● AI Security Spending Must Be Built In Not Bolted On
Core Cybersecurity Summary in the AI Era: “If you keep layering on security every time you’re attacked, you’ll end up with a patchwork mess”
The core takeaway of this piece is simple.
In an era where AI agents send emails, read documents, and even handle payments, you can no longer survive by adding security solutions after an incident, as in the past.
In particular, when building a proprietary AI foundation model, the so-called independent foundation model, or Dubamo, the entire AI powerhouse strategy can wobble unless security is embedded from the earliest design stage.
In this article, we’ll cover the changes in AI hacking, access management for AI agents, cyber-physical security, vulnerabilities in Korea’s cybersecurity posture, and security budgets and talent development all at once.
And at the end, I’ve separately organized the real core points that are relatively less emphasized in other news or on YouTube but that companies and investors absolutely need to see.
1. The core of security in the AI era is not “post-incident response” but “embedding it at the design stage”
The point Jo Hyun-sook, chair of the Codegate Security Forum, emphasized most strongly was the practice of continuously bolting security onto existing systems.
When malware appears, a solution is added to block it; when another attack appears, another security device is added.
Over time, this makes systems increasingly complex, increases the number of management points, and eventually turns them into a “patchwork system” where it becomes difficult to even identify where the vulnerabilities are.
The problem is that this approach may have worked to some extent in the early days of digital transformation, but in the AI era it no longer works.
AI models keep connecting with data, infrastructure, APIs, plugins, open source, and external agents.
Therefore, security is not a feature to be added later; it must be designed as part of the system from the beginning.
This is especially true for Korea’s push for its own AI foundation model.
If Dubamo is to become core national infrastructure for competitiveness, security must be built into the model design, data collection, training process, authentication system, access permissions, and deployment environment.
In other words, the approach of “build the AI first and add security later” is dangerous.
Going forward, AI investment and cybersecurity investment must not move as separate budgets; they must move within the same strategy.
2. AI vs. human hackers: human insight still matters, but the gap is narrowing quickly
This year at Codegate, the showdown between human hackers and AI drew attention.
In team-based competition, AI pulled ahead quickly on simple calculation-style problems early on, but as the rounds progressed, it reportedly fell to around 18th place as human judgment became necessary for more complex problems.
This is quite symbolic.
At present, AI is strong at fast search, computation, and repetitive tasks, but it still needs human involvement for complex contextual judgment and strategic decision-making.
Still, this is not a situation to feel safe about.
What matters is that in individual-style competition, AI rose as high as second place.
While human collaboration was strong in team-based complex problems, this means that in hacking and analysis tasks for specific purposes, AI has already reached a considerable level.
In the future, we may move beyond “an era where AI assists hackers” and enter “an era where AI itself becomes the attacker.”
Attackers can use AI to find vulnerabilities, alter malware, personalize phishing messages, and bypass defensive systems.
Conversely, defenders must use AI to detect anomalies, analyze intrusion paths, and automate real-time response.
3. AI hacking is completely different from conventional hacking
In the past, hacking mainly had relatively clear goals such as server intrusion, personal data theft, system paralysis, or ransomware infection.
Accordingly, defenses were designed around servers, networks, endpoints, and databases.
But in the AI era, the attack surface becomes much broader.
Everything becomes a target: what data the AI model was trained on, what permissions it has, what APIs it connects to, what open-source libraries it uses, and what agents it interacts with.
For example, if an AI agent can read internal company documents, send emails, manage schedules, and even process payment approvals, the situation changes completely.
Attackers no longer need to break directly into the server.
They can trick the AI agent into executing the wrong commands, sending sensitive information outside, or approving fraudulent payments.
As mentioned in the interview, if the average time from vulnerability discovery to actual attack used to be around 2.2 years, some analyses suggest that using AI could reduce that to around 20 hours.
That is a signal that the very way security operations are run must change.
Monthly checks, quarterly audits, and incident-after reporting systems alone cannot keep up with the speed of AI-based attacks.
4. How much authority should we give AI agents?
The core of AI agent security is access control.
Going forward, companies will entrust AI agents with tasks like writing emails, searching documents, writing code, responding to customers, reviewing contracts, processing purchase requests, and handling payments.
The most important question at that point is: “How far can this agent go?”
