Skip to content

The End of the Password Era: What the Breach of 16 Billion Accounts Tells Us

The 16 Billion Credential Breach: A Final Wake-Up Call for the Password Era

The recent exposure of 16 billion login credentials from services including Google, Apple, and Facebook is more than just another data breach; it is the definitive event signaling the end of the password era. Caused by infostealer malware and now actively traded on the dark web, this incident reveals a systemic failure in our digital identity infrastructure. The age of password-based security is over.

The Inherent Flaw: Why Passwords Were Doomed to Fail

For years, passwords have been the weakest link in digital security. They are fundamentally vulnerable to an ever-growing list of threats, from brute-force attacks to sophisticated phishing scams. Human psychology is the core of the problem; we create simple, predictable patterns or reuse the same password across multiple services out of convenience. This turns a single compromised password into a master key that can unlock an individual’s entire digital life, leading to identity theft, financial fraud, and catastrophic corporate data breaches.

The New Paradigm: Authentication Without Passwords

In response, a new security paradigm has become essential: passwordless authentication. Based on global standards like FIDO2, this method verifies users without a password, instead leveraging factors that can’t be easily stolen or guessed: what you are (biometrics like a fingerprint), what you have (a device like a smartphone), or where you are (geolocation).

The benefits are transformative. Since no password exists, all attacks targeting them are rendered obsolete. User convenience is dramatically improved, eliminating the need to remember complex credentials. For IT teams, it means an end to enforcing frustrating password policies and managing endless reset requests, freeing them to focus on more critical security tasks.

From Theory to Enterprise Reality with iSIGN Password-less

Adopting a passwordless future requires a solution built for the complexities of the enterprise. Penta Security’s iSIGN Password-less is designed to bridge this gap, delivering both enhanced security and seamless user convenience. It goes beyond simply removing the OS password by integrating deep Single Sign-On (SSO) functionality. A single, simple login to a device grants a user automatic, authenticated access to all their critical business platforms, from groupware and ERP to email.

This platform provides the granular policy controls, integrated monitoring, and anomaly detection that enterprises need to manage their security environment with precision. Backed by global security certifications (Common Criteria, Good Software) and robust encryption modules, iSIGN. Password-less is an enterprise-ready solution for a post-password world.

Passwordless authentication is no longer an option—it is the new standard for security and operational efficiency.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

WAPPLES Wins 2025 National Service Awards for the Second Consecutive Year

WAPPLES Wins 2025 National Service Award

Penta Security’s WAPPLES Marks 20th Anniversary with Second Consecutive National Service Award Win

Intelligent WAAP solution honored for superior customer satisfaction and market leadership, reaffirming its status as the sole winner in the award’s cybersecurity category.

Penta Security’s intelligent WAAP (Web Application and API Protection) solution, WAPPLES, has once again been honored at the 2025 National Service Awards, winning the Cybersecurity Solution category for the second consecutive year. This recognition coincides with the 20th anniversary of WAPPLES, marking two decades of market leadership and innovation in web security.

The National Service Awards recognize organizations that have earned exceptional consumer support, evaluating them on criteria such as customer satisfaction, competitive advantage, and service management. The cybersecurity category was established in 2024, with WAPPLES being its inaugural and, to date, only winner.

Since its launch in 2005, WAPPLES has maintained its position as the #1 web security solution in the Korean market for 17 straight years, renowned for its high detection accuracy and low false positive rate. Today, it is a top-tier global WAAP solution deployed in 171 countries and serves as the core engine for the Cloudbric SECaaS platform, which protects over 700,000 internet businesses worldwide.

“Winning this award as we celebrate the 20th anniversary of WAPPLES is incredibly meaningful,” said a spokesperson for Penta Security. “It validates two decades of customer trust and our commitment to innovation. We will continue to build on this legacy to deliver the highest level of satisfaction and security.”

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

“In the End, Encryption Is the Ultimate Solution to Cybersecurity”

Encryption

Data Encryption D.AMO

Beyond Compliance: Why Encryption is the Ultimate Answer to Modern Cybersecurity

The recent security incident at SK Telecom serves as a stark reminder of a fundamental truth in cybersecurity: compliance is not the same as security. As Penta Security’s Executive Director Taejun Jung explains, true data protection requires a proactive mindset where encryption is seen not as a regulatory burden, but as the ultimate line of defense.

