On April 14, the ‘ICGN Korea Conference 2026’ was held at the Korea Exchange Conference Hall in Yeouido, Seoul. While the key agenda items of the day were the performance of the Value-Up Program and an international comparison of Stewardship Codes, some speakers mentioned cybersecurity as a sustainability risk that boards of directors must address. The fact that the International Corporate Governance Network (ICGN), a global institutional investor network, placed cybersecurity within the official framework of a corporate governance conference carries significant implications.
The Ripple Effects of Cybersecurity Issues
The year 2025 marked a turning point in South Korea’s cybersecurity history. According to the Cybersecurity Threat Trends Report published by the Ministry of Science and ICT and the Korea Internet & Security Agency, the number of corporate personal information breach reports in South Korea reached 2,383 cases in 2025, a 26.3% increase from 2024. Among these were the personal data breach incidents at SK Telecom and Coupang that we all remember. First, the April 2025 SK Telecom personal data breach, in which subscriber information was leaked on a massive scale through a malware attack, was recorded as a representative case in which a telecommunications giant at the forefront of ESG disclosure exposed structural vulnerabilities in its core infrastructure security. With changes to the Personal Information Protection Act’s penalty criteria, sanctions of up to approximately KRW 500 billion were mentioned, and the financial ripple effects on the company were enormous.

[Notice regarding the April 2025 SK Telecom personal data breach incident © SK Telecom]
In November of the same year, 33.7 million account names, addresses, and order information were leaked en masse from Coupang, South Korea’s largest e-commerce platform company. Coupang became aware of the personal data breach 12 days after the initial incident occurred. The gap between the initially identified scale of 4,500 affected accounts and the actual scale of 33.7 million exposed a comprehensive void in the company’s internal control and monitoring systems. S&P Global downgraded Coupang’s ESG score immediately after the incident. Penalties of up to KRW 1.2 trillion were mentioned for Coupang, and the incident once again proved that cybersecurity failures are directly linked to ESG ratings and corporate value.
The Global Response Through Regulation
While breach incidents have surged in South Korea, global regulatory authorities are forging a trend toward legislating cybersecurity as a board responsibility agenda. The U.S. Securities and Exchange Commission (SEC), through a December 2025 amendment to its cybersecurity disclosure rules, designated material incidents as mandatory reporting subjects and codified the direct oversight responsibility of boards of directors. Based on this amendment, U.S. financial companies are under pressure to establish systems for customer data breach incidents and comply by June 3, 2026.
Europe has been implementing the Digital Operational Resilience Act (DORA) since January 2025. Under this act, financial institutions within the EU must comply with requirements including reporting major security incidents and establishing digital operational resilience testing. The Organisation for Economic Co-operation and Development (OECD) also stipulated in its October 2025 report, <OECD Corporate Governance Factbook 2025>, that “boards should define the risk appetite for key risks, including sustainability and cybersecurity, and ensure management policies are in place.”

[The Digital Operational Resilience Act (DORA), which entered into force on January 16, 2023, and has been formally applied since January 17, 2025 © ESMA Official Website]
Cybersecurity: From an IT Team Task to a Board Responsibility
So why is cybersecurity now being mentioned as an ESG agenda, going beyond a board responsibility agenda? The online academic journal platform ScienceDirect estimated the global economic losses caused by cyberattacks in 2025 at approximately USD 10.5 trillion. In November 2025, Donnelley Financial Solutions, a U.S. investment research firm, stated in an official blog post that “investors are intensively scrutinizing corporate governance strengthening, cybersecurity oversight, and human capital as financially material ESG factors.”
In South Korea, ESG disclosure will become mandatory from 2028 for KOSPI-listed companies with total assets of KRW 30 trillion or more. Moreover, Korean Sustainability Disclosure Standards compatible with the International Sustainability Standards Board (ISSB) standards are set to be applied in phases, starting with KOSPI-listed companies. Within this disclosure framework, cybersecurity is no longer merely a technical task for the IT team. As the SK Telecom personal data breach demonstrated, cybersecurity incidents are directly linked to corporate ESG reputation risk, declining investor confidence, and punitive fines. In this structure, a board’s failure to directly oversee cybersecurity is tantamount to a governance gap. The fact that cybersecurity was mentioned as one of the key agenda items at the ICGN Korea Conference 2026 serves as an advance warning that global capital will no longer be lenient toward companies that have failed to fill that gap.
by Editor N
