Posts

AI PenTest (Penetration Testing) Agents — Technological Evolution and Implementation Roadmap (3/3)

Image
๐Ÿšข Shipjobs Insight The Expansion of Autonomous Security into Industrial Domains  — A New Paradigm for Maritime and Shipbuilding Sectors 1️⃣ Introduction — “Security Now Lives on Code and Pipelines” AI-driven penetration testing (PenTest) technology has moved beyond research environments — it is now entering the industrial frontlines : shipyards, vessels in operation, and smart maritime infrastructures. Previously, AI security referred mainly to SOC logs or cloud traffic monitoring. Today, it encompasses engine rooms, control networks, PLC systems, and onboard data infrastructures — domains where AI directly observes, analyzes, and tests system behavior in real time. This shift represents more than just “security automation.”It marks the birth of self-governing security — systems that can monitor, test, and adapt without constant human intervention. “AI is no longer a guardian of code — it is becoming the architect of the entire security system.” — Shipjobs, 2025 2️...

AI PenTest (Penetration Testing) Agents — Technological Evolution and Implementation Roadmap (2/3)

Image
๐Ÿšข Shipjobs Insight The Rise of the AI Red-Team and Autonomous Security Strategies for the Maritime Industry 1️⃣ AI Agentic PenTest Landscape 2025 The current AI-driven penetration testing landscape is no longer a collection of static security tools — it has evolved into a network of adaptive, self-learning security organisms known as Agentic Security Systems.  Across the ecosystem, five major categories of tools are leading the transformation. Each approaches the problem from a different angle but shares a common pursuit of balance among Offensive capability, Autonomy, Defensive capacity, and Maturity. No Tool Core Function Role Key Characteristics 1 Pentagi (PentAGI) Multi-Agent Autonomous Penetration Testing Offensive Builds and executes attack chains autonomously — a self-organizing Red-Team 2 Nebula CLI-based AI Pentest Assistant Offensive Integrates with Nmap, ZAP, and other tools — practical for real-world use 3 PentestGPT Conversational, GPT-based Assistant Hybrid Safe f...

AI PenTest (Penetration Testing) Agents — Technological Evolution and Implementation Roadmap (1/3)

Image
๐Ÿšข Shipjobs Insight From AI that Penetrates Security to AI that Designs It (Part 1) AI PenTest (Penetration Testing) Agents   — Technological Evolution and Implementation Roadmap 1️⃣ Introduction — The Paradigm of Security Is Changing Just a few years ago, AI-driven security was understood as technology that supported human decision-making — detecting anomalies or analyzing threats. But today, AI is no longer a mere assistant; it is evolving into an independent actor — capable of designing attacks, constructing defenses, and continuously improving its own strategies through learning. The recently emerging AI PenTest (Penetration Testing) Agents are no longer single-purpose tools. They communicate, define objectives, and autonomously coordinate the entire chain of attack → analysis → reporting as part of an Agent Network . This trend began with PentestGPT — which followed human security engineers’ workflows, acting as an assistant that analyzed logs and proposed attack scenari...

The Psychology of Leadership Crisis and Growth Created by Success – Part 2: Must Sun-sin Lee Disappear from the Organization?

Image
⚔️ At the Moment of Growth, a Leader Steps onto the Test Stage As retirement gradually comes into view, I’ve often thought about writing a book that captures the lessons and experiences of my journey. At first, it was going to be about technology and trends — AI, data, cybersecurity, and digital transformation. Those were the things I knew best. But as the years passed, my focus began to shift — from technology to people , from systems to leadership . Because what’s truly difficult is not innovation itself, but finding the right balance between growth and leadership . Through years of changing organizations and moving between teams, I began to see one clear pattern: “Every organization tests itself at the moment of growth.”   When results begin to show, the team often starts to shake. People who once ran in the same direction begin to watch one another instead. As performance increases, people change. As the numbers climb, trust quietly erodes. And in that moment, the...

์„ฑ๊ณต์ด ๋งŒ๋“  ๋ฆฌ๋”์˜ ์œ„๊ธฐ์™€ ์„ฑ์žฅ์˜ ์‹ฌ๋ฆฌํ•™ - Part 2: ์กฐ์ง์—์„œ ์ด์ˆœ์‹ ์€ ์‚ฌ๋ผ์ ธ์•ผ๋งŒ ํ•˜๋Š”๊ฐ€?