In the SKT case, the leaked USIM data was not legally required to be encrypted. However, Jung notes that when combined with other information, such data can easily lead to personal identification. This highlights the critical danger of a check-box approach to security and why companies must proactively expand their encryption coverage beyond minimum legal requirements.

Many organizations hesitate to encrypt broadly due to fears of performance degradation, but Jung argues this is a misconception. “With proper system optimization, performance can often be maintained or even improved,” he stated, reframing encryption as “a form of insurance, not a cost.”

Looking ahead, the security landscape will be defined by connectivity, driven by AI, autonomous driving, IoT, and the cloud. “As a result, the importance of encryption to securely protect connected data will only grow,” Jung predicted. This is why Penta Security is actively researching next-generation technologies like homomorphic encryption and post-quantum cryptography.

The lesson is clear. In a world of evolving threats, perimeter defenses will inevitably be breached. Jung’s final message is a call for a paradigm shift: “In the end, encryption is the last line of defense… encryption is the answer.”

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security Expands Cloudbric Managed Rules for AWS WAF to Two New Regions

Penta Security Showcases Leading Data Security Solutions at GISEC 2025, Tapping into Middle East’s Booming Market

Penta Security has successfully concluded its participation at GISEC 2025, the Middle East and Africa’s largest cybersecurity exhibition, highlighting the company’s strategic focus on this rapidly growing region. The event in Dubai provided a valuable opportunity to engage with partners and customers as the demand for advanced security solutions soars.

The Middle East’s security market is experiencing robust growth, projected at 9.6% annually. This is fueled by widespread digital transformation, smart city initiatives, and strengthening data protection regulations like the UAE’s Personal Data Protection Law (PDPL).

At the exhibition, Penta Security engaged with over 25,000 security experts, showcasing its suite of enterprise-grade solutions designed to meet these regional challenges:

  • D.AMO: A comprehensive cryptographic platform for data encryption.
  • WAPPLES: An intelligent Web Application and API Protection (WAAP) solution.
  • Cloudbric WAF+: Korea’s first Security-as-a-Service (SECaaS) offering for web protection.

A key takeaway from the event was the significant interest from regional banks, government agencies, and enterprises in Penta Security’s D.AMO encryption platform. This demand directly correlates with the implementation of GDPR-level data protection regulations across the region, making data security a top priority.

Following successful meetings with promising partners and clients, Penta Security is poised to rapidly expand its presence in the Middle East and African cybersecurity markets, continuing its mission to deliver trusted security on a global scale.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Cloudbric in the Fast-Growing SaaS Market

The SaaS Revolution: How Cloud-Based Solutions Became Essential for Modern Business

The global shift to Software-as-a-Service (SaaS) is undeniable, with the market growing at a staggering pace. In Korea alone, the market is projected to surpass KRW 2.5 trillion this year. This isn’t just a trend; it’s a fundamental change in how businesses operate, driven by the need for agility and efficiency in a post-pandemic, digitally transformed world.

The appeal of SaaS lies in its inherent advantages over traditional on-premises software. It eliminates massive upfront hardware costs, offers predictable subscription-based pricing, and provides unparalleled scalability. For businesses, this means the freedom to scale services up or down as needed, while freeing IT teams from the burden of manual software updates and maintenance.

Pioneering Security-as-a-Service: The Cloudbric Story Penta Security recognized this potential early on. In 2015, when the SaaS model was still nascent in Korea, we launched Cloudbric, the country’s first Security-as-a-Service (SECaaS) platform. This year, as we celebrate its 10th anniversary, Cloudbric has evolved from a single web security solution into a comprehensive security platform.

The power of this model is evident in Cloudbric’s growth. It is now trusted by over 1,100 enterprise clients across 171 countries, delivering a robust suite of solutions that includes Web Application Firewalls (WAF), Zero Trust Network Access (ZTNA), and a cyber threat intelligence platform—all fully accessible online without hardware installation.

