South Korea's Financial Services Commission has ordered financial companies to immediately review all externally accessible IT assets and services following recent data breaches and cyberattacks. The sectorwide response focuses on identifying security and access control weaknesses, blocking unauthorized access and unnecessary information exposure, and accelerating threat intelligence sharing among financial companies and relevant authorities. Firms must examine every externally accessible system, regardless of whether it is customer-facing, and identify any route that allows access to internal information without adequate authentication. Particular attention must be given to authentication controls used when accessing personal and other internal data. The commission plans to provide a vulnerability checklist and require firms to report their review results promptly. The measures follow a Sept. 30 data breach at Shinhan Bank and subsequent attacks affecting KB Kookmin Bank and other major financial companies. Financial authorities have begun on-site investigations after receiving incident reports and are sharing attacker IP addresses, attack methods and other threat data with bodies including the Korea Internet and Security Agency. They will also supervise affected firms' consumer protection and compensation measures while analyzing the incidents for possible policy changes.