News Details

img

Korea Research Security

South Korea strengthens research security at universities

South Korea has begun building a national research-security system to prevent advanced technologies from leaking out of universities and research institutions, under new rules that took effect on 20 August.

The revised National R&D Innovation Act introduces a new ‘sensitive project’ category and expands universities’ security obligations, as the government seeks to connect universities, specialist research-security bodies and ministries into a nationwide response system.

The policy overhaul follows technology-leak cases involving university laboratories and rising concern about systematic Chinese efforts to lure researchers with “irresistible” economic packages, as reported by News 1.

One leak case involved a Vietnamese graduate student researching power-conversion technology for electric vehicles at a university in Seoul who abruptly left the programme in June 2023 and moved, via Vietnam, to a university research institute in Taiwan, as reported by Money Today in April 2025.

Police later confirmed that the student had stored research materials, including technical drawings, on a cloud server and taken them abroad.

When he returned to Korea in November 2024, police seized his laptop and mobile phone, obtained the relevant materials through forensic analysis and investigated him for violating the Act on Prevention of Divulgence and Protection of Industrial Technology.

The new security regime comes as Korean universities are becoming more internationally connected than ever.

According to Ministry of Education figures published on 12 February 2026, the number of international students at Korean higher education institutions rose from about 153,000 in 2020 to 209,000 in 2024 and 253,000 in 2025. Ministry and Korean Educational Development Institute data also show that the number of international graduate students more than doubled over the decade, from 24,160 in 2016 to 59,040 in 2025.

Separately, the government is confronting a broader increase in technology-leak cases. National Police Agency figures released on 19 January showed that police detected 179 technology-leak cases in 2025, up 45.5% from the previous year.

Of 33 cases involving overseas leaks, 18, or 54.5%, involved China, followed by Vietnam with four and Indonesia and the United States with three each. Overseas leaks were concentrated in areas that included semiconductors, displays, batteries and shipbuilding.

Yet voices from the field suggest that universities’ research-security management has not kept pace with the growing speed of international collaboration and researcher mobility.

Speaking to University World News on 12 September, one engineering professor who requested anonymity said: “In my experience, we are seeing more cases in which international students or overseas research partners take research results with them.”

University and law-enforcement sources interviewed for this article pointed to uneven security practices across institutions.

Some universities rely heavily on confidentiality agreements signed by research participants, while procedures for recovering research materials, terminating system access or checking what a departing researcher may have copied externally vary from institution to institution.

Sources also pointed to reluctance to report suspected leaks externally because of concerns about reputational damage as another potential vulnerability.

Security capacity-building needed

The government has itself identified the shortage of dedicated research-security organisations and personnel at universities as a weakness.

Announcing the Research Security Capacity-Building Support Programme on 5 June, the Ministry of Science and ICT, or MSIT, said that while international joint research and personnel exchanges had become routine, universities lacked dedicated organisations and staff to manage research security and advise researchers.

The issue resurfaced in recent law-enforcement discussions. At a Policy Forum for Industrial Technology Protection held on 10 September by the Industrial Technology Security Investigation Unit of the Seoul Metropolitan Police Agency, research-security vulnerabilities at universities and research institutions were among three main agenda items.

According to a 10 September report by the Yonhap News Agency, a dedicated session discussed “ways for universities and institutions to cooperate in strengthening research security”. Seoul Metropolitan Police Commissioner Ko Beom-seok said at the forum that the agency would “reflect voices from the field in investigations and policy to build a prevention-focused response system” against technology leaks.

Towards a national response system

The central aim of the government's new approach is to ensure that universities are no longer expected to handle research-security risks largely on their own.

At a research-security stakeholders’ meeting on 9 June attended by the Ministry of Education, the Ministry of Trade, Industry and Energy, the National Intelligence Service and experts from the field, MSIT unveiled four principles for research-security policy:

• Balancing the protection of researchers and research assets with open innovation.

• Prioritising prevention over punishment after an incident.

• Differentiating protective measures according to the sensitivity of the research.

• Strengthening international cooperation with major partner countries.

First Vice-Minister of Science and ICT, Gu Hyeok-chae, who chaired the 9 June meeting, said the ministry would “establish a field-orientated support system to help our researchers engage safely in international cooperation”, with the aim of making South Korea “a trusted partner with a globally competitive research-security system”.

In practice, the government is building several layers of support. Research-security centres were established at KAIST and Chung-Ang University in April, while the Science and Technology Policy Institute, or STEPI, operates the Global Research Security Policy Support Center to support the implementation of research-security policy and institutions.

Eight more universities – Busan National, Seoul National, Yonsei, Yeungnam, Incheon National, Changwon National, POSTECH and Hanyang – were selected this year for the Research Security Capacity-Building Support Programme. Under the programme, the selected universities are to receive around KRW500 million (US$360,000) a year through December 2028.