As digital transformation continues to accelerate, the SaaS model is no longer an alternative—it’s the standard. As a pioneer in SaaS-based security, Penta Security and the Cloudbric platform are perfectly positioned to help businesses navigate this new landscape securely and efficiently.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

[Penta Inside] Penta Security at AWS Summit Seoul 2025

Penta Security Connects with Cloud Leaders and Showcases Advanced Security Suite at AWS Summit Seoul 2025

The atmosphere was electric at AWS Summit Seoul 2025, Korea’s largest IT conference, where the future of generative AI and cloud innovation took center stage. Penta Security was proud to be at the heart of the action, engaging with thousands of attendees and showcasing our comprehensive suite of cloud security solutions.

At our Expo booth, we held live demonstrations and technical consultations for our three core cloud offerings: the D.AMO cryptographic platform, the WAPPLES SA virtualized web firewall, and the Cloudbric WAF+ security SaaS platform. Each solution is designed to address the complex challenges businesses face as they move deeper into the cloud.

To better understand these challenges, we conducted a live survey at our booth. The results were clear:

Nearly half (47.7%) of all respondents identified cloud security as their most critical concern.

When choosing a solution, they prioritized high security (37.2%) and cost-effectiveness (18.4%), validating the market’s need for proven, efficient security products.

The conversations and feedback from this event were invaluable. As a long-standing AWS Partner, we are more committed than ever to using these insights to enhance our solutions and leverage the AWS global ecosystem to help more businesses secure their cloud journey. Thank you to everyone who visited our booth and shared their perspectives.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Pentasecurity Participates in GISEC 2025, the Middle East and Africa’s Largest Exhibition

GISEC 2025

GISEC 2025 Insights: How Data Sovereignty and Smart Cities are Shaping the Middle East’s Cybersecurity Future

Penta Security has successfully concluded its participation at GISEC 2025, the Middle East and Africa’s largest cybersecurity exhibition, offering a firsthand look into one of the world’s most dynamic digital markets. The event in Dubai underscored the region’s rapid transformation and highlighted the critical security challenges and opportunities emerging as a result.

The Middle East’s cybersecurity market is experiencing explosive growth, projected at 9.6% annually. Our engagement at GISEC revealed two primary drivers behind this surge: a new regulatory imperative for data sovereignty and the immense security demands of ambitious smart city projects.

The New Regulatory Imperative: Data Encryption as a Mandate A key takeaway from our discussions with regional banks, government agencies, and enterprises was the profound impact of new data protection laws. With regulations like the UAE’s Personal Data Protection Law (PDPL) now in full force, organizations are moving beyond basic security and prioritizing comprehensive data protection. This has created an urgent, compliance-driven demand for robust data encryption. The significant interest shown in our D.AMO cryptographic platform confirmed that securing data at its core is no longer a “nice-to-have”—it’s a foundational requirement for doing business in the region.

Securing the Smart City Vision The region’s ambitious digital transformation and smart city initiatives are creating a vast new ecosystem of interconnected services, applications, and APIs. While these projects drive innovation, they also dramatically expand the digital attack surface. We observed a strong understanding among attendees that these new public and financial sector services require robust, specialized protection from day one. This validated the need for comprehensive Web Application and API Protection (WAAP) solutions like our intelligent WAPPLES platform, as well as agile, easy-to-deploy security like our Cloudbric WAF+ SaaS solution.

A Strategic Partner for a Digital Future The insights from GISEC 2025 confirm that Penta Security’s focus on foundational security—data encryption and application protection—is perfectly aligned with the strategic needs of the Middle East and Africa. Following highly productive meetings with promising partners and clients, we are more committed than ever to expanding our presence and serving as a key partner in securing the region’s digital ambitions.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

[Security Issue] SKT Hack Exposes One-Third of South Koreans to Risk

Massive SKT Hack Becomes National Crisis (SKT Hack)

A massive cyberattack has struck SK Telecom, South Korea’s largest mobile carrier, escalating into a national crisis that affects approximately 23 million subscribers. The breach, which occurred on April 18, 2025, goes far beyond a typical corporate data leak—it involved the theft of USIM data, which functions as a digital identity card for nearly a third of the population.

