← Founder Blog
·4min·Society· views

The Lie Called Security Awareness

Another data breach, and the same refrain follows: “change your password, beware of suspicious texts.” Isn’t it strange? They collected the data — yet the one who must be careful is always me.

The lie called security awareness.

Another breach. And once again, the same words follow. “Change your password.” “Beware of suspicious text messages.” “Take care with your personal information.”

Isn’t it strange? They were the ones who collected the data, yet the one who must be careful is always me.

On the Korean internet, security always operates in a strange way. Signing up is endless: phone number, date of birth, real-name verification, authenticator apps, SMS codes. But when an incident happens, the arrow of responsibility points in exactly the opposite direction — as if it all happened because the user wasn’t careful.

There is no shortage of procedure. Consent forms are long, password rules are elaborate. But the complexity of procedure and actual safety are separate matters. Users keep getting inconvenienced, companies keep hoarding data, and when the breach comes, the victim is the user again. Is this security, or an administrative ritual for diffusing responsibility?

Here we need to go one layer deeper. Why do all these companies, as if on cue, collect so much?

More than corporate greed, it is because the state designed it that way. The residue of the internet real-name system, identity-verification mandates, financial and telecom regulation. The state has legally compelled identification for the sake of control, and for companies, identity verification became not a choice but compliance. If you don’t collect, you can’t open the service. So everyone converges on “collect as much as possible, just in case.” It was regulation, not the market, that made over-collection the standard.

And this structure is what breaks security. Because collection is mandated, central depots of identity data spring up everywhere: verification agencies, payment processors, every service’s database. The number of points that can be breached becomes not one but hundreds. A place that holds no data has nothing to steal in the first place. But when the system orders everyone to hold it, every place becomes a potential leak. Identification for the sake of control accelerates data collection, and accelerated collection makes security fragile.

This is not my claim. On August 23, 2012, the Constitutional Court struck down the real-name verification system in a unanimous decision, stating that the system had increased the possibility of users’ personal information being leaked or misused [1]. That a system meant to verify identity endangers identity — the nation’s highest court acknowledged this fourteen years ago. Yet that design philosophy lives on everywhere today under different names.

And when a breach happens? Punishment. But after-the-fact punishment saves no one.

Punishment is retribution for a leak that has already occurred; it is not prevention. Companies calculate the probability and severity of punishment and invest only the minimum in security. Users go on living with their leaked data. You can change a password, but you cannot change a resident registration number. Even with compensation, identity itself is never restored. A structure with only post-hoc punishment and no prior prevention converges on a single state: breaches keep happening, punishments keep coming, and no one gets safer.

A different design already exists. The heart of Europe’s GDPR is not its heavy fines but its ordering. The data minimisation principle — personal data must be adequate, relevant and limited to what is necessary for the purpose — comes first [2], and punishment backs it up. Making companies collect less in the first place is the center of the design, and for grave violations, fines of up to 4% of global revenue enforce that principle [3].

Korea went the opposite way this year. The amended Personal Information Protection Act, promulgated in March, allows fines of up to 10% of total revenue for companies with repeated or grave breaches — a whip that exceeds the GDPR’s 4%, the harshest in the world. It takes effect on September 11 [4].

But the structure that mandates collection remains untouched. The whip is made the strongest in the world, while the burden everyone was ordered to carry is never set down. Ordered to collect to the maximum — then, when robbed, punished harder than anywhere on earth.

This is not security policy. It is a contradiction.

So “people lack security awareness” is only half true. What is really lacking is not individual caution but institutional responsibility. Three things are needed. Make them collect less. Make them retain less. And impose real consequences on the agencies and companies that keep having incidents. Before demanding caution from users, the side that designed the system should be careful first.

If the structure stays as it is — users surrender everything, and when the breach comes it is users who must be careful again — then that is not a security system. It is a blame-shifting system.

References

[1] Constitutional Court of Korea, decision of Aug. 23, 2012, 2010Hun-Ma47·252 (consolidated) — the identity verification system (internet real-name system) ruled unconstitutional; the increased possibility of personal data leaks and misuse cited among the grounds.

· National Law Information Center, Constitutional Court decisions / Open Net commentary: opennet.or.kr/17467

[2] GDPR Article 5(1)(c) — the data minimisation principle: personal data limited to what is necessary for the purposes of processing.

· gdpr-info.eu/art-5-gdpr

[3] GDPR Article 83 — administrative fines: for grave violations, up to 4% of total worldwide annual turnover of the preceding financial year, or €20 million, whichever is higher.

· Shin & Kim GDPR newsletter (shinkim.com)

[4] Personal Information Protection Act amendment (promulgated Mar. 10, 2026; effective Sep. 11, 2026) — new punitive fine provisions for repeated or grave breaches, ceiling raised to 10% of total revenue (from 3%); CEO ultimate responsibility codified.

· E-Focus, “Data breach fines up to ‘10% of revenue’… CEOs to bear final responsibility” (June 2026)

Originally published on Brunch · July 8, 2026
L
Lee · Lee's Blueprint
Founder, MAEUM.io
Email [email protected]