The end of the 'cost of doing business' fine
South Korea just moved the goalposts. They are raising maximum fines for data breaches to 10% of total revenue.
Look at it this way. That isn't just a penalty. It is a balance sheet event, and when the rules switch from flat fines to a percentage of global turnover, compliance stops being some small legal cost and becomes a risk to your very existence. If you run a multi-billion dollar business, losing 10% of your revenue isn't something you just mention on a quarterly call. It is the kind of thing that gets you fired by the board.
Are most of you just performing control theatre? You've got the policy and the annual slide deck for training; you have a SOC 2 report claiming your service organization is suitable in some vague way. That works fine for auditors, but it won't stop data from leaking.
I saw this happen around 2003 when SOX first started; firms spent millions on consultants to make massive spreadsheets of controls that looked great on paper. In practice, they did nothing, and those companies thought a signed PDF counted as a control. It didn't. It was just proof that someone clicked save.
The issue with a checklist is that it looks for existence instead of effectiveness; you can prove you have an encryption policy while your actual database passwords sit in a plaintext file on a shared drive. If South Korea hits you for 10% of your revenue, the regulator won't care that your CISO signed a paper in January, and they only care that the data is gone.
If you're the person implementing these controls, here is what this actually means for your evidence. Stop collecting "proof of policy" and start collecting "proof of prevention."
Stop sending me a screenshot of a firewall configuration once a year. It's useless. I want the logs. Specifically, show me every blocked attempt to access the crown jewels from the last ninety days.
Do you have an incident response plan? Great. Now show me the post-mortems from the last three minor leaks, and I need to see exactly how you changed the control design so those things don't happen again.
The strongest objection here is usually that this is "too granular" or "operationally expensive." The argument is that as long as the framework is mapped, the risk is managed.
That's a lie. Mapping a framework is just drawing a map of a minefield; it doesn't mean you can walk through it safely.
Your insurers are the ones who'll feel the second-order effect here. They aren't stupid. They've watched the Nigerian Data Protection Commission start probing several firms (over three high-profile cases this week alone) and they've seen the new hammer coming out of South Korea. These providers will stop covering fines based on revenue if you can't show evidence of runtime controls. Your premiums will spike or your coverage will just vanish because you leaned on a "robust" framework (god, I hate that word) instead of actual engineering.
You're exposed if you still treat compliance as a shield to hide behind during an audit; the regulator doesn't want a perfect folder of evidence. They want the hole in the fence that let the data out.
Would your current evidence prove that the control worked if a breach happened tomorrow, or would it just prove you followed the process of failing?
Check your database access logs before Friday.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- South Korea raises data breach fines to 10% of revenue - Korea JoongAng Daily Data Privacy (Google News)
- NDPC Probes Remita, Sterling Bank Over Alleged Data Breach - thefact.ng Data Privacy (Google News)
- FASB releases standard for mutual fund fair value reporting - Accounting Today PCAOB
- Macron pushes for EU-wide social media ban for under-15s amid privacy and enforcement concerns - Tomorrow's Publisher Data Privacy (Google News)
- Continuum GRC: Agentic AI Turns Governance Into a Runtime Control Discipline - The Des Moines Register InfoSec Compliance (Google News)
- Deloitte warns auditor BDO to lift standards after unacceptable ratings - streamlinefeed.co.ke PCAOB
- Congress Pushes AI Agents Into the Audit Trail - PYMNTS.com InfoSec Compliance (Google News)
- Federal regulators say mDLs can be used for bank identity checks - Biometric Update InfoSec Compliance (Google News)