The compromised information includes USIM keys, International Mobile Subscriber Identity (IMSI) numbers, device identifiers (IMEI), and mobile phone numbers—all of which are tightly linked to individuals’ digital lives. These details can be exploited for USIM cloning, unauthorized communications, and financial fraud, posing a serious national security threat.

The incident reveals a critical vulnerability in the country’s communications infrastructure and underscores just how fragile our digital foundations can be in the face of sophisticated cyber threats. (SKT Hack)

SK Telecom Hack Exploited Weekend Timing and VPN Vulnerabilities

The cyberattack on SK Telecom occurred during the late-night hours of Saturday, April 18, 2025—a time when security monitoring tends to be less vigilant. Investigators believe the attackers strategically timed the breach to coincide with this window of reduced oversight. By the time the company’s security team detected the anomaly—on the night of April 19—data linked to nearly 23 million subscribers’ USIMs had reportedly already been compromised.

The attackers specifically targeted SK Telecom’s Home Subscriber Server (HSS)—a core component of the mobile authentication infrastructure. The HSS plays a critical role in verifying user identities and enabling mobile services, often referred to as the “heartbeat” of the telecom network. The fact that such a high-level system was compromised suggests the involvement of a highly sophisticated threat actor, likely beyond the capabilities of ordinary hackers.

While the full scope of the breach is still under investigation, early findings point to a vulnerability in SK Telecom’s VPN (Virtual Private Network) infrastructure as a key entry point. VPNs are commonly used to secure remote access to internal corporate systems, but in this case, outdated VPN equipment, weak authentication protocols, and a fundamental trust model that “grants full access once authenticated” were all cited as major weaknesses.

Attackers exploited these VPN flaws to gain initial access, and then laterally moved within the network to infiltrate high-value systems and extract sensitive data. The incident starkly illustrates the limitations of perimeter-based security models, particularly in the context of modern, distributed work environments. (SKT Hack)

Leaked Data and Associated Risks

The information leaked in this incident includes the USIM authentication key (KI), International Mobile Subscriber Identity (IMSI), device identifier (IMEI), and phone numbers—all of which are essential for user identification and authentication within mobile networks. This highly sensitive data effectively functions as a digital identity, and its exposure introduces several serious risks:

  • USIM Cloning Risk: With access to the stolen KI, attackers could replicate legitimate users’ USIMs, enabling unauthorized use of mobile communication services under someone else’s identity.
  • Bypassing Identity Verification: The stolen data could be used to circumvent mobile-based identity checks, which are widely used in financial services and public sector authentication systems.
  • Sophisticated Smishing Attacks: Combining leaked phone numbers with other personal data opens the door to targeted, high-precision smishing (SMS phishing) campaigns.
  • Network Disruption: If a large number of cloned SIMs are activated simultaneously, it could result in network congestion or outages, potentially paralyzing mobile services.

Although no confirmed cases of abuse have been reported as of now, experts warn that this kind of information is highly valuable on the dark web and may pose long-term cybersecurity risks.

SK Telecom data breach

How to Respond to Sophisticated Cyberattacks: Embracing SDP and ZTNA

The recent SK Telecom hacking incident has brought renewed attention to the vulnerabilities of traditional VPN infrastructure—highlighting how attackers exploited outdated equipment as a primary entry point. As cyber threats become more sophisticated, technologies like Zero Trust Network Access (ZTNA) and Software-Defined Perimeter (SDP) are emerging as essential alternatives to conventional perimeter-based security.

ZTNA is a security model that continuously verifies every access entity—users, devices, locations—before granting least-privileged access to resources. By authenticating and authorizing each access request to networks, applications, and data, ZTNA significantly reduces the risk of unauthorized access or lateral movement.

SDP, on the other hand, provides a dynamic and secure approach to access control by making internal resources invisible to unauthenticated users. Unlike VPNs, which often expose internal systems once connected, SDP only reveals specific services to validated identities—dramatically minimizing the attack surface.

Penta Security offers a ZTNA-based solution called Cloudbric Access Solution (PAS), built on SDP principles. PAS delivers high-level security by continuously verifying user identity and access permissions. As a SaaS offering, it requires no additional infrastructure and can be deployed instantly from any internet-connected environment—supporting fast, scalable rollout.