Chairwoman Jo emphasized that the following items must be tightly controlled when using AI agents.
-
Check what the AI model was trained on.
-
Restrict what data it can access.
-
Understand the infrastructure it operates on.
-
Clearly define the scope of actions it can take.
-
Inspect which APIs it uses to connect with other agents.
-
Verify that vulnerabilities are not being introduced through the open-source supply chain.
-
Ensure that a human can intervene immediately and shut it down if a problem occurs.
In other words, an AI agent may look like a smart employee, but from a security perspective it is an automated internal user with permissions.
If those permissions are overly open, incidents can arise that combine insider threats with external attacks.
From a company’s perspective, adopting AI agents should not be judged only by productivity.
You also need to look at who approves actions, what records are left, when automatic execution stops, and how access to sensitive data is restricted.
This area is likely to become an important variable in future corporate valuation and industrial security risk analysis as well.
5. Cyber-physical security: now hacking can stop factories and power grids
Cyber-physical security is the concept of preventing cyberattacks from causing damage in the physical world.
Simply put, it means hackers can affect not just computers but also semiconductor factories, data centers, smart factories, robots, autonomous vehicles, power grids, and telecommunications networks.
In the past, information security and physical security were viewed separately.
Information security was about protecting servers and networks, while physical security was about building access and facilities.
But in the era of physical AI and smart factories, it is hard to separate the two.
For example, if the production control system of a semiconductor plant is attacked, it does not end with a simple data leak.
The production line can stop, equipment can malfunction, and delivery schedules can be disrupted.
This can quickly lead to supply chain risk and weakened export competitiveness.
The same is true for data centers.
If data centers, the core infrastructure of the AI industry, are attacked, cloud services, financial systems, enterprise operations systems, and public services can all be affected in succession.
Therefore, cybersecurity is no longer just an IT cost; it is a national infrastructure investment and an economic security strategy.
6. Korea’s biggest cybersecurity weakness is “culture and decision-making structure,” not technology
Korea is a world-class IT powerhouse, yet it repeatedly shows vulnerability to cyberattacks.
Chairwoman Jo does not see the reason as simply a lack of technology.
The bigger problem is organizational culture and the speed of decision-making.
When a problem is found in the field, it must be fixed immediately.
But in actual organizations, reporting procedures are long, approval stages are many, and there are often delays until the top decision-maker decides on equipment purchases.
In an era where AI-based attacks can infiltrate within 20 hours, this structure is extremely dangerous.
Another problem is that the punishment and accountability system after incidents is weak.
If companies and institutions do not truly bear strong responsibility even after major security incidents repeat, preventive investment will inevitably continue to be pushed back.
If security is seen only as a cost, budgets are added only after incidents occur.
But by then, the damage has already been done.
A recurring issue in Korea’s cybersecurity policy is the lack of a control tower.
National-level cyber threats are connected across finance, telecommunications, defense, manufacturing, public services, and energy infrastructure.
But if responses are split across ministries and institutions, it becomes difficult to see the big picture.
The AI era needs an integrated control tower even more urgently.
7. Dubamo and the national AI strategy: the security budget is not “leftover money” but a core investment
Korea is planning to invest a large budget into its AI strategy.
Within that process, the security industry is calling for at least 3% of the budget to be allocated to security.
If huge sums are spent on AI infrastructure and model development while security is treated as an add-on cost, the price paid later can be far greater.
The important point is that the security budget should not simply be split and distributed across multiple agencies.
Security architecture must be designed first within the overall AI strategy, and then each ministry, agency, and company should operate under the same standards.
In particular, Dubamo is directly tied to national AI sovereignty.
If this model is used in finance, manufacturing, defense, public services, healthcare, and education, a security failure is not just a technical issue.
It can affect data sovereignty, industrial technology leakage, national security, and even economic growth rates.
There are many ways AI models can be attacked.
Data poisoning that mixes malicious data into training sets, prompt injection that induces the model to output sensitive information, privilege theft through external plugins, and exploitation of open-source library vulnerabilities are all possible.
That is why security must be included within the model development methodology, not treated as a post-completion inspection step.
8. Developing AI security talent: offense and defense should not be split apart
When nurturing security talent, people often distinguish between white hackers and defensive personnel.
