SK shieldus said on the 18th that it published a technical report based on real response cases from its incident response team Top-CERT ahead of Information Security Month in July.
As the use of artificial intelligence (AI) for automated attacks and sophisticated hacking techniques spreads, ransomware and supply chain attacks are becoming more refined. According to the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA), the number of domestic incident reports last year was 2,383, about double the 1,277 in 2023.
The security industry says that in this environment, the importance of response capabilities that identify the cause of attacks and the paths of spread, beyond simple recovery, is growing. In practice, corporations continue to invest in building preventive systems and adopting security solutions, but after an incident, many focus on service normalization and fail to sufficiently identify intrusion routes or internal lateral movement. In such cases, there is a risk of reentry or repeated infection using the same vulnerability.
The report includes major incident cases reconstructed from Top-CERT's actual investigation experience. It introduces cases such as restoring encrypted data from a ransomware attack with forensic technology to normalize services without paying a ransom, and restoring deleted logs to assess the scale of personal data leakage and swiftly responding to restore corporations' trust.
It also includes a case in which the attacker's reentry route was found in a recurring ransomware infection that could not be resolved by simple recovery alone, blocking additional damage, and a case in which the flow of a supply chain attack via a partner company was backtracked to identify the leaked data and attack scenario.
SK shieldus explained that incident investigation is the starting point of cyber resilience, leading not only to identifying causes, confirming the scope of damage, and establishing recurrence prevention measures, but also to restoring customer trust and improving security systems.
Cybersecurity division head Kim Byung-mu (vice president) said, "Now, corporations' security competitiveness is determined not only by how well they block attacks, but also by how quickly and accurately they respond after an incident," adding, "Incident investigation is not a simple incident response expense, but an essential investment to protect corporations' core asset and brand trust."