Korea trains security engineers well and then loses them to better-paid work

The country produces world-class offensive security talent through small elite programmes while the firms that actually need defenders compete for staff on budgets set by subcontracting economics.

Korea’s reputation in information security rests on a narrow and genuinely impressive base. Korean teams have finished at or near the top of DEF CON’s capture-the-flag finals repeatedly since the mid-2010s, and Korean researchers are a steady presence in vulnerability disclosure and exploit development at the international conferences. On the evidence of competition results alone, the country would appear to have a surplus of security expertise.

The domestic labour market does not behave as though it does. Successive assessments from the science ministry and the Korea Internet & Security Agency have projected shortfalls in security personnel running to the tens of thousands cumulatively over a decade, with several thousand unfilled positions in any given year. These estimates are sensitive to how “security personnel” is defined — whether a systems administrator with security duties counts, whether compliance staff count — and they should be treated as indicative. What is not in dispute among the firms doing the hiring is the direction.

The first explanation is compensation, and it is not primarily a comparison with other countries. It is a comparison with the desk next door. A capable engineer who can read assembly and write a fuzzer can also write backend services, and in Korea’s labour market the backend role at a large platform or game company pays more, offers clearer promotion tracks and produces work that shows up in a product. Security is a cost centre almost everywhere; in Korea, where the large employers grew up as manufacturers and portals rather than as software firms, it has often been budgeted as one.

The second explanation is structural, and it is specific to how Korea buys technology. A great deal of enterprise and public-sector security work is procured as fixed-price projects through system integrators, then passed down through tiers of subcontractors, each taking a margin. The engineer at the bottom of that chain performs the actual monitoring or penetration testing on a rate that has survived several rounds of price competition. Regulators have been aware of the problem for years — the push for “adequate compensation” in public information-security contracts, and the mandatory information-security disclosure regime introduced for large companies in 2022, were both attempts to make security spending visible enough to be defended internally. Disclosure has produced useful comparative data. It has not rewritten the procurement chain.

Against this, the training side has been unusually good. The Best of the Best programme, run by the Korea Information Technology Research Institute since 2012, selects a couple of hundred participants a year for a long mentored course in vulnerability analysis, digital forensics and product development, and its alumni network now runs through the country’s security startups and research teams. Korea University’s cyber defence department, established with the defence ministry, trains officers on full scholarship in exchange for a service commitment. Both programmes are selective, well-regarded and small — which is the point of them, and also their limit. Elite pipelines produce researchers. They do not produce the several thousand competent security operations engineers that banks, hospitals, local governments and mid-sized manufacturers need in order to be merely adequate.

Incidents have raised the price of inadequacy. A run of large telecommunications and platform breaches through the early 2020s put personal data of millions of Koreans into circulation, and the 2023 amendment of the Personal Information Protection Act shifted the basis of administrative fines toward a share of a company’s total revenue rather than the revenue related to the violation. That changes boardroom arithmetic in the right direction. It changes it on a schedule set by enforcement actions, while the workforce responds on a schedule set by university admissions and career decisions taken years earlier.

The gap between those two clocks is where the shortage lives, and no amount of competition-winning talent at the top of the distribution closes it.