Image
⚔ ์„ฑ์žฅ์˜ ์ˆœ๊ฐ„, ๋ฆฌ๋”๋Š” ์‹œํ—˜๋Œ€์— ์˜ค๋ฅธ๋‹ค ์–ธ์  ๊ฐ€ ์€ํ‡ดํ•˜๋Š” ์‹œ์ ์—, ์ง€๊ธˆ๊นŒ์ง€์˜ ๊ฒฝํ—˜์„ ๋‹ด์€ ํ•œ ๊ถŒ์˜ ์ฑ…์„ ๋‚ด๊ณ  ์‹ถ๋‹ค๋Š” ์ƒ๊ฐ์„ ์˜ค๋ž˜์ „๋ถ€ํ„ฐ ํ•ด์™”๋‹ค. ์ฒ˜์Œ์—” ๊ธฐ์ˆ ๊ณผ ํŠธ๋ Œ๋“œ์˜ ์ด์•ผ๊ธฐ์˜€๋‹ค. AI, ๋ฐ์ดํ„ฐ, ๋ณด์•ˆ, ๊ทธ๋ฆฌ๊ณ  ๋””์ง€ํ„ธ ์ „ํ™˜. ๊ทธ๊ฒŒ ๋‚ด๊ฐ€ ๊ฐ€์žฅ ์ž˜ํ•  ์ˆ˜ ์žˆ๋Š” ๋ถ„์•ผ๋ผ ๋ฏฟ์—ˆ๋‹ค. ํ•˜์ง€๋งŒ ์—ฐ์ฐจ๊ฐ€ ์Œ“์ผ์ˆ˜๋ก, ๋‚ด ์‹œ์„ ์€ ์ ์  **‘์‚ฌ๋žŒ’๊ณผ ‘์กฐ์ง’**์œผ๋กœ ์˜ฎ๊ฒจ๊ฐ”๋‹ค. ๊ธฐ์ˆ ๋ณด๋‹ค ๋” ์–ด๋ ค์šด ๊ฑด ๊ฒฐ๊ตญ ๋ฆฌ๋”์‹ญ๊ณผ ์„ฑ์žฅ์˜ ๊ท ํ˜• ์ด์—ˆ๋‹ค. ์ด์ง๊ณผ ์กฐ์ง ์ด๋™์„ ๋ฐ˜๋ณตํ•˜๋ฉฐ ๋‚˜๋Š” ๊ณตํ†ต๋œ ํŒจํ„ด ํ•˜๋‚˜๋ฅผ ๋ณด๊ฒŒ ๋˜์—ˆ๋‹ค. “๋ชจ๋“  ์กฐ์ง์€ ์„ฑ์žฅ์˜ ์ˆœ๊ฐ„์— ์Šค์Šค๋กœ๋ฅผ ์‹œํ—˜ํ•œ๋‹ค.” ์„ฑ๊ณผ๊ฐ€ ๋‚˜๊ธฐ ์‹œ์ž‘ํ•  ๋•Œ, ํŒ€์€ ์˜คํžˆ๋ ค ํ”๋“ค๋ฆฌ๊ธฐ ์‹œ์ž‘ํ•œ๋‹ค. ํ•œ๋•Œ ํ•œ ๋ฐฉํ–ฅ์œผ๋กœ ๋›ฐ๋˜ ์‚ฌ๋žŒ๋“ค์˜ ์‹œ์„ ์ด ์–ด๋А์ƒˆ ์„œ๋กœ๋ฅผ ์˜์‹ํ•˜๊ธฐ ์‹œ์ž‘ํ•œ๋‹ค. ์„ฑ๊ณผ๊ฐ€ ์Œ“์ผ์ˆ˜๋ก ์‚ฌ๋žŒ์€ ๋‹ฌ๋ผ์ง€๊ณ , ์ˆซ์ž๊ฐ€ ์˜ฌ๋ผ๊ฐˆ์ˆ˜๋ก ์‹ ๋ขฐ๋Š” ์กฐ๊ธˆ์”ฉ ์ค„์–ด๋“ ๋‹ค. ๊ทธ ์ˆœ๊ฐ„, ์กฐ์ง์—๋Š” ‘์ด์ˆœ์‹ ’๋ณด๋‹ค ‘์›๊ท ’๊ณผ ‘์„ ์กฐ’๊ฐ€ ๋Š˜์–ด๋‚œ๋‹ค. ์œ„๊ธฐ๊ฐ€ ์•„๋‹ˆ๋ผ, ์„ฑ๊ณต์ด ๋งŒ๋“ค์–ด๋‚ธ ๋ณ€ํ™” ๋‹ค. ์„ฑ๊ณต์€ ์–ธ์ œ๋‚˜ ์กฐ์ง์„ ์„ฑ์žฅ์‹œํ‚ค์ง€๋งŒ, ๋™์‹œ์— ๊ทธ ์กฐ์ง์˜ ๋ณธ์งˆ์„ ์‹œํ—˜ํ•œ๋‹ค. ์ง„์งœ ๋ฆฌ๋”๋Š” ๊ทธ ์‹œํ—˜๋Œ€ ์œ„์—์„œ ์กฐ์šฉํžˆ ์ค‘์‹ฌ์„ ์žก๋Š” ์‚ฌ๋žŒ ์ด๋‹ค. ⚖️ ์„ฑ์žฅ๊ณผ ์ •์น˜ ์„ฑ๊ณต์˜ ๊ธฐ์ค€๊ณผ ์„ฑ์ทจ์˜ ๋งŒ์กฑ์€ ์‚ฌ๋žŒ๋งˆ๋‹ค ๋‹ค๋ฅด๋‹ค. ๊ทธ๋ž˜์„œ ์„ธ ๋ช… ์ด์ƒ์ด ๋ชจ์ด๋ฉด, ๊ทธ ์•ˆ์—๋Š” ๋ฐ˜๋“œ์‹œ ์ •์น˜๊ฐ€ ์ƒ๊ธด๋‹ค. “์ •์น˜๋Š” ํ”ผํ•  ์ˆ˜ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋ฐฉํ–ฅ์€ ์„ ํƒํ•  ์ˆ˜ ์žˆ๋‹ค.” ๋ฌธ์ œ๋Š” ์ •์น˜์˜ ์กด์žฌ๊ฐ€ ์•„๋‹ˆ๋ผ, ๊ทธ ์ •์น˜๊ฐ€ ์–ด๋””๋ฅผ ํ–ฅํ•˜๊ณ  ์žˆ๋А๋ƒ ์ด๋‹ค. ๋ˆ„๊ตฐ๊ฐ€๋ฅผ ๋Œ์–ด๋‚ด๋ฆฌ๋Š” ์ •์น˜๊ฐ€ ์•„๋‹ˆ๋ผ, ์กฐ์ง์„ ๋” ๋ฉ€๋ฆฌ ๋ฐ€์–ด ์˜ฌ๋ฆฌ๋Š” ์ •์น˜๋ผ๋ฉด ๊ทธ๊ฑด ์ด๋ฏธ ‘์ „๋žต’์ด๊ณ , ‘์ง€ํ˜œ’๋‹ค. ์ •์น˜๋Š” ์‚ฌ๋ผ์งˆ ์ˆ˜ ์—†๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด ๊ทธ๊ฒƒ์„ ๋‘๋ ค์›Œํ•˜๊ธฐ๋ณด๋‹ค, ์กฐ์ง์˜ ์ง€์†์  ์„ฑ์žฅ์„ ์œ„ํ•œ ๊ตฌ์กฐ๋กœ ์„ค๊ณ„ ํ•ด์•ผ ํ•œ๋‹ค. ์กฐ์ง์ด ํŒŒ์ด๋ฅผ ํ‚ค์›Œ์•ผ ํ•˜๋Š” ์ด์œ ๋„ ์—ฌ๊ธฐ์— ์žˆ๋‹ค. ์ด์ˆœ์‹ ๋„, ์›๊ท ๋„, ์„ ์กฐ๋„ — ๊ทธ๋ฆฌ๊ณ  ์ด๋ฆ„ ์—†๋Š” ๋ณ‘์‚ฌ๋“ค๊นŒ์ง€ — ๋ชจ๋‘๊ฐ€ ์ž์‹ ์˜ ์ž๋ฆฌ์—์„œ ์˜๋ฏธ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋„๋ก ๋งŒ๋“œ๋Š” ๊ฒƒ. ๊ทธ๊ฒƒ์ด ๊ฑด๊ฐ•ํ•œ ์ •์น˜ ์ด๋ฉฐ, ์ง€์† ๊ฐ€๋Šฅํ•œ ์„ฑ์žฅ์˜ ์กฐ๊ฑด ์ด๋‹ค. ์ •์น˜๊ฐ€ ๊ฐ์ •์ด ์•„๋‹ˆ๋ผ ๊ณต์ •ํ•œ ์—ญํ• ...

