KQC Stephen Oh Vice President
"The adoption of AI agents is fundamentally changing the threat assumptions and attack surface of financial and public-sector institutions.
As delegated agents interpret goals and invoke tools across systems, traditional user-, session-, and network-centric Zero Trust controls are no longer sufficient to govern “abnormal behavior under valid authentication.”
This session presents key agent-specific threat patterns, including prompt injection, privilege drift, secret exposure, and tool misuse, through realistic finance and public-sector incident scenarios.
It then redefines the fundamental unit of Zero Trust from a “login session” to an “action” and introduces a five-layer reference architecture and control matrix that covers Agent Identity, Tool-use Control, and PQC-based Key Trust.
The session concludes with a 12-month execution roadmap aligned with financial supervisory requirements, network separation expectations, and public-sector security compliance needs."
Korean
English
Chinese
Japanese