But in reality, you have to understand attacks to defend against them.
If you do not know how attackers infiltrate systems, you cannot stop them properly.
Chairwoman Jo believes there is no need to separately divide offensive technical talent and defensive technical talent.
AI security talent should not know only AI technology, and should not know only traditional security technology either.
They must broadly understand model architecture, data processing, networks, systems, cloud, APIs, open source, and even industrial field operations.
In Korea, slogans like “train 100,000 security experts” have been repeated for years.
But more important than numbers is practical capability.
In an era where AI becomes an attack tool, what is needed are people who can solve real problems, analyze real systems, and train real response scenarios rather than simply completing a training course.
The reason international hacking defense competitions like Codegate matter is exactly this.
That is because talent from such competitions has gone on to global companies and public institutions, becoming the foundation of national security capability.
In the future, it is highly likely that AI agents, model security, and physical AI security issues will be included much more in such competitions and training programs.
9. Basic security practices that individuals should protect right away
AI security may look like a grand national strategy, but actual attacks often begin with very small habits.
An email, a text link, a free coupon, or a smartphone notification can all become the starting point of an attack.
In particular, you should be cautious of the word “free.”
The moment you click a link that looks like a free event, free download, free gift card, or free reward, malware may be installed or account information may be stolen.
The basic rules individuals should follow are simpler than you might think.
-
Do not reuse the same password across multiple apps and websites.
-
Change passwords regularly for important accounts.
-
It is best not to store passwords in a smartphone memo app or photo gallery.
-
Do not click links if the source is unclear.
-
Set up two-factor authentication for financial, email, and cloud accounts.
-
Do not postpone update alerts; keep your operating system and apps up to date.
Security is not only the domain of special experts.
In today’s world, a small personal mistake can spread to company systems, public institutions, and financial networks.
10. The real core point that other news often misses: security is not a cost, it is economic infrastructure
The most important part of this interview is not just the phrase “embed security,” but the impact that idea has on the economic structure.
Going forward, cybersecurity will become core infrastructure directly tied to national competitiveness, not merely a line item in a company budget.
First, as the AI industry grows, companies with weak security may lose trust in the market.
No matter how well an AI service is built, if personal data leaks, the model is manipulated, or permissions are abused, customer and investor trust will quickly collapse.
Second, the stronger a country is in manufacturing, the more vulnerable it can become to cyber-physical attacks.
Korea’s semiconductor, battery, automotive, shipbuilding, and biotech industries are rapidly digitizing.
This means productivity rises, but so does the attack surface.
Third, AI agents are tools that raise productivity, but they can also become a new insider risk.
When companies introduce AI agents, they should not calculate only the benefits of automation.
Only by also calculating access control, audit logs, emergency shutdown mechanisms, and data access policies can you get a true ROI.
Fourth, security budgets are not an item to cut during a downturn; rather, they are defensive investments.
One major incident can simultaneously shake stock prices, brand value, customer retention, regulatory risk, and litigation costs.
That is why, in future global company analysis, cybersecurity capability is likely to become an important risk indicator beyond the financial statements.
Fifth, competition for AI dominance is not just about model performance.
Who builds safer AI infrastructure, who has a more trustworthy data system, and who responds to threats faster may determine the winner.
< Summary >
In the AI era, security has limits if it is simply added on after an incident.
Dubamo and AI agents must embed security from the earliest stages of design.
AI is already being rapidly used on both the hacking and defense sides, and the speed of vulnerability attacks is also increasing sharply.
For AI agents, the core issues are permission management, data access control, and human intervention mechanisms.
Cyber-physical security is an economic security issue that protects semiconductor factories, data centers, power grids, and telecommunications networks.
Korea must improve not only technology but also its control tower, decision-making speed, accountability system, and security budget structure.
Going forward, cybersecurity is not a cost but core infrastructure that protects AI investment, digital transformation, industrial security, and national competitiveness.
[Related Articles…]
- Why enterprise security strategy is changing in the age of AI agents
- The moment cybersecurity becomes core infrastructure for national competitiveness
*Source: [ 티타임즈TV ]
– “공격받을 때마다 보안 얹는다? 그러다 누더기 된다” (조현숙 코드게이트보안포럼 이사장)


