In response to repeated system failures following the merger between Taishin Securities and Yuan Fu Securities, Taiwan's Financial Supervisory Commission (FSC) announced severe penalties today (21st). Due to inadequate pre-merger system planning and insufficient stress testing and drills, the integration led to major information security deficiencies. As a result, the FSC has imposed a record NT$3.6 million fine—the highest ever levied on a securities firm—along with a formal 'warning' and a requirement to double its operational risk capital charge.

Officials revealed that Taishin Securities' capital adequacy ratio will drop from 318% to 264%. For the next three months, the firm will face comprehensive restrictions on business development, including being barred from serving as an ETF liquidity provider or applying for new business lines or operational expansions.

According to in-depth audits by the Taiwan Stock Exchange (TWSE) and FSC data, Taishin failed to properly plan system integration prior to the merger, resulting in repeated electronic trading system outages on April 7, April 14, April 20, and May 21. Each outage exceeded the acceptable one-hour tolerance threshold.

The TWSE audit report identified ten major deficiencies, including: failure to report cybersecurity incidents, lack of data validation in programming, incomplete pre-launch testing and stress scenarios, incorrect program versions, inadequate business continuity planning (BCP), and insufficient monitoring of critical software and hardware.

Huang Hou-Ming, Deputy Director of the Securities and Futures Bureau, disclosed that the four system failures collectively caused 9,321 erroneous transactions involving a total trading value of NT$2.011 billion. The TWSE had previously imposed cumulative penalties of NT$3.31 million on Taishin (including breach penalties and late fees). Among the affected investors, 154 have filed complaints with the Financial Dispute Resolution Center. After proactive mediation by Taishin, nine cases remain in formal review, where investors claim losses due to 'inability to place timely orders or execute stop-losses.'

This penalty marks the highest fine ever issued to a securities firm for cybersecurity violations. Huang explained that regulatory penalties are consistently applied. Compared to Cathay Securities, which was fined NT$1.5 million in August 2023 for two days of system outages, Taishin’s incidents were more frequent and affected a significantly larger scale and transaction volume. However, considering Taishin’s post-incident efforts in resolving client disputes and mitigating investor losses, the FSC ultimately set the fine at NT$3.6 million—below the statutory maximum of NT$6 million.

In addition to the fine, the FSC invoked Article 66, Paragraph 5 of the Securities and Exchange Act to impose a series of strict supervisory measures. Most notably, Taishin must double its operational risk capital charge until all cybersecurity deficiencies are rectified. Based on June-end data, officials estimate that this doubling will cause Taishin’s capital adequacy ratio to fall from 318% to 264%.

Since the capital adequacy threshold for securities firms applying to issue ETNs is 250%, the drop to 264% brings Taishin close to the danger zone. If market volatility further reduces its capital ratio, Taishin may be forced to raise capital through equity issuance or corporate bond offerings.

The 'warning' penalty also restricts Taishin’s financial and business expansion for the next three months. It cannot apply to open new branches, make equity investments, conduct cash capital increases, issue corporate bonds, launch ETNs, or serve as a liquidity provider for newly issued ETFs.

The FSC has also ordered Taishin to submit a concrete short-, medium-, and long-term improvement plan within three months, commission a reputable third-party cybersecurity auditor for verification, and discipline responsible internal personnel, reporting the outcomes to the FSC.

The FSC emphasized that with recent record-high trading volumes in the Taiwan stock market, system stability and operational resilience are foundational to market integrity. All securities firms must prioritize IT system upgrades and cybersecurity enhancements, and must not compromise trading safety during mergers or expansion efforts.

FACT BOX

  • Source: PR Times
  • Category: News