XML 20 R7.htm IDEA: XBRL DOCUMENT v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
1. Risk Management and Strategy
Cybersecurity is integrated into our risk management procedures through which we identify, assess, monitor, control, communicate and escalate cybersecurity-related risks. As cybersecurity threats continue to evolve, we expect to continue to expend substantial resources to modify or enhance our measures to detect and prevent cybersecurity attacks and to investigate and remediate information security vulnerabilities as they are identified. The risks posed by cybersecurity threats that could materially affect us, including our business strategy, results of operations or financial condition, are discussed in “Item 3.D. Risk Factors — Other Risks Relating to Our Business and Operations — Our activities are subject to cybersecurity risk.” For a description of our information technology systems, see “Item 4.B. Business Overview — Information Technology.”
We examine cybersecurity threats on an annual basis through a professional institution holding a license recognized by the Government. Such examinations include risk assessments designed to identify potential vulnerabilities and predict the potential impact of any identified risks. Based on the results of these assessments, action plans are developed and implemented, and the outcomes are reported to our Chief Information Security Officer (“CISO”). We operate an Information Protection Council, a collaborative governance body that includes the Information Protection Committee, information security task forces, and our and our subsidiaries’ CISOs, to strengthen cybersecurity oversight and ensure consistent implementation across the group. We regularly report to our board of directors and management on matters relating to cybersecurity operational risk management. Such reports generally include, among others: (i) the results of periodic cybersecurity risk management activities, (ii) the outcomes of internal training exercises designed to enhance preparedness and response capabilities for cyber incidents, system disruptions and natural disasters and (iii) the results of reviews of credit information protection activities and the status of information sharing among our group companies.
We have appointed an experienced professional with the requisite qualifications in information security technology and personal data protection as our CISO, in compliance with applicable domestic regulations. As a trusted advisor, the CISO ensures the accuracy of information relating to cybersecurity risks, makes final decisions on cybersecurity-related matters, and convenes the Information Protection Committee to address significant risks that could potentially impact our customer services. We regularly conduct vulnerability assessments and
black-box
penetration testing to identify potential external breaches and implement preventive measures. In addition, we monitor the exposure of sensitive information such as customer data to the dark web and deep web, and conduct additional preventive activities, such as attack surface management, cyber threat intelligence collection, and phishing and pharming detection.
To minimize the risk of security breaches involving customer information and other proprietary data, we have implemented a range of group-wide preventive measures, including the adoption and implementation of robust security systems and enhanced internal control measures. We are committed to maintaining high standards of cybersecurity and consumer protection measures, as well as continually upgrading them. We have established and are operating information security management systems for us and our subsidiaries, and we have implemented ISO 27701 or ISO 27001-certified security management systems and obtained Information Security Management System, or ISMS, certifications for most of our subsidiaries. We believe that these certifications provide third-party validation of our compliance with internationally recognized information security standards. 
 
Our Integrated Cybersecurity Monitoring Center enables continuous monitoring for indicators of potential cyber-attacks and provides early warnings that allow for prompt responses. To prevent both intentional and inadvertent security breaches by employees, we operate a violation monitoring system designed to identify potential threat scenarios in advance and to collect and analyze data that facilitates the early detection of security incidents. We have also established an information security laboratory within Shinhan DS, our IT services subsidiary, to support ongoing security research and development and to enhance our ability to respond to evolving cyber threats.
We provide regular cybersecurity training to our information technology personnel and other employees and have adopted advanced security infrastructure for online financial services, including mandatory website certification and keyboard security functions, supported by a dedicated team of information security professionals. In addition, periodic audits and simulation reviews are conducted across our subsidiaries by external experts. In accordance with applicable regulations, we maintain cybersecurity insurance coverage for our subsidiaries.
In response to the increasing use of mobile devices to access financial services, we have implemented enhanced security measures, including data encryption and service terminal monitoring, to provide secure mobile banking services, prevent unauthorized disclosure or misuse of customer information, and strengthen customer privacy protections. We are also mindful of the potential litigation and regulatory risks arising from cybersecurity incidents and are actively promoting a group-wide culture emphasizing safety, accountability and responsible data stewardship.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cybersecurity is integrated into our risk management procedures through which we identify, assess, monitor, control, communicate and escalate cybersecurity-related risks.
Cybersecurity Risk Management Third Party Engaged [Flag] false
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] The risks posed by cybersecurity threats that could materially affect us, including our business strategy, results of operations or financial condition, are discussed in “Item 3.D. Risk Factors — Other Risks Relating to Our Business and Operations — Our activities are subject to cybersecurity risk.” For a description of our information technology systems, see “Item 4.B. Business Overview — Information Technology.”
Cybersecurity Risk Board of Directors Oversight [Text Block]
2. Governance
We regularly report on cybersecurity risks and related operational matters to the board of directors and management. These reports provide
a
comprehensive overview of key areas, including ICT risk identification and assessment, cybersecurity incident response and recovery training, systems change management, incident management procedures, and the results of periodic testing.
To manage various information security risks, we have appointed a CISO as well as a Chief Privacy Officer (“CPO”), and we have established related governance structures to support their functions. The CISO and CPO oversee the management of our information protection strategy and internal control framework by periodically reviewing comprehensive reports on various cybersecurity and data protection activities, including periodic vulnerability inspections, internal control and security monitoring, digital security reviews, incident response exercises, and emergency response training. Based on these reviews, the CISO and CPO make informed decisions relating to our cybersecurity and data protection practices.
In addition, the CPO also serves as the Credit Information Administrator/Guardian, as required under applicable domestic regulations. The Credit Information Administrator/Guardian is required to provide annual reports relating to credit information protection to the board of directors and submit related reports to governmental agencies. 
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The CISO and CPO oversee the management of our information protection strategy and internal control framework by periodically reviewing comprehensive reports on various cybersecurity and data protection activities, including periodic vulnerability inspections, internal control and security monitoring, digital security reviews, incident response exercises, and emergency response training.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Based on these reviews, the CISO and CPO make informed decisions relating to our cybersecurity and data protection practices.
Cybersecurity Risk Role of Management [Text Block] In addition, the CPO also serves as the Credit Information Administrator/Guardian, as required under applicable domestic regulations.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
To manage various information security risks, we have appointed a CISO as well as a Chief Privacy Officer (“CPO”), and we have established related governance structures to support their functions. The CISO and CPO oversee the management of our information protection strategy and internal control framework by periodically reviewing comprehensive reports on various cybersecurity and data protection activities, including periodic vulnerability inspections, internal control and security monitoring, digital security reviews, incident response exercises, and emergency response training. Based on these reviews, the CISO and CPO make informed decisions relating to our cybersecurity and data protection practices.
In addition, the CPO also serves as the Credit Information Administrator/Guardian, as required under applicable domestic regulations. The Credit Information Administrator/Guardian is required to provide annual reports relating to credit information protection to the board of directors and submit related reports to governmental agencies. 
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Credit Information Administrator/Guardian is required to provide annual reports relating to credit information protection to the board of directors and submit related reports to governmental agencies.