[INTERVIEW] '1% vulnerability enough to bring down system' - The Korea Times

INTERVIEW '1% vulnerability enough to bring down system'

ENKI WhiteHat CEO Lee Sung-kwon poses during an interview with The Korea Times at the company's headquarters in Songpa District, Seoul, June 2. Courtesy of ENKI WhiteHat

ENKI WhiteHat CEO Lee Sung-kwon poses during an interview with The Korea Times at the company's headquarters in Songpa District, Seoul, June 2. Courtesy of ENKI WhiteHat

ENKI WhiteHat aims to redefine cybersecurity from attacker’s viewpoint

Regardless of size, nationality or industry, a growing number of companies are falling prey to cyberattacks. In Korea, the country’s largest mobile carrier SK Telecom was among the recent high-profile victims, with several other cases also making headlines for customer data breaches or system compromises.

Though big-name businesses boast hefty investments in cybersecurity and promote their systems as safe, security experts warn that countless companies are constantly under attack in the shadows.

Against this backdrop, gaining a growing importance is offensive security, which identifies and addresses vulnerabilities from a cyberattacker’s perspective through methods such as penetration testing.

“We often use the idiom ‘closing the barn door after the horse is gone,’ and offensive security is like sneaking into the barn and stealing the horse on purpose, just to see if it’s possible,” ENKI WhiteHat CEO Lee Sung-kwon said during an interview with The Korea Times.

“What matters most is identifying realistic attack scenarios from the attacker’s point of view and preparing for them. Even attackers have their own economics. No one’s going to blow up a barn with a missile just to steal a horse. That’s why it’s more important to think like an attacker. The most effective form of security is identifying the easiest path they would take and blocking it first.”

Image generated by ChatGPT

ENKI WhiteHat is one of Korea’s top three offensive security service providers in Korea. Established in September 2016, the company has been a range of offensive security services provided by more than 50 white-hat hackers, a term referring to cybersecurity professionals who use their skills to identify vulnerabilities.

The company has more than 120 cumulative clients, including major Korean firms including KakaoBank, Hyundai Motor and Samsung Electronics. Public clients also include Agency for Defense Development, Korea Aerospace Industries and the Cyber Operations Command of Korea.

So far, the company has been reporting more than 120 security vulnerabilities for the world’s biggest tech firms, including Apple, Google and Microsoft, as well as winning top prizes at global competitions, including the DEF CON in the U.S.

ENKI WhiteHat offers three types of offensive security consulting services tailored to each client’s goals and environment: managing the attack surfaces of IT assets, penetration testing from hackers’ point of view and education program to boost clients’ capabilities against security threats.

In penetration testing, also called team tests, the company simulates real-world attack scenarios to comprehensively evaluate how effectively an organization’s entire security system can respond to threats. If a network is penetrated and access is gained, testers then assess whether sensitive information can actually be identified and stolen, validating how much data could be compromised.

Lee shared several examples from the company’s penetration testing projects. In one case, the team gained access through a server connected to a company’s commuter bus system.

In other instances, they infiltrated networks via a temporary relay server used for internal reporting or through backdoor code inadvertently left behind by developers during testing. In a more extreme case, they were able to breach the system by physically swapping out a kiosk connected to the internal network and capturing login credentials.

ENKI WhiteHat CEO Lee Sung-kwon speaks during an interview with The Korea Times at the company's headquarters in Songpa District, Seoul, June 2. Courtesy of ENKI WhiteHat

“There are many cases where clients don’t even realize they have certain IT assets,” Lee said. “Up until now, many companies have relied on checklist-based security schemes, checking up whether they have certain equipment or vulnerability assessment tools… But for attackers, all they need is a 1 percent vulnerability. We’re seeing cases where such a small opening is enough to put an entire organization at risk.”

Doubts about checklist-based security schemes have been growing in the wake of SK Telecom’s data breach in April, which potentially compromised the universal subscriber identity module (USIM) data of 27 million customers. The breach was confirmed to be coordinated since 2022 using what global cybersecurity experts describe as “a state-sponsored backdoor designed for cyber espionage.”

Conventional security consulting services have largely focused on assisting companies to comply with government or internal security regulations. However, the SK Telecom breach revealed that attackers are increasingly sophisticated, with operations often carried out by state-sponsored or highly advanced groups.

Security experts, including Lee, argue that companies must improve their “actual defense capabilities by training against attackers, as they exploit every possible method to gain access to the system, regardless of rules or boundaries.”

ENKI WhiteHat CEO Lee Sung-kwon presents the company's offensive security solution during the Thales Trust My Tech 2025 program in this handout photo released May 26. Courtesy of ENKI WhiteHat

As part of this view, ENKI WhiteHat currently concentrates on its training solution, OFFen CAMP. It is an artificial intelligence-driven cybersecurity training platform designed to grow in-house elite security experts through scenario-based exercises. OFFen CAMP is now used by the Korean military, government IT organizations and foreign universities.

With OFFen CAMP, the company is now partnering with Thales, a France-based multinational aerospace and defense firm, through the latter’s Trust My Tech 2025 program.

Under the partnership, ENKI WhiteHat and Thales will look to explore integrating OFFen CAMP’s simulation scenarios with Thales’ latest cybersecurity solutions to create real-world training environments.

Lee said the company is already working with clients and partners in Singapore and Rwanda, and seeking to expand its reach to other global markets including Canada and Japan. The CEO also noted that the company is expecting a collaborative project in Saudi Arabia next year.

“Cybersecurity is shaking the very foundation of infrastructure around the world, and it is now one of the most important components of business management,” Lee said. “We believe an organization’s cybersecurity integrity hinges on the strength of its red team… Through partnerships with global clients, our goal is to become the leading white hat hacking firm in Asia.”



Nam Hyun-woo

Nam Hyun-woo has worked as a staff writer at The Korea Times since 2013, mostly covering business and politics. He currently belongs to the Business Desk where he covers topics such as emerging tech, AI, ICT and Korea's chaebol community. Prior to joining the team, he was the paper's correspondent for the presidential office of Korea during the Yoon Suk Yeol and Moon Jae-in administrations.

Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크