Investment in Information Security in the Pharmaceutical and Biotech Sectors Has Increased, but… Dedicated Staff Remains at '0' and CISOs Continue to Hold Dual Roles
[Edaily Reporter Hong Ju-yeon ] As the importance of information security for companies grows, domestic pharmaceutical and biotech firms have increased their investment in information security; however, it has been revealed that lax management systems—such as having “zero” dedicated staff or having the Chief Information Security Officer (CISO) and Chief Privacy Officer (CPO) hold dual roles—persist.
According to the Korea Internet & Security Agency (KISA) Information Security Disclosure Portal on the 3rd, companies subject to mandatory disclosure posted their information security status reports by the 30th of last month. An analysis of the disclosures by PharmEdaily—E-Daily’s premium pharmaceutical and biotech content service—revealed that while information security investment by major pharmaceutical and biotech companies increased overall, there were significant disparities among them.Trends in Dedicated Information Security Personnel at Major Companies (Image: Comprehensive Information Security Disclosure Portal)
According to the disclosures, SAMSUNG BIOLOGICS(207940)invested 10.419 billion won in information security last year. This represents a slight increase from 9.214 billion won in 2024, bringing the total above 10 billion won. The scale of investment in information security accounts for 9.9% of the company’s total IT investment. The company has a total of 8.5 dedicated information security personnel, comprising 7.5 in-house staff and 1 outsourced employee.
Celltrion(068270)The company’s investment in information security totaled 2.965 billion won last year, an increase of more than 300 million won from 2.61 billion won in 2024. This represents 17.2% of its total IT investment. The number of dedicated staff also increased from 8.8 in-house employees to 11.5. This figure exceeds the average number of dedicated information security personnel (11.2) among the 773 top-revenue listed companies, as compiled by the Ministry of Science and ICT.
Among traditional pharmaceutical companies, #GC Biopharma Corp. had the highest investment last year at 2.49 billion won, followed by HanmiPharm(128940)(1.545 billion won), CHONGKUNDANG(185750)(1.496 billion won), Yuhan(000100)(1.269 billion won), and DongKook Pharmaceutical Co.,Ltd.(086450)(1.16 billion won). In particular, GC Biopharma Corp. saw its information security investment grow by 207.4% over the past three years, and its investment last year increased by 39.1% compared to the previous year.
In terms of the proportion of information security investment relative to total IT investment, DongKook Pharmaceutical Co.,Ltd. (14.1%), CHONGKUNDANG (13.2%), Yuhan (11.8%), and GC Biopharma Corp. (10.8%) all exceeded 10%. HanmiPharm (5.1%) and DongwhaPharm(000020)(5.5%), among others, fell below the average information security investment ratio of 5.9% among the 726 companies subject to disclosure this year.
“Zero” Dedicated Staff and Reliance on Outsourcing… Some Companies Even Reduced Their Workforce
Unlike investment levels, management systems—including staffing and governance—largely showed no improvement. CHONGKUNDANG reported that it outsources the operation and maintenance of its information processing systems to Bell I&S, a group IT affiliate, and has no dedicated internal staff, relying instead on 6.5 outsourced personnel. HanmiPharm also had zero dedicated internal staff, and its outsourced workforce stood at 4.7 people—a decrease from 5.4 people last year. Yuhan (4.7 internal staff), GC Biopharma Corp. (3 internal staff), and DongKook Pharmaceutical Co.,Ltd. (1.7 internal staff) also had relatively small dedicated IT teams.
DongwhaPharm reported that it had zero dedicated personnel, both internal and external. The company explained that its holding company handles IT operations through a shared-service model, and that two employees in the information technology department also serve in information security roles. Investment in information security amounted to 170 million won, a slight increase from last year’s 144 million won, but it remains at only 5.5% of the investment in the IT sector (3.059 billion won). NOVAREX Co., Ltd.(194700) also reported zero dedicated personnel, both internal and external, and its investment of 49.73 million won represents 4.8% of the investment in the IT sector.
The issue of CISO and CPO roles being held concurrently also persisted. While both the CISO and CPO are responsible for corporate security, their roles differ. The CISO oversees information security strategy and execution, while the CPO manages personal information in accordance with laws and regulations. Typically, the CISO role is filled by a technical expert, and the CPO role by a legal expert. Concerns have been raised that if a CISO or CPO holds another position concurrently, security tasks requiring constant attention may be pushed to the back burner. However, many companies have a single executive serving in both roles for reasons such as cost, and such dual roles are permitted under current law.
At SAMSUNG BIOLOGICS, the Head of the Information Security Team—an executive—serves as both CISO and CPO, while at Celltrion, the Head of the relevant division—an executive—holds both positions. At GC Biopharma Corp., the CISO also serves as CPO and Head of the Digital Innovation Office. At Yuhan, the CISO and CPO concurrently serve as Head of the Information Technology Office and Head of the Business Management Division, respectively. At CHONGKUNDANG, an executive in charge of finance serves as CISO, while an executive in charge of compliance serves as CPO.
At HanmiPharm, the CISO and CPO hold the positions of Head of the Information Strategy Group and Head of the Human Resources and General Affairs Team, respectively, and also serve as CISO and CPO for Hanmi Science. There are also cases where the CISO is not at the executive level. The CISOs at HanmiPharm, Yuhan, and DongKook Pharmaceutical Co.,Ltd. are not executives, and at DongwhaPharm, the Head of the Information Strategy Team—who is not an executive—serves as both CISO and CPO.
Heightened Awareness Due to Hacking Incidents at Global Big Pharma Companies
The focus on information security systems in the pharmaceutical and biotech industries stems from a recent spate of cyberattacks targeting global pharmaceutical companies. According to foreign media outlets such as Reuters, Novo Nordisk suffered a breach of some of its internal IT systems last month. The hackers demanded a ransom of up to $50 million (approximately 72.2 billion won) and claimed that the stolen data included information on new drugs—both launched and unlaunched—clinical trial data, information on employees, physicians, and patients, details regarding production facilities, and information on the company’s internal AI models. The industry views this incident not as a simple ransomware attack but as an attempt to steal industrial technology. In South Korea as well, as security incidents continue across all sectors, there is growing concern regarding the security systems of pharmaceutical and biotech companies that hold research and development data and clinical information.
Current information security disclosure requirements apply to businesses above a certain size, such as those with annual sales of 300 billion won or more, or those with an average of 1 million or more daily users of information and communications services. Since it is difficult for outsiders to verify the investment scale of companies not subject to disclosure requirements, the government has been pushing for legislative amendments since last January to remove the “300 billion won or more in revenue” condition and expand the disclosure obligation to all corporations listed on the KOSPI and KOSDAQ markets.
LGELECTRONICS has developed a technology to recover and recycle rare earth elements—key minerals—from discarded home appliances. The company plans to utilize waste home appliances as a new source of r…
Hong Won-sik, former chairman of NamyangDairyProducts, lost his lawsuit against NamyangDairyProducts(003920)seeking 44.35775 billion won in severance pay. The court dismissed the former chairman’s cla…
At SOOP(067160), official esports tournaments, educational programs, collaborative matches, and variety shows are being created around a single game intellectual property (IP). Streamers and user comm…