ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Korea Council of Corporate Directors (KCCD), in collaboration with the Korea Exchange (KRX) is committed to enhancing corporate governance and protectinginancial consumers in South Korea and Global KCCD provides corporate boards with strategic guidance to strengthen transparency, accountability, and leadership in an increasingly complex macroeconomic and regulatory environment.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 A.I CyberSecurity Scoring

KCCD

Company Details

Linkedin ID:

kccd

Employees number:

1

Number of followers:

0

NAICS:

5416

Industry Type:

Business Consulting and Services

Homepage:

or.kr

IP Addresses:

0

Company ID:

KOR_1845092

Scan Status:

In-progress

AI scoreKCCD Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/kccd.jpeg
KCCD Business Consulting and Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreKCCD Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/kccd.jpeg
KCCD Business Consulting and Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

KCCD Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회: Coupang breach exposes data of nearly 34 million customersCyber Attack100512/2025
Rankiteo Explanation :
Attack threatening the organization's existence

Description: **South Korea’s Financial Watchdog Calls for Increased Cybersecurity Spending Amid Rising Threats** South Korea’s Financial Supervisory Service (FSS) is pressing corporations to boost cybersecurity budgets, warning that current investment levels fall short of international standards and leave businesses vulnerable to catastrophic breaches. FSS Governor Lee Chan-jin, speaking at his first press briefing since taking office in August, highlighted the disparity in spending, noting that Korean companies allocate far less to security than their U.S. counterparts and even the global average. Lee emphasized the severe financial risks of underinvestment, stating that a major cyber incident could threaten business continuity or even lead to bankruptcy. The push for higher budgets comes as recent cyberattacks underscore the growing sophistication and frequency of threats targeting critical financial systems. The FSS’s stance reflects broader concerns over the country’s preparedness to counter evolving cyber risks in an increasingly digital economy.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회: Coupang breach exposes data of nearly 34 million customers
Cyber Attack
Severity: 100
Impact: 5
Seen: 12/2025
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: **South Korea’s Financial Watchdog Calls for Increased Cybersecurity Spending Amid Rising Threats** South Korea’s Financial Supervisory Service (FSS) is pressing corporations to boost cybersecurity budgets, warning that current investment levels fall short of international standards and leave businesses vulnerable to catastrophic breaches. FSS Governor Lee Chan-jin, speaking at his first press briefing since taking office in August, highlighted the disparity in spending, noting that Korean companies allocate far less to security than their U.S. counterparts and even the global average. Lee emphasized the severe financial risks of underinvestment, stating that a major cyber incident could threaten business continuity or even lead to bankruptcy. The push for higher budgets comes as recent cyberattacks underscore the growing sophistication and frequency of threats targeting critical financial systems. The FSS’s stance reflects broader concerns over the country’s preparedness to counter evolving cyber risks in an increasingly digital economy.

Ailogo

KCCD Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for KCCD

Incidents vs Business Consulting and Services Industry Average (This Year)

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 has 16.28% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 has 53.85% more incidents than the average of all companies with at least one recorded incident.

Incident Types KCCD vs Business Consulting and Services Industry Avg (This Year)

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — KCCD (X = Date, Y = Severity)

KCCD cyber incidents detection timeline including parent company and subsidiaries

KCCD Company Subsidiaries

SubsidiaryImage

Korea Council of Corporate Directors (KCCD), in collaboration with the Korea Exchange (KRX) is committed to enhancing corporate governance and protectinginancial consumers in South Korea and Global KCCD provides corporate boards with strategic guidance to strengthen transparency, accountability, and leadership in an increasingly complex macroeconomic and regulatory environment.

Loading...
similarCompanies

KCCD Similar Companies

Korn Ferry

Korn Ferry is a global consulting firm that powers performance. We unlock the potential in your people and unleash transformation across your business—synchronizing strategy, operations, and talent to accelerate performance, fuel growth, and inspire a legacy of change. That’s why the world’s most fo

Advantage Solutions

At Advantage Solutions, we're the unseen architects behind your everyday purchases. From pantry staples to your online shopping carts, we ensure your favorite goods are always in stock and within reach by connecting manufacturers to the right retailers and teaming up with retailers to figure out the

Capgemini Invent

Capgemini Invent is the digital innovation, consulting and transformation brand of the Capgemini Group, a global business line that combines market leading expertise in strategy, technology, data science and creative design, to help CxOs envision and build what’s next for their businesses. For more

Alvarez & Marsal

Alvarez & Marsal is a leading global professional services firm dedicated to helping organizations tackle their most complex business issues, maximize stakeholder value, and deliver sustainable change. Privately held since its founding in 1983, clients select us for our deep expertise and proven a

WNS (Holdings) Limited (NYSE: WNS) is a global digital-led business transformation and services company. WNS combines deep industry knowledge with technology, analytics, and process expertise to co-create innovative, digitally-led transformational solutions with over 600+ clients across various indu

Accenture

Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are

Deloitte

Deloitte drives progress. Our firms around the world help clients become leaders wherever they choose to compete. Deloitte invests in outstanding people of diverse talents and backgrounds and empowers them to achieve more than they could elsewhere. Our work combines advice with action and integrity.

Xerox

Xerox has been redefining the workplace experience for over a century. As a services-led, software-enabled company, we power today’s hybrid workplace through advanced print, digital, and AI-driven technologies. In 2025, Xerox acquired Lexmark—expanding our global footprint, strengthening service c

Choosing a digital partner is about more than capabilities — it’s about collaboration and character. Unrealistic overhauls and off-the-shelf products ignore what matters most — your unique needs, culture, goals, and your legacy data and technology environments. At EXL, our collaboration is built o

newsone

KCCD CyberSecurity News

December 10, 2025 08:34 AM
Strengthening cybersecurity in the age of AI

In this SJUK exclusive, Digital Content Editor, Eve Goode speaks with Michael Downs, VP of Global Sales, SecurEnvoy about cybersecurity and...

