CFE Home
KOR

[Op-Ed] Voice Phishing Arrest Rate at 1%; Breakthrough Requires Corporate Autonomy in Security

Writer
Na-young Kim


The government is focused not on apprehending hackers but on strengthening its regulatory power over companies, holding back the adoption of new technologies


Rather than government-led ex ante regulation, we need to move toward the market principle of “autonomy and responsibility,” led by financial firms themselves


The average time required for regulatory review and approval is 6 months to 1 year, while voice phishing methods evolve every 1 to 2 months


In the face of voice phishing crimes that inflict losses worth hundreds of billions of won every year, the government’s countermeasures remain ineffective. The reason is that the government has treated financial institutions not as key players in security innovation but merely as objects of oversight. What is needed now is a sweeping shift in governance: granting financial firms autonomy over security to encourage market competition, while the state focuses on its proper role of maintaining information security and public order.


Ex ante regulation refers to a “positive regulation” system in which the government, in the name of accident prevention, specifies in advance and in detail how companies must conduct security—for example, by mandating network separation or requiring the installation of specific security solutions. The biggest problem with this kind of regulation is that financial institutions end up pouring their resources not into a technological war against hackers, but into the administrative task of “passing the government checklist.”


The fundamental reason criminals are not being apprehended effectively is that the government has concentrated its administrative capacity on exercising regulatory authority over private companies, while neglecting its true responsibility of strengthening information security and investigative capabilities. Financial companies, too, are expending energy in the wrong places and are therefore unable to focus on reinforcing their actual security systems.


Ex ante regulation imposed on the financial sector has paradoxically delayed the introduction of new security technologies. According to a survey by the Financial Security Institute, when introducing new technologies such as cloud services or AI, the time required for regulatory review and approval of exceptions to network separation averages from 6 months to more than 1 year. Yet voice phishing methods evolve on average every 1 to 2 months, maintaining a technological edge. In effect, the government’s ex ante regulation is hamstringing technological adoption.


Moreover, despite the administrative costs companies incur to comply with ex ante regulation, the arrest rate for voice phishing criminals remains markedly low. According to academic papers by domestic cybersecurity experts, companies face the problem of allocating 40 to 50 percent of their budgets first to infrastructure construction and consulting for regulatory compliance rather than to investment in practical defensive technologies.


Meanwhile, the state’s own share of responsibility—“apprehending the criminal masterminds”—remains stuck in the 1 percent range. As of 2023, about 25,000 people were apprehended for voice phishing, but only around 1 to 2 percent of them were “masterminds (principal offenders).” This clearly represents a dereliction of government duty and a shifting of costs onto the private sector.


What we need now is not government-led ex ante regulation but the market principle of “autonomy and responsibility,” with financial firms themselves taking the lead.


Voluntary disclosure is, in itself, a means for financial firms to secure competitiveness. In the end, within a market economy system, a company’s standing is determined by customer choice. Under these circumstances, customers will inevitably choose “the bank that protects my money best,” and security will become a core quality that determines a bank’s brand value.


The government’s proper role is information security and public order. For example, it should make the methods of overseas fraud rings and the latest crime data into public goods and supply them sufficiently to financial companies. On that basis, banks would then be able to autonomously build the optimal defense systems suited to their own customers.


This would enable companies to develop more practical voice phishing response systems through proactive security frameworks. For example, without ex ante regulation mandating network separation, banks could immediately adopt the latest cloud technologies or external AI security solutions. If ex ante regulation on financial firms is removed and autonomy is granted, companies can build secure systems that outpace the speed at which criminals evolve.


Ultimately, the solution is clear. The government should create an environment in which companies can freely compete to provide “reassuring security,” while itself becoming a strong guardian that protects cyberspace. When autonomy and responsibility function in the market, only then can we achieve both digital innovation and the safety of citizens.


Nayoung Kim, Intern Researcher, Center for Free Enterprise (CFE)


Original title: [칼럼] 보이스 피싱 검거율 1%, 기업이 보안 자율권 가져야 타개 가능

Author: Na-young Kim

Date: 2026-03-17

Source: https://www.cfe.org/bbs/bbsDetail.php?cid=free_opinion&idx=28703