Cybersecurity 2026

TAIWAN Trends and Developments Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

Inadequate contractual cybersecurity protections Vendor agreements too often fail to adequately address basic cybersecurity expectations, leaving organisations dangerously exposed to potential data loss. Without explicit provisions, organisations have difficulty enforcing standards or seeking damages in the wake of a violation. Common contractual impediments include: • no definition of security baselines; • no mandatory incident reporting timelines; • no audit rights; and • unclear subcontractor liability. Even if the cause of a breach is traced back to a ven - dor, enterprises are in many cases left “holding the bag” under the PDPA. It is difficult to recoup losses from a vendor without strong contracts. In 2026, best practices dictate a risk-based approach where contracts are tailored to the sensitivity of the service. Cybersecurity clauses are now essential risk allocation tools, not merely boilerplate Absence of continuous monitoring mechanisms Many Taiwanese enterprises appear to consider vendor risk assessment as a one-time process dur - ing onboarding, barring major incidents. This static approach is increasingly at odds with the dynamic nature of cyber threats. In fact, a vendor’s cybersecu - rity posture may decline over time due to staff turno - ver, system upgrades, financial strain or outsourcing decisions. Enterprises risk being unaware of new vul - nerabilities until they are exploited if they do not have an effective monitoring system in place. Typical deficiencies observed in this area include: • no re-evaluation of the security controls of the ven - dor at any interval; • no incident-reporting drills or tabletop exercises with vendors; • no monitoring of adherence to contractual security requirements; and • the absence of a centralised governing body for third-party cyber risk.

Supervisory authorities are increasingly adopting a continuous assurance model. Drafting contractual terms is not sufficient – organisations must demon - strate active enforcement. Regular reporting of vendor risk metrics is necessary for directors to meet their fiduciary responsibilities and avoid accusations of One of the important tools to tackle cybersecurity risk is to include cybersecurity-related clauses in con - tracts to be signed with the supply chain partners. In addition, as said, government procurement con - tracts in Taiwan usually include provisions requiring the suppliers to comply with the same cybersecurity obligations that the procuring agencies are subject to under Taiwan law. To ensure compliance, suppliers may need to consider including the same obligations in the agreements with its upstream partners. The fol - lowing are some of the clauses that companies may consider adopting in their contracts. Minimum-security baselines While there is no universally adopted or official defi - nition for a “minimum-security baseline”, several authoritative organisations have published standards and certifications that serve this purpose. In Taiwan, for instance, all public companies are required to obtain cybersecurity management compliance cer - tifications, including the CNS 27001 national stand - ard or the international ISO/IEC 27001 standard. This requirement extends to certain sectors, such as tel - ecommunications. neglect in risk oversight. Contracting strategies To meet these compliance standards, many companies impose contractual obligations on their supply chain partners to maintain a cybersecurity baseline as well as take specific actions. These often involve security assessments and cybersecurity health checks, such as vulnerability scans and checks for malicious activ - ity, conducted at least once every two years. Addition - ally, companies may mandate the implementation of cybersecurity defences and the regular updating or upgrading of relevant software and hardware. Incident report and response co-operation clauses Under the CMA, whenever there is a cybersecurity incident, government agencies and certain other busi -

410 CHAMBERS.COM

Powered by