To prevent future security breaches like the SK Telecom incident and to strengthen foundational network security, ZTNA and SDP should be actively considered as core strategies. Zero trust–based architectures that segment access and eliminate implicit trust are rapidly gaining adoption both domestically and globally.

As digital transformation accelerates and remote work becomes the norm, the traditional notion of a fixed network perimeter is no longer sufficient. The SK Telecom hack serves as a wake-up call—companies must now move away from the outdated “trust but verify” approach and transition toward a zero trust model that assumes no implicit trust and enforces continuous verification. (SKT Hack)

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

[Penta Inside] WAPPLES Celebrates 20th Anniversary

On April 25, 2025, Penta Security’s intelligent WAAP solution, WAPPLES, celebrated its 20th anniversary. To mark the occasion, we take a brief look back at the journey WAPPLES has taken over the past two decades. Discover how WAPPLES continues to lead the web security market both in Korea and abroad—setting the standard for modern web protection.

 

 

WAPPLES 20th Anniversary

 

Korea’s First Intelligent Web Firewall, WAPPLES, Launched in 2005

As the web connects everything, cyber threats exploiting it have also grown rapidly. In response, Penta Security launched WAPPLES in 2005—Korea’s first intelligent web firewall designed to create a secure web environment.

Unlike traditional network firewalls, web application firewalls (WAFs) are specifically developed to protect web applications. Their primary role is to detect and block attacks such as SQL injection and cross-site scripting (XSS). In addition to guarding against direct attacks, WAFs help prevent data breaches, unauthorized logins, and website tampering. In other words, WAFs like WAPPLES act as a protective fence—shielding a web application’s “home” from external threats and internal risks alike.

WAPPLES stands apart from conventional, pattern-based firewalls by using COCEP, its proprietary logic-based detection engine, to analyze attack behavior. This approach enables intelligent threat detection with high accuracy and low false positives, even for previously unknown or unstructured attacks.

Just two years after launch, WAPPLES secured its first overseas customer in 2007. By 2008, the number of deployments had surpassed 500, drawing significant attention both domestically and internationally.

 

2008: Launch of WAPPLES Control Center

As the number of WAPPLES deployments grew both domestically and internationally, the need emerged for a centralized system to efficiently manage multiple WAPPLES instances across diverse network environments. In response, Penta Security launched the WAPPLES Control Center in 2008—an integrated policy management system that enables remote control of multiple WAPPLES units through a single console.

When managing WAPPLES becomes complex due to varying configurations, the Control Center simplifies operations by providing centralized monitoring and streamlined management. With this solution, WAPPLES can now ensure secure web protection across a broader range of environments—without limitations.

 

2011: Launch of WAPPLES SA / 2013: Expansion into Japan’s Cloud Market

In 2011, Penta Security introduced WAPPLES SA, the cloud-based version of its web application firewall. Unlike the traditional hardware appliance, WAPPLES SA is delivered as a virtual image, offering the same robust detection and blocking capabilities as the original WAPPLES—with only the delivery model changed. At a time when many organizations were hesitant to store sensitive data in the cloud, Penta Security addressed these concerns by offering the same high-level protection in a cloud environment, accessible through a simplified purchase and deployment process.

In 2013, Penta Security began offering its cloud-based web firewall services in Japan. Although Japan had a cloud adoption rate more than 30% higher than Korea at the time, its cloud security market was still in its infancy. Building on its local presence since establishing a Japanese branch in 2009, Penta Security leveraged market research and localization efforts to successfully enter the Japanese market with WAPPLES SA.

That same year, WAPPLES was honored with two major awards: a commendation from Korea’s Minister of Science, ICT and Future Planning as part of the Korea IT Innovation Grand Prize, and the Web Application Firewall of the Year Award from global research firm Frost & Sullivan.

 

2015: WAPPLES Ranked No. 1 in Asia-Pacific Market Share

In 2015, marking the 10th anniversary of its launch, WAPPLES ranked No. 1 in the Asia-Pacific web security market according to the Frost IQ: Asia-Pacific Web Security Vendor 2015 Report by global research firm Frost & Sullivan. The report highlighted WAPPLES’ market dominance, attributing it to the outstanding performance of its logic-based detection engine and Penta Security’s consistent investment in customer engagement—such as partner seminars and training programs.