KORMARIN 2025, Back on That Sea Again

Image
 I stood at KORMARIN again, after two years. The excitement and tension I felt the first time had quietly settled into a calm confidence. The industry continues to move fast. People, technology, interests, and time— all shifting and reshaping within its current. And somewhere along the way, I, too, have been changing with it. I think I finally recognized that this time. There was a faint scent of the sea in the exhibition hall, familiar faces and brief greetings exchanged, the subtle warmth of the field I hadn’t felt in a while— and for a moment, the thought came to me: “I’ve walked this path well, after all.” This KORMARIN was not just another exhibition. It was a quiet voyage back through my own journey. The event comes every two years. Some years I came because I wanted to, and some years because I had to— carrying a tired heart with me. But this year was different. My mind felt steadier, my view less shaken, and the direction ahead already clearer. There...

๐Ÿšข The Psychology of Leadership Shaped by Success - Part 1: Let’s Move Forward Together

Image
Dear EY MCH, As our project scopes continue to expand, each area now demands deeper specialization and accountability. Naturally, the roles and responsibilities that each of you carry are also growing. In the coming months, we expect to secure several new projects. Until our system-based organizational structure is fully established, things will likely become even busier and require greater focus and discipline. (However, as I’ve mentioned before — we will never compromise on the capability and attitude of the people we choose to work with. ) As I have shared with both management and many of you, our goal is not to build a conventional time-based consulting organization. We are creating a hybrid model — combining the operational depth of the maritime industry with the strategic and analytical discipline of consulting — to become a specialized consulting organization for the global shipbuilding and maritime domain. At the heart of this vision lie two essential values: Trust and...

⚓ ๋ฐ”๋‹ค์™€ ๊ธฐ์ˆ ์‚ฌ์ด์—์„œ ์Šค๋งˆํŠธ ๋งˆ๋ฆฐ ์ปจ์„คํ„ดํŠธ์˜ ์ด์•ผ๊ธฐ - Part 4: ์Šค๋งˆํŠธ ์„ ๋ฐ• ํ”„๋กœ์ ํŠธ๋Š” ์‹ค์ œ๋กœ ์–ด๋–ป๊ฒŒ ์ง„ํ–‰๋ ๊นŒ?

