Full Deployment of Self-Developed 'Titan'
Implementing Zero Trust Based on SASE
Plans to Expand to Banking and Securities Affiliates

Toss has discontinued the use of foreign security solutions and adopted its self-developed solution. It is unusual for a financial institution to replace foreign products by developing its own security solution. Moving forward, Toss plans to expand the adoption of its in-house solution across all affiliates, transitioning from reliance on foreign solutions to a system where the company designs its own security infrastructure.
According to a comprehensive report by this newspaper on the 10th, Toss recently applied its self-developed security solution 'Titan' (derived from “Toss Infrastructure Trusted Access Networking”) across the entire company. Toss has transitioned from the global security firm Zscaler's solution to Titan.
Toss plans to address any issues identified during Titan's use, enhance its functionality and stability, and then expand it to all affiliates, including Toss Bank, Toss Securities, and Toss Insurance.
Titan is a Security Access Service Edge (SASE)-based solution that integrates network and security functions to manage user and device access. It implements a 'zero trust' security framework that continuously verifies user identity and device status. Zero trust does not automatically trust employees or devices by default; instead, it verifies permissions and security status every time a system is accessed. As cloud and external service usage increases, the focus of security has shifted from protecting the boundaries between internal and external networks to repeatedly verifying users and devices.

Toss began in-house development after recognizing limitations in expanding functionality, handling failures specific to Toss, and cost efficiency while using foreign commercial solutions. They implemented private network access, internet access controls, device security checks, and data leak prevention independently.
Few financial institutions develop security solutions in-house due to the required expertise and operational burdens. Typically, financial firms adopt solutions developed by specialized security vendors and adapt them to their environments. In-house development demands substantial internal capabilities.
A security expert noted, “In-house development is considered when existing solutions fail to meet performance standards or lack necessary features. Toss, with its large development workforce, can build and deploy required systems internally. Additionally, the high costs of foreign solutions likely motivated their in-house approach.”
Toss's security investments have surged sharply. Last year, they invested approximately 19.3 billion KRW in information security—a 24% increase from the previous year.
The adoption of Titan marks Toss's shift toward internal control of core security domains. Beyond network security, Toss is expanding its self-developed security framework to include AI and software supply chain protections.
Challenges accompany in-house development. Toss must now directly manage solution development, maintenance, and failure response—tasks previously outsourced. Another security expert advised, “For Titan to stabilize, it requires quality verification comparable to commercial products, rigorous failure response protocols, and security checks for backup environments.”
A Toss representative stated, “We plan to evolve Titan into a security solution specialized for Toss's environment. Our goal is to swiftly respond to emerging threats through Titan.”