Add preferred source
LG Uplus’s ISMS-P certification renewal review has been delayed for more than a year. The existing certificate expired last December, but the Korea Internet & Security Agency has yet to reach a conclusion. Industry observers believe the administrative investigation and police probe into last year’s hacking allegations are weighing on the review process. While the expiration of the certificate does not halt the company’s mobile telecom services, the prolonged review is creating uncertainty for business procurement, as certification status is used as an evaluation criterion in public and financial institution tenders. If the renewal is ultimately denied, LG Uplus could face fines and restrictions on participating in new projects.
Key Elements
LG Uplus’s core information security certification renewal has been delayed for more than a year, heightening uncertainty over the South Korean telecom operator’s ability to win public and financial sector contracts. The company applied for renewal in July of last year, but the Korea Internet & Security Agency (KISA), which oversees the review, has yet to issue a decision. The existing certificate expired on December 26 of last year.
According to telecom industry sources on the 11th, LG Uplus’s Information Security and Personal Information Protection Management System (ISMS-P) certificate was valid from December 27, 2022, to December 26, 2025. ISMS-P is a certification system that evaluates whether a company has established the organizational structure, personnel, access control systems, and incident response procedures needed to defend against hacking and data breaches, while also auditing the entire lifecycle of personal information from collection to destruction.
As a telecom operator, LG Uplus is legally required to obtain ISMS certification. Holding an ISMS-P certificate satisfies the statutory certification obligation for the information security segment. KISA conducts the certification review, while the Ministry of Science and ICT and the Personal Information Protection Commission jointly oversee the program.
LG Uplus applied for renewal in July of last year but has not received a result more than a year later. The company’s Privacy Center website still displays the expired certificate as its most recent document.
Industry observers point to the prolonged administrative investigation and police probe into last year’s hacking allegations as the reason for the delay. After allegations emerged that LG Uplus’s internal server access control system (APPM) had been hacked, exposing information on 8,938 servers and 42,256 accounts, the Personal Information Protection Commission launched an administrative investigation. The case later expanded into a police probe after additional suspicions arose that the company had recognized signs of the breach but failed to report it in a timely manner.
Security industry experts note that the hacking investigation and the ISMS-P certification review overlap significantly in their audit scope, making it difficult to rule on certification before the investigation concludes. Jang Hang-bae, a professor of industrial security at Chung-Ang University, said, “The hacking investigation could reveal flaws in the management system. If certification were renewed before the investigation results are finalized, the two determinations could conflict, which would also burden the certification body.”
A KISA official said only that “the review process is currently underway,” adding that “it is difficult to answer why the review is taking so long.”
Growing Uncertainty for Business Procurement
The expiration of the certificate does not mean LG Uplus must immediately suspend mobile telecom services or terminate existing contracts. The problem is that some public institutions, financial organizations, and large corporations use ISMS or ISMS-P certification status as a bidding requirement or security evaluation criterion.
The currently published certificate still shows the expired validity period. As a result, LG Uplus may find itself in a position where it must separately explain that a renewal review is in progress and clarify its current certification status during bidding processes or corporate customers’ security assessments. While having a renewal review underway does not by itself bar the company from all business participation, the longer the decision is delayed, the greater the uncertainty in securing new contracts and renewing existing ones.
In the worst-case scenario, if LG Uplus fails to obtain renewed certification and also fails to secure separate ISMS certification, it could face statutory certification compliance issues. Operators that fail to fulfill the ISMS certification obligation may be subject to fines of up to 30 million won (approximately $22,000), and participation in new projects where certification is a mandatory requirement would also become difficult.
The key issue at present is not the immediate suspension of mobile telecom services but the business uncertainty created by the prolonged review. With KISA declining to specify the reason for the delay, attention is focused on when and how LG Uplus’s certification review will ultimately be resolved.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