Image
  — ์Šค๋งˆํŠธ ์„ ๋ฐ• ํ”„๋กœ์ ํŠธ๋Š” ์‹ค์ œ๋กœ ์–ด๋–ป๊ฒŒ ์ง„ํ–‰๋ ๊นŒ? ๊ธฐํš๋ถ€ํ„ฐ ๊ตฌ์ถ•·์šด์˜๊นŒ์ง€์˜ ์ „์ฒด ๋กœ๋“œ๋งต ์Šค๋งˆํŠธ ์„ ๋ฐ• ํ”„๋กœ์ ํŠธ๋Š” ๊ฒ‰์œผ๋กœ ๋ณด๋ฉด ๋‹จ์ˆœํ•ฉ๋‹ˆ๋‹ค. “๊ธฐ์ˆ  ๋„ฃ๊ณ  ์‹œ์Šคํ…œ ๊ตฌ์ถ•ํ•˜๋Š” ํ”„๋กœ์ ํŠธ ์•„๋‹Œ๊ฐ€์š”?”๋ผ๊ณ  ๋ฌป๋Š” ๋ถ„๋“ค๋„ ๋งŽ์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์‹ค์ œ๋กœ ๋“ค์–ด๊ฐ€ ๋ณด๋ฉด ๊ธฐ์ˆ ๋ณด๋‹ค ์กฐ์œจ , ์žฅ๋น„๋ณด๋‹ค ํ”„๋กœ์„ธ์Šค , ๊ธฐ๋Šฅ๋ณด๋‹ค ์‚ฌ๋žŒ์˜ ์—ญํ•  ์ด ํ›จ์”ฌ ๋ณต์žกํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๊ทธ ๋ณต์žกํ•จ ์†์—์„œ ๊ธธ์„ ์žก๋Š” ๊ฒƒ์ด ์ œ ์—ญํ• ์ž…๋‹ˆ๋‹ค. ์˜ค๋Š˜ 4ํŽธ์—์„œ๋Š” ์Šค๋งˆํŠธ ์„ ๋ฐ• ํ”„๋กœ์ ํŠธ๊ฐ€ ์–ด๋–ป๊ฒŒ ์‹œ์ž‘๋˜๊ณ  , ์–ด๋–ค ๋‹จ๊ณ„๋ฅผ ์ง€๋‚˜ , ์–ด๋””์—์„œ ๊ฐ€์žฅ ๋งŽ์€ ๋ฌธ์ œ๊ฐ€ ์ƒ๊ธฐ๊ณ  , ์–ด๋–ป๊ฒŒ ์šด์˜ ๋‹จ๊ณ„๊นŒ์ง€ ์ด์–ด์ง€๋Š”์ง€ , ์ œ์˜ ์กฐ์„ ์†Œ ์žฌ์ง์‹œ์ ˆ ์Šค๋งˆํŠธ ์•ผ๋“œ ๊ทธ๋ฆฌ๊ณ  ์Šค๋งˆํŠธ ์‰ฝ ์—ฐ๊ตฌ ๊ฐœ๋ฐœ ํ˜„์žฅ์—์„œ ๊ฒฝํ—˜ํ•œ ํ๋ฆ„ ๊ทธ๋Œ€๋กœ ์„ค๋ช…ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ⚓ 1. ๊ธฐํš(Define) — ๋ฌด์—‡์„, ์™œ, ์–ด๋””๊นŒ์ง€ ํ•  ๊ฒƒ์ธ๊ฐ€ ์Šค๋งˆํŠธ ์„ ๋ฐ• ํ”„๋กœ์ ํŠธ์˜ ๊ฐ€์žฅ ํฐ ์‹คํŒจ ์š”์ธ์€ ‘๊ธฐ์ˆ  ๋ถ€์กฑ’์ด ์•„๋‹ˆ๋ผ ๋ชฉํ‘œ ์ •์˜ ๋ถ€์กฑ ์ž…๋‹ˆ๋‹ค. ๋Œ€๋ถ€๋ถ„์˜ ํ”„๋กœ์ ํŠธ๋Š” ์ด๋ ‡๊ฒŒ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค. “AI ๊ธฐ๋ฐ˜ ์—”์ง„ ์ง„๋‹จ์„ ํ•˜๊ณ  ์‹ถ๋‹ค” “์›๊ฒฉ ๋ชจ๋‹ˆํ„ฐ๋ง์„ ํ•˜๊ณ  ์‹ถ๋‹ค” “์„ ๋ฐ• ๋ฐ์ดํ„ฐ๋ฅผ ๋ชจ์•„์„œ ๋ญ”๊ฐ€ ํ•˜๊ณ  ์‹ถ๋‹ค” “IMO ๋Œ€์‘์„ ์œ„ํ•œ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์‹œ์Šคํ…œ์„ ๊ตฌ์ถ•ํ•ด์•ผ ํ•œ๋‹ค” ํ•˜์ง€๋งŒ ์™œ ํ•„์š”ํ•œ์ง€ , ์–ด๋””๊นŒ์ง€ ํ•ด์•ผ ํ•˜๋Š”์ง€ , ์–ด๋–ค ROI๋ฅผ ๊ธฐ๋Œ€ํ•˜๋Š”์ง€ ๊ฐ€ ๋ถˆ๋ช…ํ™•ํ•œ ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ ๊ธฐํš ๋‹จ๊ณ„์—์„œ ๋ฐ˜๋“œ์‹œ ํ•ด์•ผ ํ•˜๋Š” ์ผ์€ ์„ธ ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค. ✔ 1) ๋ฌธ์ œ ์ •์˜ (Problem Framing) – ์ง€๊ธˆ ๋ฌด์—‡์ด ๋ถ€์กฑํ•œ๊ฐ€? – ๊ธฐ์ˆ ์ด ์‹ค์ œ ์–ด๋–ค ๋ถ€๋ถ„์„ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋Š”๊ฐ€? ✔ 2) ๋ฒ”์œ„ ์„ค์ • (Scope Design) – ์„ ๋ฐ• 1์ฒ™ ๊ธฐ์ค€์ธ์ง€, Fleet ์ „์ฒด์ธ์ง€ – ์‹œ์Šคํ…œ vs ํ”„๋กœ์„ธ์Šค vs ์žฅ๋น„ ์—ฌ๋ถ€ ✔ 3) ์„ฑ๊ณต ๊ธฐ์ค€ ์ •์˜ (Success Criteria) – ์–ผ๋งˆ๋‚˜ ํ–ฅ์ƒ๋˜๋ฉด ์„ฑ๊ณต์ธ๊ฐ€? – ๊ทœ์ • ์ค€์ˆ˜ ๊ธฐ์ค€์€ ๋ฌด์—‡์ธ๊ฐ€? – ๋น„์šฉ/ํšจ๊ณผ ๊ตฌ์กฐ๋Š” ์–ด๋–ป๊ฒŒ ๋˜๋Š”๊ฐ€? ์ด ๋‹จ๊ณ„์—์„œ ๊ธธ์ด ์ž˜๋ชป ์žกํžˆ๋ฉด ํ›„๋ฐ˜๋ถ€์—์„œ ๋ฐ˜๋“œ์‹œ ๋ฌธ์ œ๊ฐ€ ํ„ฐ์ง‘๋‹ˆ๋‹ค. ๐ŸŒŠ 2. ์„ค๊ณ„(Design) — ๊ธฐ์ˆ ...