The funding is intended primarily to build research-security governance within universities rather than physical security infrastructure.

Selected universities are to establish dedicated research-security organisations and personnel.

They will also assess the reliability and safety of partner institutions and proposed collaborations before international cooperation begins, conduct internal security assessments and provide researchers with advice, training and legal and administrative support on issues including international contracts and intellectual property.

On 13 August, MSIT said the eight universities would be linked with the research-security centres at KAIST and Chung-Ang University and STEPI’s Global Research Security Policy Support Center, with the longer-term aim of building a “national-level research security response system” connecting government ministries, related agencies and the research community.

Hwang Seong-hun, MSIT’s Director-General for International Cooperation, said in the ministry's 13 August announcement that the government would continue supporting universities so that a management system could take root that addressed vulnerabilities "such as the potential overseas leakage of technology" while supporting safe international cooperation.

Universities’ security obligations expanded

The legal changes that took effect on 20 August give this emerging support system a regulatory counterpart by expanding the security obligations that universities and other research institutions must meet.

The most significant change is the creation of the "sensitive project" category, an intermediate category that sits between existing "security projects" and ordinary projects.

Under the revised enforcement decree, sensitive projects are designated by taking into account factors that include their strategic importance to national security and diplomacy, their technical and economic value and the impact that an overseas leak could have on the country.

Unlike security projects, sensitive projects do not in themselves restrict international collaboration. Instead, additional security procedures are required to prevent core technical information from leaking overseas.

Seoul-based legal firm Yulchon, which advises on intellectual property and technology, said in a post on LinkedIn that the new category enables “flexible security management commensurate with applicable risk levels”.

Universities’ institutional obligations have also expanded. Under the revised enforcement decree, universities receiving KRW30 billion or more in government R&D funding annually, as well as institutions conducting security or sensitive projects, must establish institutional security measures.

These include appointing a security officer, providing security training and managing foreign participation and contacts.

According to advice posted by Yulchon, key measures universities need to take include “maintaining appropriate records of foreign researcher participation, establishing processes to conduct risk-based assessments of international research partners and maintaining appropriate records of institutional contacts with foreign persons and entities”.

Accountability for violations has also been strengthened. According to MSIT’s 11 August announcement, unauthorised disclosure or leakage of results from security or sensitive projects, failure to comply with a government corrective order on security and unauthorised transfer of ownership of security-project results are explicitly defined as misconduct that can lead to restrictions on participation in national R&D programmes and financial penalties.

Key guidance is still to come

Although the legal framework took effect on 20 August, universities are still waiting for some detailed guidance on how the new system will operate in practice.

According to MSIT's 11 August announcement, the ministry plans to establish a cross-government Security Guidelines for National R&D Projects and publish related manuals, including guidelines for classifying security and sensitive projects, in October.

The ministry also said it would hold explanatory sessions for universities, government-funded research institutes and research-management agencies during August and September.

The timing is significant because the new category requires judgements beyond the relatively specific areas covered by existing security projects. Sensitive projects are to be assessed according to considerations that include the strategic importance to national security and diplomacy, technical and economic value and the national impact of a potential overseas leak.

At the 9 June research-security meeting, MSIT identified differentiating protective measures according to research sensitivity as one of the four principles underpinning the new system. The guidance is therefore expected to provide universities with more detailed criteria for putting that principle into practice.

Impact on international collaboration

The government has repeatedly stressed that strengthening research security is not intended to reduce international collaboration.

The basic direction announced by MSIT on 9 June put balancing the protection of researchers and research assets with the promotion of open innovation first among its four principles. Rather than restricting international cooperation, the policy is intended to identify and manage risks while allowing research collaboration to continue.

Universities are grappling with the same balance. In an announcement published on 24 August confirming its selection for the Research Security Capacity-Building Support Programme, POSTECH quoted Park Su-jin, director of its Office of Research Affairs, as saying: “Research security is not a device for restricting research but a foundation for protecting researchers and research outcomes and for sustaining trustworthy international collaboration.”

Park said POSTECH would use the programme to build a research-security and technology-protection system suited to its research environment, with the aim of protecting nationally strategic technologies while strengthening the university's research capacity.

The distinction between managing research risk and treating foreign researchers themselves as a risk will be particularly important. The new framework does not generally prohibit foreign researchers from participating in research. Sensitive projects, in particular, are designed to allow international collaboration while applying additional safeguards to information judged to require protection.

That distinction matters in a university system that now hosts more than a quarter of a million international students. The challenge for universities will be to identify risks associated with particular research and collaborations without allowing nationality itself to become a substitute for risk assessment.

They will be seeking to close documented gaps in research security without creating unnecessary barriers for the international students, researchers and partners on whom the country's increasingly global research system depends.

  • SOCIAL SHARE :