Cybersecurity 2026

TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

• maintaining a clear understanding of the service provider’s data usage, processing and control measures; • ensuring that customer data is distinctly segre - gated from the service provider’s own data as well as that of other clients; • guaranteeing that customer data processed by the service provider remains accessible to both the financial institution and the FSC upon request; • conducting regular examinations and supervision of the service provider’s operations, either through external audits or internal review processes; and • in the event of a foreign financial regulator seek - ing information concerning Taiwanese customers from the service provider, notifying the FSC and obtaining its prior approval before any disclosure is made. 3.6 Threat-Led Penetration Testing At present, there are no legislative frameworks explic - itly dedicated to penetration testing. However, publicly available information indicates that the FSC has previ - ously implemented a penetration testing plan as part of its cybersecurity assessment operations for banks’ computer systems. It appears that these penetration testing requirements are grounded in the FSC’s super - visory authority. The CSMA does not impose the same level of securi - ty-by-design obligations for specific ICT products and services as the Cyber Resilience Act (CRA) in the EU. That being said, the competent authorities of specific sectors have issues with product-focused guidelines. Specifically, the FSC has, mostly through co-operat - ing with the financial industry association, announced various cybersecurity rules governing financial institu - tions’ use of certain products and services. For instance, the Banking Association has stipulated several product/service-specific regulations, such as e-bank services, electronic signatures, mobile debit cards, internet of things (IoT) products and AI, in the Regulations Governing the Security Control of IoT Equipment Used by Financial Institutions. The Insur - 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

ance Association and the Security Association have established similar guidelines for various products/ services for their members to adopt. Additionally, pursuant to the authority granted by Arti - cle 42 of the Telecommunications Management Act, the NCC has issued the Technical Specifications for Cybersecurity Testing of Critical Telecommunications Infrastructure ICT Equipment, which were subse - quently amended by MODA (Cybersecurity Testing of Critical Telecommunications Infrastructure – CTCTI) to outline the technical standards for firewalls, switches and routers with ethernet interfaces installed at critical connection points (ie, those linking various core func - tions within critical telecommunications infrastructure, and those connecting critical telecommunications infrastructure with other operators’ public telecom networks) within facilities (critical telecommunications infrastructure equipment). 4.2 Key Obligations Under Legislation Exhibit 10 of Regulations on Classification of Cyber Security Responsibility Levels provides some require - ments for entities subject to the CSMA to ensure the integrity and the availability of their information sys - tems. For example, entities with a defence standard classified as “high” are required to implement at least the following control measures: • the cyber system should adopt automatic tools to monitor the access of communication flows and, if unusual or unauthorised activities are found, con - duct an analysis of such activities; • conduct an inspection of the integrity of software and information; • use integrity verification tools to detect any unau - thorised change of specific software and informa - tion; • examine the legitimacy of input data of users on the server terminal of the application system; and • if any violation of integrity is found, implement the security protection measures designated by the agencies. Financial Sector For the financial sector, the regulations issued by the FSC and relevant financial industry associations vary significantly across products and services. This vari -

401 CHAMBERS.COM

Powered by