TAIWAN Trends and Developments Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
nesses must notify the competent authority within one hour of discovery thereof and complete system dam - age control or recovery of the system within 36–72 hours, depending on the severity. Additionally, pub - lic companies are also obligated to disclose such incidents when they become material. Given these time-sensitive requirements, in practice, government agencies and the relevant companies expect their supply chain contractors to promptly provide infor - mation about any cybersecurity incidents affecting the organisation. Meanwhile, as well as for the purpose of complying with the incident reporting requirements, it is very important for a company to be alerted when its supply chain partner is being attacked, so that the company can take proper action to protect itself from cyber- attacks. Hence, it is important to include an incident reporting and response co-operation clause in the agreement with supply chain partners. In practice, to mitigate supply chain risks, these requirements are often passed down to contrac - tors through “flow-down” clauses in their contracts, ensuring compliance with regulations. Contractors are then obligated to report any cybersecurity information to the agency they work with. Many contracts also include the obligation to take proper security meas - ures to tackle a cybersecurity incident or attack. Audit right To ensure compliance with cybersecurity obligations, government agencies and certain private businesses will be periodically audited by the authority. In prac - tice, the regulator may also require a private supplier to audit its sub-contractor or supply chain partners. As a result, it is advisable to include audit rights in the relevant agreements. With regard to auditing, the competent authority may perform regular or unscheduled audits of cybersecu - rity maintenance plans, which, according to enforce - ment rules, must align with cybersecurity policies and objectives. Therefore, in practice, agencies frequently require their supply chain contractors to avoid actions that contradict these policies. Furthermore, to ensure compliance and effective enforcement of the contract,
agencies may also include audit clauses in their con - tracts with contractors. Liability allocation and cyber-insurance integration The CMA imposes administrative fines on private businesses that are designed as critical infrastruc - ture providers. Those who fail to comply may face several consequences. The competent authority can order them to rectify the issue within a specific timeframe; failure to do so can result in a fine rang - ing from TWD100,000 to TWD5 million. For reporting violations, the fine increases to between TWD300,000 and TWD10 million. As a result, it is likely that such businesses will include indemnification clauses in contracts, holding supply chain contractors responsi - ble for claims, losses, penalties and expenses arising from the contractor’s failure to comply with its obliga - tions under the contract. While not legally required, the FSC encourages com - panies to purchase cybersecurity insurance due to rising cyber threats. In practice, to allocate the risks, companies are often encouraged to acquire cyber- insurance that covers the property losses caused by cyber-attacks, computer extortion or the insured’s mismanagement, as well as liability for third-party compensation. International best practices NIST SP 800-161 National Institute of Standards and Technology (NIST) Special Publication 800-161, Revision 1 (the “NIST Framework”) incorporates existing NIST standards and international frameworks. It offers a comprehen - sive blueprint for managing the complex risks inher - ent in the global supply chain ecosystem for ICT and operational technology (OT), while helping enterprises understand and implement effective cybersecurity supply chain risk management (C-SCRM) practices. Some of the key provisions are as below: • C-SCRM in acquisition (including due diligence): The NIST Framework primarily focuses on the acquisition life cycle because enterprises rely heav - ily on commercial products and outsourced ser - vices for their business operations. Under the NIST Framework, enterprises are expected to develop and maintain a C-SCRM strategy and implementa -
411 CHAMBERS.COM
Powered by FlippingBook