December 10, 2025 08:10 AM
Vietnam passes revised cybersecurity law, retains data localization rules

MLex Summary: Vietnam's National Assembly on Wednesday passed the revised cybersecurity law, with over 90 percent of 443 lawmakers voting in...

December 10, 2025 08:05 AM
Secretary-General of ASEAN Presides Over Closing and Handover of Cybersecurity Enhancement Project

Secretary-General of ASEAN, Dr. Kao Kim Hourn, today presided over the Project Closing and Handover Ceremony for the 5-Year Implementation...

December 10, 2025 08:00 AM
New Portuguese Law Shields Ethical Hackers from Prosecution

Portugal has recently taken a significant step forward for online safety by updating its cybercrime law. This change, which was made public...

December 10, 2025 07:38 AM
Why SAP Security Still Needs the Wisdom of an 18th-Century Bookkeeper

The wisdom contained in the principle of “least privilege” has been with us for a very long time and has never died.

December 10, 2025 07:11 AM
From cybersecurity to cancer care: MeitY highlights early AI adoption across public services

To accelerate innovation for public good, the IndiaAI Mission has also partnered with ministries and government institutions to conduct...

December 10, 2025 07:04 AM
Key cybersecurity takeaways from the 2026 NDAA

A 4.1% increase in military cyber funding in the FY2026 NDAA budget underpins new requirements for hardened mobile devices,...

December 10, 2025 07:00 AM
Henkel CISO on the messy truth of monitoring factories built across decades

Smart manufacturing struggles with fragile architectures, legacy devices, and uneven monitoring that create cybersecurity weaknesses.

December 10, 2025 06:41 AM
How ransomware crime is evolving into a smart business crime

In early years of its introduction, ransomware appeared as a chaotic, often clumsy attempt by cyber criminals to lock victims out of their...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

KCCD CyberSecurity History Information

Official Website of Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

The official website of Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is https://kccd.or.kr.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s AI-Generated Cybersecurity Score

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s AI-generated cybersecurity score is 767, reflecting their Fair security posture.

How many security badges does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’ have ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 have SOC 2 Type 1 certification ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is not certified under SOC 2 Type 1.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 have SOC 2 Type 2 certification ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 does not hold a SOC 2 Type 2 certification.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 comply with GDPR ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is not listed as GDPR compliant.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 have PCI DSS certification ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 does not currently maintain PCI DSS compliance.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 comply with HIPAA ?

According to Rankiteo, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is not compliant with HIPAA regulations.

Does Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 have ISO 27001 certification ?

According to Rankiteo,Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 operates primarily in the Business Consulting and Services industry.

Number of Employees at Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 employs approximately 1 people worldwide.

Subsidiaries Owned by Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 presently has no subsidiaries across any sectors.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s LinkedIn Followers

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s official LinkedIn profile has approximately 0 followers.

NAICS Classification of Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 is classified under the NAICS code 5416, which corresponds to Management, Scientific, and Technical Consulting Services.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s Presence on Crunchbase

No, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 does not have a profile on Crunchbase.

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회’s Presence on LinkedIn

Yes, Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/kccd.

Cybersecurity Incidents Involving Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회

As of December 10, 2025, Rankiteo reports that Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 has an estimated 18,259 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Korea Council of Corporate Directors (KCCD) / 한국기업이사회협의회 ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

Incident Details

Can you provide details on each incident ?

Incident : Cyber Attack

Title: None

Description: Watchdog pushes for higher cybersecurity budgets following recent incidents in South Korea. The Financial Supervisory Service (FSS) urges corporates to increase security-related investment, citing lagging international benchmarks and inadequate risk recognition.

Type: Cyber Attack

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyber Attack KCC1765306489

Operational Impact: Potential bankruptcy risk due to breaches

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Cyber Attack KCC1765306489

Lessons Learned: Current cybersecurity spending levels in South Korea lag international benchmarks and do not match the scale of risk to business continuity.

What recommendations were made to prevent future incidents ?

Incident : Cyber Attack KCC1765306489

Recommendations: Increase security-related investment to align with international standards and mitigate risks of catastrophic breaches.

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are Current cybersecurity spending levels in South Korea lag international benchmarks and do not match the scale of risk to business continuity.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Increase security-related investment to align with international standards and mitigate risks of catastrophic breaches..

References

Where can I find more information about each incident ?

Incident : Cyber Attack KCC1765306489

Source: Korea Times

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Korea Times.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Cyber Attack KCC1765306489

Stakeholder Advisories: FSS Governor Lee Chan-jin advises corporates to recognize the risk of bankruptcy due to cyber breaches and increase cybersecurity budgets.

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was FSS Governor Lee Chan-jin advises corporates to recognize the risk of bankruptcy due to cyber breaches and increase cybersecurity budgets..

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Cyber Attack KCC1765306489

Root Causes: Inadequate cybersecurity investment and low risk recognition among Korean companies.

Additional Questions

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was Current cybersecurity spending levels in South Korea lag international benchmarks and do not match the scale of risk to business continuity.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Increase security-related investment to align with international standards and mitigate risks of catastrophic breaches..

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Korea Times.

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was FSS Governor Lee Chan-jin advises corporates to recognize the risk of bankruptcy due to cyber breaches and increase cybersecurity budgets., .

cve

Latest Global CVEs (Not Company-Specific)

Description

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=kccd' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge