This study classifies security incidents into physical and information security incidents, and compares how social responses and major issues differ in news discourse by incident type. It also aims to propose response strategies tailored to each type....
This study classifies security incidents into physical and information security incidents, and compares how social responses and major issues differ in news discourse by incident type. It also aims to propose response strategies tailored to each type. The Kakao data center fire was selected as a representative physical security incident, and the SKT USIM·eSIM-related incident as a representative information security incident. For each case, news data were collected and analyzed for the six months following the incident using the keywords ‘Kakao’ and ‘SKT’. In addition, news data collected using the keyword ‘security’ during the six months following each incident in 2022 and 2025 were analyzed to compare differences in broader security discourse. The results show that physical security incidents mainly generated responses centered on service disruption, recovery, and compensation, reflecting concerns about availability. In contrast, information security incidents expanded into issues such as hacking, information leakage, personal information protection, user rights, and corporate accountability. Topic modeling based on the keyword ‘security’ further showed that information security incidents had greater centrality and diffusion in general security discourse than physical security incidents. This suggests that information security incidents more strongly evoke concerns about potential harm to users and rights-related issues, thereby generating more sensitive social responses. The findings confirm that physical and information security incidents are problematized differently in news discourse and that corporate response strategies should differ accordingly. Physical security incidents require strategies focused on service continuity and operational resilience, whereas information security incidents require strategies centered on user protection, redress for user rights, and corporate accountability. Therefore, responses to security incidents should be differentiated according to incident type rather than follow a single uniform approach.