KT Group rated the information protection level of KTis, the group's customer center operating affiliate, at the top-tier S grade last year, but data show KTis actually addressed less than half of the security vulnerabilities found in the same year. Because the performance in fixing vulnerabilities deteriorated sharply despite receiving the highest grade, questions are being raised about whether KT Group's security assessment properly reflected the affiliate's practical ability to respond to vulnerabilities.
◇ Despite a 100% security inspection rate, the vulnerability remediation rate is 46.9%
According to KTis's "2026 ESG report" on the 20th, the vulnerability remediation rate in 2025 was tallied at 46.9%. That is 32.2 percentage points lower than 79.1% in 2024. The vulnerability remediation rate refers to the proportion of identified vulnerabilities—found through system inspections or penetration tests—for which remediation has been completed. It is an indicator that shows not just whether vulnerabilities were found but how much the discovered issues were actually resolved.
KTis operates KT customer centers and contact centers for general corporations, artificial intelligence contact centers (AICC), telecommunications product distribution, and the 114 directory service. Because its business structure handles large volumes of customer information, including consultation records, contact details, and voice and text data, it requires a higher level of security management and rapid vulnerability remediation than general corporations.
In particular, as it expands its AICC business into the finance, public, medical, and manufacturing sectors and increases AI- and cloud-based services, the amount of customer data processed and the number of externally linked systems are likely to grow.
KTis itself selected "protection of customer and employee information" as its No. 1 ESG key issue and "strengthening the information security system" as No. 2. Although it put information protection forward as a core management task, the actual vulnerability remediation rate fell sharply. A gap has emerged between the information protection goals the company emphasized and its actual improvement performance.
In the same report, KTis said it received the top-tier S grade in KT Group's information protection level assessment. The number of information security incidents and violations of personal information protection regulations was zero each year from 2023 to 2025. The completion rate for employee personal information protection training was 100% for three consecutive years, and the inspection rate for 10 customer information processing systems also recorded 100%. However, inspecting all systems and actually eliminating the vulnerabilities found during the inspections are different matters. A 100% inspection rate shows whether all prescribed security inspections were conducted. In contrast, the vulnerability remediation rate indicates whether the necessary improvements after inspections were properly carried out. In effect, all inspections were completed, but the rate of completing follow-up actions was only 46.9%.
A security industry official said, "The vulnerability remediation rate is a preventive indicator that shows how much risk that could lead to incidents has been removed in advance," adding, "Zero security incidents can also be used as an indicator supporting the highest grade, but it is difficult to conclude that potential security risks were sufficiently managed on that basis alone. Incident counts are only a lagging indicator that shows the results of breaches that have already occurred."
◇ KTis: "Cumulative impact of new security vulnerabilities"… the cause of the 32.2 percentage point plunge is unclear
Amid a situation where a core preventive security indicator fell below half, questions are also being raised about KT granting KTis an S grade. If the remediation rate was included as an evaluation item, the appropriateness of the criteria for awarding the highest grade despite a low performance of 46.9% could be controversial. Conversely, if it was not included, the effectiveness of the evaluation system could be called into question for assessing the information protection level while excluding a core indicator that shows how much of the identified security risk was actually removed. In either case, observers say KT needs to explain whether its assessment properly reflected KTis's practical capability to respond to vulnerabilities.
In response, KTis explained that the decline in the vulnerability remediation rate was less a deterioration in response capability than a result of the methods for diagnosing vulnerabilities and calculating the rate. After the first diagnosis by item, additional new vulnerabilities were found through a second implementation diagnosis during the remediation process, and as the total number of diagnoses accumulated, the remediation rate became relatively lower. A KTis official said, "It is difficult to view the system's safety level as having decreased based on that figure alone," and noted, "Items not yet remediated are also being improved sequentially according to separate plans." KT said, "We comprehensively evaluate technical and managerial safeguards—such as the group company's security policies, information asset management, access control, and incident response systems—to diagnose information protection levels and assign grades."
However, KTis's explanation only describes a structure in which the vulnerability remediation rate can be calculated at a low level; it does not account for why last year's figure plunged by 32.2 percentage points from the previous year. Because the method of adding new vulnerabilities in the second implementation diagnosis was applied the same way in 2024, it is difficult to explain the large gap between the two years. KT also did not clearly state whether the vulnerability remediation rate is an item in the security grade evaluation.
Given that KTis is expanding its AICC business handling sensitive information in finance, the public sector, and medical fields, the sharp drop in the vulnerability remediation rate means more than a simple internal management metric. As touchpoints connected to external systems increase, even small vulnerabilities are more likely to lead to customer data leaks or service disruptions. Observers say the company should strengthen its standing response capability to swiftly resolve identified vulnerabilities rather than resting on the fact that it received the highest grade.