New cybersecurity threats in the AI transformation (AX) era include hacking of autonomous systems, AI model theft and manipulation, IoT vulnerability attacks, deepfake-based crimes, ransomware, and supply chain attacks. Accordingly, the European Union...
New cybersecurity threats in the AI transformation (AX) era include hacking of autonomous systems, AI model theft and manipulation, IoT vulnerability attacks, deepfake-based crimes, ransomware, and supply chain attacks. Accordingly, the European Union (EU) NIS-2 Act is a comprehensive law to strengthen cybersecurity and aims to improve the level of cybersecurity across the European Union. The NIS-2 Act applies to Essential Entities and Important Entities. The NIS-2 Act requires cybersecurity risk management measures and strengthens reporting obligations. An early warning must be issued within 24 hours of becoming aware of a major incident, an initial assessment must be submitted within 72 hours of becoming aware of the incident, and a final report on incident handling and recovery efforts must be submitted within one month.
As a way to improve the Information and Communications Network Act, first, we can pursue the integration and unification of laws related to personal information protection. Second, we must establish a legal system that can flexibly respond to the development of new technologies. Third, the procedures for ensuring the speed of blocking and deleting illegal information should be simplified, and the authority and responsibility of related organizations should be clarified. Fourth, reporting obligations and procedures in the event of a breach should be clarified, and the support system for rapid response and recovery should be strengthened. Fifth, in the event of user damage due to cyberattacks, a simple and quick procedure for receiving relief must be established.
As a way to improve the Information and Communications Infrastructure Protection Act, first, the scope of designation should be expanded to include private digital services, platforms, and cloud-based services that have a significant impact on national security and the lives of citizens as “Important information and communications infrastructure,” and clear legal standards should be established. Second, we must make threat information sharing mandatory or activate it by establishing and operating an information sharing platform between major information and communication infrastructures and between the government and private companies. Third, we must establish legal grounds and guidelines for new security challenges resulting from the introduction of new technologies, such as distribution of security responsibilities in cloud computing environments, vulnerability analysis and evaluation methods for AI-based systems, and IoT device security. Fourth, since cybersecurity is a national task that the government must shoulder in order to ensure the stability of the people's lives, the government must bear the costs related to cyber risks.
As a way to improve the Information Protection Industry Act, first, the legal system should be reorganized to eliminate duplication and fill in the gaps between laws related to information protection. Second, practical incentives that can encourage companies to invest in information protection, such as expanded tax benefits, financial support, and financial assistance, should be strengthened. Third, there is a need to encourage information and communication-related companies to comply with laws and regulations regarding information protection and to strengthen the effectiveness of the disclosure system.