TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
these objectives. In addition, under Article 6 of the CSMA, MODA is responsible for creating and pro - moting national cybersecurity policies, advancing cybersecurity technologies, encouraging internation - al co-operation and implementing comprehensive cybersecurity measures. Additionally, MODA must annually publish the National Cyber Security Status Report, and an audit summary report on cybersecurity maintenance plans, to enable all sectors to under - stand national cybersecurity trends. Information Exchange Article 9 of the CSMA dictates that MODA should set up a cybersecurity information sharing mechanism. The Cyber Security Information Sharing Regulations further provide that the competent authorities of the relevant industries should exchange cybersecurity information with the “specific non-government agen - cies” under their charge (Article 3 of the Regulations). For individuals, entities and organisations that are not subject to the CSMA, the competent authorities or MODA may also exchange cybersecurity information with them, provided that they have agreed in writing to comply with the requirements under the Regulations (Article 10 of the Regulations). In implementing the Regulations, and to establish the national-level Information Sharing and Analysis Center, (ISAC), computer emergency response team (CERT) and Information Security Control Center (SOC) in nine critical infrastructure domains, the Adminis - tration for Cyber Security under MODA has built a national information security joint defence system, which allows information sharing among govern - mental agencies and critical infrastructure providers. Additionally, some authorities of the industries, such as the National Communication Commission (NCC), also periodically hold training sessions and seminars to encourage companies to strengthen their informa - tion security. In addition to information sharing, MODA also pro - vides assistance to help agencies cope with cyber - security incidents and help the competent authority in charge of the relevant industry provide necessary support or assistance to help a “specific non-govern - ment agency” report or respond to a cybersecurity
incident, according to the Regulations for Reporting and Responding to Cybersecurity Incidents.
3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Previously, the FSC released the Financial Cyber Security Action Plan 1.0 to ensure the uninterrupted operation of financial systems, and Financial Cyber Security Action Plan 2.0 to enhance the financial institutions’ cybersecurity and secure a safe trading environment. On 30 December 2025, in alignment with the Nation - al Cybersecurity Strategy 2025 and to safeguard the continuous operation of financial systems, the FSC announced the Financial Cyber Resilience Develop - ment Blueprint. The Blueprint sets forth 29 targeted measures structured around a four-pillar framework: goal-driven governance, ubiquitous protection, eco - system collaborative defence and robust resilience. Its primary aim is to establish a financial ecosystem that is predictable, defensible and recoverable. The ten strategic highlights of the Blueprint follow. • Elevating governance and accountability: Estab - lishing a “triad of governance” (responsibility, authority and resources) for CISOs, the Blueprint strengthens the accountability chain and ensures independent decision-making. Furthermore, it grants CISOs the flexibility to implement proactive control measures in response to a rapidly shifting threat landscape. • Cultivating strategic talent: Shifting from a “one- size-fits-all” baseline to a strategic objective mod - el, the FSC will continually update the Financial Cybersecurity Talent Competency Map. Through cross-institutional forums and “theme-based” workshops, the industry will share best practices to move towards a “measurable, growth-oriented, and differentiated” framework. • Shift-left security and design: To minimise potential risks and remediation costs, the Blueprint advo - cates for shift-left security to integrate security
396 CHAMBERS.COM
Powered by FlippingBook