Seoul Sets Five-Year Cybersecurity Plan
- •Seoul plans a 2027–2031 cybersecurity overhaul centered on N2SF, Zero Trust and AI-based detection.
- •AI will scan websites, equipment and devices for vulnerabilities, while the city strengthens patch management and private-cloud monitoring.
- •Seoul plans broader working-level policy talks, with committees under review for its current 12-member steering group.
Seoul has set a cybersecurity plan for 2027–2031 covering the National Network Security Framework (N2SF), Zero Trust, AI-based detection and response, a shift to quantum-resistant cryptography, and stronger security governance. Baek Jong-hyun, head of Seoul’s Information Security Division, announced the policy direction for the next five years on October 7 at the Korea Cybersecurity Conference 2026 in Seoul’s COEX. The city created a dedicated information security department in July 2024 and enacted a cybersecurity ordinance in September 2025. It plans to prepare enforcement rules and related guidelines by the end of 2026.
Seoul will move from a system centered on network separation to one aligned with N2SF, which classifies information and systems by importance and risk, then applies security measures at different levels. Using National Intelligence Service guidelines, the city will assess the importance of information assets and cloud adoption plans at city hall and affiliated organizations to decide where the framework applies. It will test approaches suited to Seoul’s environment. Baek said Seoul plans to join a pilot project in 2027, develop the framework, secure funding and then expand it across the city. Seoul will also draw on public-sector N2SF pilot and demonstration cases from the Korea Internet & Security Agency (KISA). Zero Trust, already applied to remote work, will be extended to other work settings. The principle requires ongoing checks of users, devices and access activity rather than trusting access simply because it comes from an internal network.
Seoul will use the U.S. National Institute of Standards and Technology (NIST) Cybersecurity Framework as a reference for a city framework defining asset identification, protection, detection, response and recovery, as well as roles for city hall, district offices and affiliated organizations. Baek said security controls require an accurate inventory of assets such as servers, devices, accounts and data. He called for a management system in which departments verify their assets and responsibilities and take part in security work. An AI-based vulnerability analysis and response system will check externally exposed websites, data-center equipment and work devices, and track whether patches are applied. Baek said the city would prioritize checking and patching weak points, noting that attacks tend to target areas with weak management.
Seoul will upgrade security filters that prevent personal or sensitive information from being entered into generative AI systems: instead of detecting only prohibited words, they will assess sensitive information using context. The city will also build an integrated security management system to collect vulnerability inspection and remediation records from each organization. For private cloud services, Seoul plans a dedicated security zone and wider monitoring by its Cyber Safety Center. Baek said a personal information leak involving Seoul’s public bike service, Ttareungi, occurred in a private cloud in 2026. The center provides security monitoring for Seoul-related organizations 24 hours a day, 365 days a year, and is upgrading AI-based detection and blocking.
Seoul plans to shift the National Information Security Policy Council from a focus on general assemblies and conferences toward working-level discussions. It is considering committees for policy, technology and operations, building on its current 12-member steering group. The council includes central government ministries, local governments and public institutions. Members are expected to share practical experience, policy materials and good practices on AI security, N2SF and quantum-resistant cryptography, and to establish a system for joint responses to emerging cyber threats. Baek said organizations need a forum to discuss implementation because their environments and scale differ.