Legislative Acts

Cybersecurity Legislation and Issue Advocacy

Cybersecurity reform is not only a technical issue. It is a shared defense for digital resilience, supply-chain security, and digital human rights. Legislator Ju-Chun Ko argues that government should strengthen SME cybersecurity budgets while preventing anti-fraud measures from harming citizens’ digital rights.

Current progress45%

Legislative deliberation and budget advocacy underway.

The Silent War in Cyberspace

Warfare in the 21st century has changed. Conflicts between nations no longer occur solely on traditional battlefields; increasingly, they take place as a “silent war” in cyberspace. A single successful cyberattack can paralyze critical infrastructure, steal state secrets, disable financial systems, and shake societal trust through disinformation.

Escalating Global Cyber Threats

According to a 2024 report by Check Point Research, Taiwan is the most frequently attacked target in the Asia-Pacific region, suffering nearly 4,000 attacks per week on average. This is a direct reflection of geopolitics—Taiwan stands on the front line of democratic nations and serves as a primary target for external cognitive warfare and cyber penetration.

Attack vectors have grown increasingly sophisticated: evolving from traditional phishing and DDoS attacks into supply-chain attacks (compromising a single software vendor to affect thousands of clients), ransomware (encrypting mission-critical data for ransom), and AI deepfakes (generating highly deceptive fabricated videos and messages).

International Standards: GDPR and Digital Sovereignty

The European Union’s General Data Protection Regulation (GDPR) has become the global gold standard for privacy protection, granting individuals the right to be forgotten, data portability, and the right to object to automated decision-making. Simultaneously, facing potential backdoors and data leakage risks from foreign AI software, nations worldwide are establishing strict inspection and auditing mechanisms, treating cybersecurity as a core pillar of digital sovereignty.


Taiwan’s Vulnerabilities: Three Critical Breaches

While the government champions the slogan “Cybersecurity is National Security,” the actual defense system suffers from critical vulnerabilities.

Breach 1: The SME Cybersecurity Desert

There is a well-known principle in cybersecurity: a bucket’s capacity is determined by its shortest stave. Taiwan has 1.68 million small and medium enterprises (SMEs). They are indispensable links in global supply chains, yet hackers view them as the “shortest stave.”

Attackers often employ a stepping-stone strategy: breach vulnerable SMEs first, then pivot to infiltrate large corporations or government agencies. A prime example occurred in November 2025, when a Taiwanese digital marketing firm was compromised long-term by the Chinese hacking group APT24, impacting over 1,000 client domains.

Yet government investment in SME cybersecurity remains negligible. Current funding under the SME Cybersecurity Joint Defense Program averages only about NT$59 per company per year—less than the price of a lunch box, making effective defense impossible.

Breach 2: Structural Budget Imbalance

Taiwan’s cybersecurity budget suffers from a top-heavy imbalance: central agencies and major state-owned enterprises have ample funding for firewalls and Security Operations Centers (SOCs), but SMEs—making up 98% of all businesses—are left largely on their own.

Compounding the problem, the current budget operates on a single-year allocation model, hindering long-term planning. Cybersecurity is not a one-time software purchase; it is a long-term operational endeavor requiring continuous monitoring, regular drills, and ongoing updates.

Breach 3: Anti-Fraud Overreach Harming Digital Rights

In combating fraud, the government has required social media platforms to take down suspicious accounts en masse. While well-intentioned, execution has been deeply flawed. Due to the lack of rigorous review mechanisms and algorithmic transparency, many innocent citizens have had their accounts suspended without appeal, resulting in digital disenfranchisement.

When algorithms become blunt enforcement tools with unexplained logic and zero accountability, digital human rights and speech freedoms are severely compromised.


Legislator Ju-Chun Ko’s Reform Demands

Facing these structural vulnerabilities, Legislator Ju-Chun Ko has proposed a set of concrete legal and budgetary demands, summarized as “Fix the holes, build a stronger wall, and protect human rights.”

