Principal-Agent Problem in Cybersecurity
ComplianceFebruary 21, 2022

Principal-Agent Problem in Cybersecurity

Prince Adu

It is natural for people to think about themselves first. Explore the critical dynamics of governance between technical specialists and management.

In April 2011, the largest Bank in South Korea, Agricultural Bank, experienced a system shutdown. Unlike other cyber attacks such as distributed denial of service attacks, the entire system and customer database was removed by running a UNIX command — rm -rf/ — meaning force recursive removal of the entire system. Customers were unable to transact business, banking halls were full with no sign of system restoration.

Ironically, until today, the person who caused the entire system to shut down cannot be identified. Why would such a command be executed to shut down an entire banking system, and for what purpose? As expected, the blame was pushed on North Korea.

The staged attack started with a compromise on a Windows-based laptop computer used by a hired management engineer (agent) who had access to a grey box UNIX-based system that held the bank's customer data. The question is: was it the negligence of the management engineer that caused the system shutdown, or was there a malicious intent behind the attack? Regardless, the contracted engineer had a responsibility in safeguarding access to the UNIX system.

Imagine the reputational damage, customer dissatisfaction, and lost business to competitors.

What would you have done if you were the CEO or MD of Agricultural Bank of South Korea?

Technology projects require specialized engineering skills in their execution. However, technology decisions related to the what and how are mostly delegated to network, systems and software engineers — of which the principal, due to his or her limited knowledge, can only test the system like any other end user. Obviously, there is insufficient and ineffective oversight on the operations of the engineers (agent), which eventually generates a conflict of interest.

In most companies, cybersecurity professionals are employees (agents) acting on behalf of the principal — MDs, CEOs, shareholders, and senior management. Companies rely on specialists for development, and the principal who has significant knowledge and expertise in securing systemic systems can effectively manage the conflict of interest problem with the agent.

So what happened to the Agricultural Bank of South Korea — was it a cyberattack or a mistake?

Written by

Prince Adu

All Insights