide clear national guidelines for this reason. He emphasized the need to establish standards while explaining that the financial sector views the risk of information leakage in the use of external LLMs as significant.
The security industry then advised that new response measures suited to AI-driven changes are needed. The point was that response systems must be reorganized in line with the spread of AI. Bae Hwan-guk, CEO of SoftCamp, compared the spread of AI attacks to the COVID-19 pandemic and advised minimizing the surfaces that come into contact with the outside world in cyberspace as well.
In the photo of the forum remarks, Lee Won-tae, chair of the Security Special Committee of the National AI Strategy Committee, is seated third from the left. From left to right in the photo are Kim Jin-su, chair of KISIA; Son Kyung-ja, chair of the Government Informatization Council; Lee Won-tae, chair of the committee; and Jo Hyeong-jin, vice president of NH NongHyup Non-Life Insurance.
Bae stressed that in the past, intermittent attacks targeted only certain organizations, but in the future everyone could become a target. He said improving the speed of patch deployment alone would not be sufficient. He then compared the situation to the pandemic period, when points of contact were minimized, and emphasized the need to reduce the attack surface in IT environments as well.
Bae also stressed the importance of managing 'Cyber Hygiene' to protect devices and data. The point was that in a situation where cyberattack targets are becoming broader, reducing the attack surface and managing 'Cyber Hygiene' are more important than simply strengthening patches.
Choi Young-cheol, CEO of SGA Solutions, then proposed reorganizing compliance for the AI era and said standards must be established to respond to AI security threats. He pointed out that many controls in private sector, public sector and defense compliance are based on existing IT environments, and argued that response measures suited to AI threats must be newly established. He also proposed building a national common reference framework for companies and institutions, explaining a plan in which government ministries and industry would set detailed standards and design security systems based on that framework. Choi said that if common standards are established under government leadership, overlap and confusion among ministries can be reduced.
Kim Wan-jip, chair of the National Information Security Policy Council, emphasized the need to secure a cooperative framework and workforce for the on-site adoption of standards and technologies, saying there is a need to move away from fragmented responses by organization. He said cooperation among security companies, the central government, local governments, and the private, public and academic sectors is necessary, and argued that a central hub should be established to oversee AI adoption within institutions from a security perspective.
Kim Wan-jip said frontline staff are already overloaded with existing work, and pointed out that it is difficult for them to simultaneously handle AI learning, business application and endpoint security. Regarding these limitations, he said a control tower is needed to manage AI development and adoption across departments, and added that such a control tower should help improve practical capabilities at frontline institutions.
Experts said AI attacks transcend the boundaries of industries and institutions, while defense systems remain separated by sector and ministry. They also said that establishing common standards alone is not enough, and that the standards must be translated into on-site measures such as zero trust, Cyber Hygiene and stronger resilience. They predicted that the speed at which the gap between standards and implementation is closed will determine the success or failure of the security transition in the AI era.
Lee said the current AI security measures are somewhat fragmented and pointed out the need to organize technical control items. He then proposed establishing a national cyber resilience framework that covers the entire lifecycle, from AI development to post-incident recovery.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241803
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.