Taishin Securities merged with Yuan Fu Securities on April 6 this year, but subsequently experienced repeated electronic trading system outages, drawing widespread complaints from investors. On May 21, the Financial Supervisory Commission (FSC) announced a fine of NT$3.6 million against Taishin Securities—the highest penalty ever levied on a securities firm in Taiwan's history—along with a formal warning and restrictions on its financial operations.
The FSC determined that Taishin Securities clearly failed to implement proper internal control systems, and the incident has severely damaged investor confidence in financial institutions. After comprehensive assessment of Taishin’s subsequent handling of the situation, the FSC imposed the NT$3.6 million fine under Article 178-1, Paragraph 1, Item 4 of the Securities and Exchange Act. Additionally, a warning was issued under Article 66, Item 1 of the same law, and the company was ordered to take other necessary corrective measures under Article 66, Item 5.
In fact, system outages occurred not only on April 7, but also on April 14, April 20, and May 21. An investigation by the Taiwan Stock Exchange revealed multiple deficiencies at Taishin Securities, including failure to properly report cybersecurity incidents, system downtime exceeding the tolerable one-hour threshold, lack of data validation in programs, incomplete pre-deployment testing scenarios, failure to verify system changes post-deployment, absence of stress testing, incorrect software version deployment, inadequate business continuity planning, lack of business continuity drills, and insufficient monitoring of critical hardware and software—indicating a failure to enforce internal controls, in violation of Article 2, Paragraph 2 of the Securities Firms Management Rules.
Huang Hou-Ming, Deputy Director of the Securities and Futures Bureau, stated at a press conference that in addition to the warning and fine, the FSC has required Taishin Securities to implement multiple corrective actions. Until cybersecurity deficiencies are resolved, the firm must double its operational risk capital charge for capital adequacy ratio calculations. It must conduct a comprehensive review of system flaws and submit short-, medium-, and long-term system improvement plans within three months, potentially engaging cybersecurity consultants. These improvement measures and their implementation progress must be reported to the boards of both Taishin Securities and its financial holding company parent until full remediation is achieved.
Furthermore, Taishin Securities must commission a credible third-party cybersecurity professional institution to conduct verification and submit the verification report to the Taiwan Stock Exchange for forwarding to the FSC. It must also complete disciplinary actions against personnel responsible for the violations within three months and file the results with the FSC for record.
Huang emphasized that once a securities firm receives a warning under Article 66, Item 1 of the Securities and Exchange Act, its financial and operational activities will be restricted. For the next three months, it cannot apply to expand business lines or operations, establish new branches, make investments in related businesses, conduct cash capital increases or issue corporate bonds, or serve as an ETF liquidity provider or issuer of index investment securities (ETNs).
With the Taiwan stock market experiencing record-high trading volumes and increasing investor participation, securities firms' information systems are under growing pressure. Recently, other securities firms have also reported cybersecurity incidents due to system anomalies.
Huang stressed that stable information system operations and operational resilience are fundamental to investor protection and market trust, and must be prioritized by securities firms. They should continuously invest in system upgrades, capacity expansion, and cybersecurity enhancements to strengthen IT infrastructure, ensure stable trading operations, and improve operational resilience.
The FSC has already directed the Taiwan Stock Exchange to regularly convene meetings to enhance securities firms' trading system stability, discuss responses to recent cybersecurity incidents, and require all securities firms to sustainably allocate resources to information technology and cybersecurity to improve overall operational stability and cyber defense capabilities, promoting the healthy and sustainable development of the securities market.
FACT BOX
- Source: PR Times
- Category: News