Building on its strong foundation in Korea, Penta Security expanded rapidly across Asia by forming regional partnerships and adapting its business operations to local market needs, particularly in Japan and Southeast Asia. By offering a flexible product lineup—including appliance, cloud, and virtualized versions—along with centralized management tools, WAPPLES has been able to deliver tailored solutions to meet diverse customer requirements. This adaptability has played a key role in securing a leading position across the Asia-Pacific region.

Penta Security’s leadership in the web security market was further recognized in 2016, when it received the Best Security Company award at Frost & Sullivan’s APAC ICT Awards. The company has since played a pivotal role in establishing web application firewalls as a critical security layer within the ICT ecosystem.

 

2019–2024: Advancing Security with Intelligence and Global Recognition

In 2019, WAPPLES introduced a machine learning–based self-inspection feature to further enhance system reliability and security. This feature automatically detects potential issues during operation and either alerts administrators in real time or resolves them autonomously. It also provides continuous updates on system and service status to ensure operational stability and prevent disruptions.

Thanks to its advanced security and ease of management, WAPPLES earned several prestigious global awards in the following years. In 2020, it won the Application Security category at the BIG Fortress Cyber Security Awards, followed by the Best Innovation in Web Application Security at the Global Infosec Awards in 2021. In 2022, WAPPLES became the first Korean solution to be listed in Forrester Research’s Now Tech report for web application firewalls, and in 2024, it was named Web Firewall of the Year by Frost & Sullivan for the second consecutive year—cementing its reputation in the global cybersecurity arena.

In 2023, WAPPLES was selected as a key item in the Service Convergence category of the Industrial Convergence Innovation Awards hosted by Korea’s Ministry of Trade, Industry and Energy. That same year, it also received the National Service Award in the Cybersecurity category for the first time. Domestically, WAPPLES continues its legacy of leadership, maintaining the No. 1 market share in web firewalls for 17 consecutive years based on Korea’s national procurement platform.

Intelligent WAAP to Protect 700,000 Businesses in 2025

For 20 years since its launch, WAPPLES has been recognized as a leading web security solution in the Asia-Pacific region—delivering exceptional protection with low false positive rates. Its scalability, stability, and high performance have made it a core component of Cloudbric, Penta Security’s SECaaS (Security-as-a-Service) platform. Today, WAPPLES helps secure over 700,000 websites and online infrastructures worldwide.

From its beginnings as an appliance-based product to its current cloud-based SaaS model, WAPPLES has continuously evolved to stay at the forefront of global web security. In celebration of its 20th anniversary, Penta Security reaffirms its commitment to building a safer web environment, leveraging decades of trusted security technology and global experience.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

[Security Issue] Post-Quantum Cryptography: A New Security Paradigm for the Post-Quantum Era

In recent years, the term ‘quantum computer’ has appeared frequently in the news. Quantum computers are an innovative technology with computational power that differs fundamentally from conventional computers, but they are also causing great concern because they pose a serious threat to the Internet security systems we use today. Post-Quantum Cryptography

Most digital services such as financial services, email, and messaging applications that we use daily are secured using public key encryption technologies such as RSA and ECC. Unlike conventional computers, quantum computers can easily solve the mathematical problems (including prime factorization of large numbers) that these encryption systems rely on by using a special algorithm called Shor’s algorithm. In other words, the possibility of the Internet’s current security foundation collapsing increases once quantum computers become commercially viable. As a result, governments and companies around the world are focusing on a new encryption technology that can replace existing encryption systems to protect information safely even in the post-quantum era—post-quantum cryptography (PQC).

 

 

Post-Quantum Cryptography

 

What Is Post-Quantum Cryptography?

Post-quantum cryptography (PQC) literally refers to cryptographic techniques that are resistant to quantum computer attacks. While existing cryptographic systems have structures that can be easily compromised by the computational power of quantum computers, post-quantum cryptography is designed based on mathematical problems that remain difficult to solve even with quantum computers.