Secure Multi-Year Project Funding

In the Legislative Yuan’s 2025 general policy inquiry, Legislator Ju-Chun Ko demanded the Executive Yuan allocate multi-year cybersecurity project funding to significantly increase subsidies for SMEs. Specific requests include:

  • Raise the SME cybersecurity joint defense budget to at least 10,000 NTD per firm per year
  • Adopt multi-year (3–5 year) budget planning to enable long-term cybersecurity programs
  • Establish a cybersecurity insurance mechanism to share and mitigate risks across firms
Play

Defend Digital Human Rights: Four Concrete Measures

To prevent anti-fraud measures from becoming instruments of digital repression, Legislator Ju-Chun Ko proposed the following four measures:

  1. Establish a single complaint window: Citizens must have a clear, centralized appeals channel so government agencies can’t pass responsibility between ministries
  2. Publish regular statistics: Release monthly counts of account takedowns, appeals, and account reinstatements for public and parliamentary oversight
  3. Review algorithmic logic: Anti-fraud algorithms should be audited periodically, with error rates published and continuous improvements mandated
  4. Prohibit training on real user accounts without consent: Government or private actors should not train AI models on users’ real social media accounts without explicit permission

These measures emphasize that technological enforcement must respect human rights and avoid opaque algorithmic decisions.

Aligning Personal Data Laws with International Standards

Legislator Ju-Chun Ko also pushes for amendments to Taiwan’s Personal Data Protection Act inspired by GDPR:

  • Data portability: Citizens can request and receive an export of their personal data
  • Right to be forgotten: Under specific conditions, individuals can request deletion of their data
  • Right to object to automated decisions: Individuals subject to impactful automated decisions (e.g., loan or insurance decisions) can request human review

Aligning with international norms strengthens user protections and increases global interoperability.


Recent Major Cybersecurity Alerts

2025.03: CrazyHunter Ransomware Attacks

CrazyHunter ransomware targeted medical centers in Taiwan, encrypting systems and demanding ransom payments. The Ministry of Health and Welfare called it a “systematic attack,” underscoring severe vulnerabilities in hospital cybersecurity infrastructure that threaten patient records and the continuity of medical services.

2025.06: Chrome Distrusts Chunghwa Telecom Certificates

Google announced Chrome would no longer trust newly issued commercial certificates from Chunghwa Telecom due to certificate management noncompliance with international standards. This undermined national telecom credibility and highlighted the urgency of aligning infrastructure with global security practices.

2024.03: AI Deepfake Video Warning

Legislator Ju-Chun Ko played two AI-generated deepfake videos in the Legislative Yuan; Premier Chen Chien-jen could not distinguish them. The inquiry demonstrated that “seeing is no longer believing,” raising urgent demands for countermeasures.


Future Vision: Resilient Taiwan, Digital Security for All

Cybersecurity is not just a technical issue—it is a national concern that affects every citizen. Strengthening cybersecurity for SMEs and digital human rights enforcement will:

  • Fortify the supply chain: Strong SME defenses safeguard the entire industrial ecosystem
  • Promote digital equity: Robust appeals and transparent algorithmic practices protect citizens from arbitrary digital censorship
  • Protect national security: A secure and resilient cyber posture defends democratic institutions against foreign influence and attacks

Cybersecurity is national security—digital human rights are not negotiable. Support Legislator Ju-Chun Ko’s reform agenda to shield Taiwan in the silent war of cyberspace.

Resource Hub

Loading news topic...

Timeline

[General Inquiry] Cybersecurity Budget and Digital Human Rights

Legislator Ju-Chun Ko pointed out during the Legislative Yuan’s general policy inquiry that SME cybersecurity budgets are severely insufficient, and government anti-fraud measures may infringe on digital human rights. He demanded the Executive Yuan increase cybersecurity budgets and establish a single complaint window.

Play

[Supply Chain Attack] Digital Marketing Company Hacked

Taiwanese digital marketing companies were compromised long-term by Chinese hacking group APT24, affecting over 1,000 customer domains, exposing the extreme vulnerability of supply chain cybersecurity defenses.

[Trust Crisis] Chrome Stops Trusting Chunghwa Telecom Certificates

Google announced that Chrome browser would no longer trust newly-issued commercial certificates from Chunghwa Telecom, severely damaging the national telecom operator’s cybersecurity credibility and affecting government agencies and financial institutions.

[Healthcare Security] CrazyHunter Ransomware Rampage

Ransomware specifically targeting Taiwan attacked MacKay Memorial Hospital and other medical centers. The Ministry of Health and Welfare characterized it as a “systematic attack,” posing major threats to patient privacy and medical operations.

[General Inquiry] AI Fraud Deepfake Video Inquiry

Legislator Ju-Chun Ko played two AI-generated videos in the Legislative Yuan and asked Premier Chen Chien-jen to identify which was real. The Premier could not distinguish them. This highlighted the AI fraud crisis of “seeing is no longer believing” and demanded concrete government countermeasures.

Play

[Warning] Asia-Pacific Cyberattack Leader

Check Point Research reported that Taiwan is the most frequently attacked country in the Asia-Pacific region, suffering an average of nearly 4,000 attacks per week.