Toss Replaces Foreign Security Solutions... Expands In-House 'Titan' to All Subsidiaries
Toss has invested 19.3 billion won in information security. This figure represents a roughly 24% increase from the previous year, demonstrating a significant expansion of security investment. Toss is expanding its in-house security framework to cover not only network security but also artificial in

Toss has invested 19.3 billion won in information security. This figure represents a roughly 24% increase from the previous year, demonstrating a significant expansion of security investment.
Toss is expanding its in-house security framework to cover not only network security but also artificial intelligence (AI) and software supply chains. Moving away from its previous reliance on external solutions, the company has transitioned to a structure where it directly detects and controls security threats starting from the stage where new services and technologies are introduced.
In-House 'Titan' Replaces Foreign Solutions
Toss's proprietary security solution, 'Titan,' was recently deployed across the entire company. Titan is an acronym for 'Toss Infrastructure Trusted Access Networking,' and it replaces the solution previously provided by global security firm Zscaler.
It was developed entirely by internal Toss personnel—including planners, security engineers, security researchers, and developers—with all stages from planning to development and operations handled in-house.
Titan is a SASE (Secure Access Service Edge)-based solution that integrates network and security functions to comprehensively manage user and device access. It implements a 'zero trust' framework that continuously verifies user identity and device status, protecting employees' work PCs from various security threats when they access the external internet.
Its primary roles include blocking external intrusions, controlling access to risky websites and programs, preventing company data leaks, and preemptively blocking attacks by leveraging the latest threat intelligence. Additionally, when accessing internal systems, it inspects the PC's security status to permit only authorized devices and restricts system access based on individual employee permissions.
By introducing Titan, Toss aimed to overcome the limitations it experienced with foreign commercial solutions, including functional scalability, incident response, and cost. The company independently implemented key features such as private network access, internet access, device security checks, and data loss prevention.
The advantages of in-house development include the ability to design security optimized for Toss's services and work environment, as well as the capacity for rapid improvement. When issues arise, the internal team can directly identify the cause, implement preventative measures, and add necessary features.
In-House Development, Rare in the Financial Sector
Cases of financial institutions developing their own security solutions are rare due to the significant burden of expertise and operations required. Most financial companies adopt solutions developed by external security firms and operate them to suit their own environments.
In-house development requires sufficient internal capabilities. Security experts explained that they consider developing solutions internally when existing products fail to meet required standards or lack necessary features. In Toss's case, a large development workforce enabled the company to build and use its own system, and the high cost of foreign solutions also motivated the in-house development.
Expanding to AI and Supply Chain Security
The adoption of Titan is part of Toss's broader effort to bring control of core security areas in-house. Starting with Titan, Toss is building an 'integrated data protection governance' framework by connecting individual security systems, such as its proprietary security framework, AI security guardrails, and supply chain firewalls. The scope of management is expanding beyond network access to encompass the processes where AI and external software connect to internal systems.
Security controls for AI services have also been strengthened. When internal AI services connect to external AI, they are routed through a separate gateway with applied security guardrails to prevent direct external connections. A system for diagnosing AI vulnerabilities prior to service launches has also been established. During the registration phase, the system automatically generates attack scenarios, diagnoses vulnerabilities, and produces a results report. Currently, prompt injection attacks are classified into 10 categories with 110 representative attack prompts.
Software supply chain security has also been reinforced. Toss has centralized the influx paths for external libraries and program packages, and new packages are subject to a seven-day grace period during which they are checked for malware in conjunction with external security databases. An average of approximately 60,000 packages are inspected daily. In fact, during a recent large-scale software supply chain attack, Toss blocked the inflow of malicious packages through its supply chain firewall, preventing damage to internal systems.
Planned Expansion to All Subsidiaries
Toss plans to expand the application of Titan to all of its subsidiaries—including Toss Bank, Toss Securities, and Toss Insurance—after further enhancing its functionality and stability.
Challenges of in-house development include the need to directly assume responsibilities previously outsourced to external experts, such as solution development, maintenance, and incident response. Security experts advised that quality verification on par with commercial products, thorough incident response, and security audits of backup environments are necessary.
A Toss official stated, "Our goal is to develop Titan into a security solution specialized for the Toss environment, enabling swift responses to new security threats."
CBC Globe publishes verified stories with editorial review, source checks, and tenant-specific publication standards.