Based on different mathematical foundations, post-quantum cryptography typically includes ‘lattice-based cryptography’, ‘code-based cryptography’, ‘multivariate-based cryptography’, and ‘hash-based signatures’. Lattice-based cryptography is particularly popular due to its combination of strong security and efficiency, and many countries and companies are already transitioning to adopt it as their next-generation security technology.

 

Post-Quantum Cryptography Types

  • Lattice-based cryptography: The most prominent approach, recognized for being both secure and efficient
  • Code-based cryptography: Established and reliable, based on well-studied mathematical foundations
  • Multivariate-based cryptography: Provides security by leveraging the difficulty of solving polynomial equation systems, though it suffers from large key sizes
  • Hash-based signatures: Offer strong security, but have the disadvantage of large key and signature sizes

 

Major Countries’ Adoption of Post-Quantum Cryptography

Post-quantum cryptography is now being actively implemented at the level of national security and industrial strategy, extending beyond lab-level technology. The movements of major countries demonstrate their recognition of its importance.

The United States is leading the response. The U.S. National Institute of Standards and Technology (NIST) has been collaborating with cryptographers around the world on the “Post**-**Quantum Cryptography Standardization Project” since 2016. The U.S. Department of Defense and the NSA have also begun implementing quantum-resistant cryptography in military and national security systems. The European Union is also moving rapidly. The EU Cybersecurity Agency (ENISA) has published guidelines for the adoption of quantum-resistant cryptography and has prepared a roadmap for its implementation across both public and private sectors within member states. Germany and France are developing strategies to strengthen their companies’ competitiveness by allocating significant budgets to research and development of related technologies at the national level.

South Korea is also moving quickly. The National Intelligence Service (NIS) announced “National Standards for Post-Quantum Cryptography” in 2022 and began implementation primarily in the financial sector and public institutions. The Institute for Information & Communications Technology Planning & Evaluation (IITP) is also supporting related workforce development and industry growth, making quantum-resistant cryptography-based services likely to proliferate in Korea in the future. China aims to secure indigenous technology in all areas including quantum computing, quantum communication, and quantum-resistant cryptography through its ‘Quantum Information Science 2030 Plan’. Its intention to implement proprietary quantum-resistant cryptography standards across Internet infrastructure is clear, positioning it as an active participant in global security standard development.

 

Post-Quantum Cryptography

 

Post-Quantum Cryptography Technology’s Impact Across Industries

Post-quantum cryptography is not just a technology to replace current cryptosystems. It is considered a key technology that will bring about fundamental changes across digital infrastructure. Its impact is expected to be particularly noticeable in several industries.

In the financial industry, banks, securities companies, and insurance companies rely on public key cryptography for customer authentication, wire transfers, and payment systems. The adoption of quantum-resistant cryptography requires substantial system overhauls, and several global banks are currently in testing phases. IoT and 5G/6G network environments are also considered major application areas for quantum-resistant cryptography. Since IoT environments connecting billions of devices are highly vulnerable to quantum attacks, active development is underway for quantum-resistant cryptographic solutions that can operate efficiently with low power consumption.

In the cloud industry, a next-generation security competition has already begun focused on protecting customer data. Global cloud service providers such as Google Cloud and AWS are experimenting with quantum-resistant cryptography-based secure data transfer protocols, and specialized quantum security service packages are likely to emerge. The defense and aerospace industries are no exception. Satellite communications, military networks, and weapon systems are considered priority areas for quantum-resistant cryptography implementation, as they are directly tied to national security. The United States has already announced plans to implement quantum-resistant cryptography in next-generation military satellites.

Widespread quantum computer commercialization could still be years or decades away. However, one fact is clear: the encryption technology we use today is not quantum-secure. This is why governments and major companies are urgently adopting quantum-resistant cryptography. Governments and businesses are developing rapid transition strategies to prepare for the ‘quantum threat’ to existing encryption systems, fundamentally changing the cybersecurity technology paradigm. Post-quantum cryptography will become the new security standard, and companies and countries that proactively adopt it will gain competitive advantages in the digital society overall. Rapid changes are expected across industries including finance, telecommunications, cloud computing, and defense, and end-user impacts are expected to materialize soon. Post-quantum cryptography is now a critical strategic necessity, not an option, when discussing the future of security.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.