Cybersecurity 2026

TAIWAN Trends and Developments Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

to national cybersecurity laws and standards, while treating PRC-related ownership, manufacturing or technological dependencies as material risk factors in vendor selection, contract renewal, scope adjust - ment and termination decisions. Taken together, these regulatory regimes demonstrate a consistent and increasingly rigorous policy direction in which suppli - ers are no longer evaluated solely on cost, efficiency or technical performance, but also on their ability to: • support national cybersecurity objectives; • maintain transparent, resilient and verifiable supply chains; • comply with extensive audit and remediation obli - gations; • manage cross-border and geopolitical risks; and • align with Taiwan’s broader long-term strategy to reduce reliance on PRC-related technologies and strengthen overall information security governance across both public and private sectors. Common gaps in Taiwanese enterprises Amid growing regulatory and operational risks, Tai - wanese companies – particularly those in the technol - ogy manufacturing, finance, telecommunications and healthcare industries – face a new challenge: attacks are increasingly aimed at supply chains rather than individual companies. While Taiwan’s cybersecurity regulatory regime is still developing, enforcement patterns and incident investigations suggest that similar weaknesses exist in third-party and vendor-related cyber risk manage - ment. The three primary areas of weakness are: • insufficient vendor due diligence; • inadequate contractual cybersecurity protections; and • the absence of continuous monitoring mecha - nisms. If ignored, these vulnerabilities could expose compa - nies to regulatory fines, civil lawsuits and significant reputational damage.

Insufficient vendor due diligence A prevalent and impactful deficit among Taiwanese businesses is the failure to intensify cybersecurity due diligence when selecting vendors. In many organi - sations, the priority when selecting vendors, cloud providers, system integrators and managed service providers, among other things, remains cost, delivery timeline or technical expertise, rather than cyberse - curity preparedness. From a legal and regulatory standpoint, this is no longer acceptable. The CMA, together with a plethora of sector-specific regulations – most notably those concerning financial institutions, critical infrastructure providers and government contractors – imposes an obligation on regulated entities to ensure that third parties handling systems or data meet certain mini - mum cybersecurity standards. However, vendor assessment often amounts to high- level questionnaires or generic self-attestations, lack - ing substantive technical or governance analysis. Common weaknesses include not evaluating whether vendors: • apply appropriate access control and privilege management policies; • have established incident response and breach notification processes; • maintain commonly recognised information secu - rity certifications (eg, ISO/IEC 27001); or • subcontract further without appropriate transpar - ency. These weaknesses are particularly concerning given Taiwan’s role as a global supply chain hub. A flaw in an upstream supplier or managed service vendor can quickly propagate and impact countless downstream customers. Regulators are increasingly treating these failures not as isolated vendor problems but as shortcomings in the enterprise’s own risk management duties. For boards and senior management, poor vendor due diligence may therefore translate into governance and oversight concerns – particularly if cyber-incidents cause service interruptions or data breaches.

409 CHAMBERS.COM

Powered by