INSIGHT
Cybersecurity in practice: How PTS Taiwan protects public media and builds resilience
13 August 2026
How is PTS Taiwan strengthening cybersecurity, information integrity and trusted communication in a high-risk environment?

By Dennis Chen, Vice President of Engineering, IT, and Production, Public Television Service (PTS) Taiwan
Taiwan’s geopolitical position, highly connected digital environment and exposure to cyber and cognitive threats make resilience a core public-media responsibility. At PTS, cybersecurity has evolved from an IT concern into an institutional capability linking governance, technology, continuity, editorial verification and public trust.
For PTS, operating in Taiwan means planning for situations in which a cyber incident, physical disruption and information manipulation may happen at the same time.
Over the past few years, we have gradually changed the way we manage cybersecurity. It is no longer just an IT issue about keeping hackers out of office computers. It is about making sure that when our systems, networks, or wider media environment come under heavy pressure, the public can still receive trusted information without disruption.
To get there, our leadership team had to confront a few practical realities:
- Some of our core broadcast and newsroom platforms are older and need modernisation.
- Real cybersecurity demands dedicated budget and specialised in-house talent.
- Policies and risk assessments can’t sit in a binder—they have to adapt constantly as technology and threat tactics evolve, especially when we are managing legacy systems without sacrificing security.
For a long-established broadcaster, some of our most difficult cybersecurity risks come not from the newest threats, but from the oldest systems still required for daily operations. Broadcast and production platforms are built to last for years.
Building security at PTS hasn’t been about creating an invincible fortress. It’s about building a reliable organisation that can take a hit, adapt quickly, keep the signal alive, and deliver accurate news when the public needs it most.
Eventually, though, you hit a point where an operating system is no longer supported, patches don’t exist, or updating a software module risks crashing specialised hardware during a live production.
Listen: How CBC/Radio-Canada manages cyber security threats
We cannot always rip and replace these legacy systems overnight. Instead, we build strict guardrails around them. For us, the practical question is often not whether an old system should be replaced—we already know it should—but how to protect it safely while it is still required for daily broadcasting.
First, we rely heavily on network segmentation. Older or sensitive systems are completely isolated from our general corporate intranet and placed in restricted zones. Only authorised operators on specific workstations can access them, and we lock down communication ports to the bare minimum needed for daily broadcasting. If a general office device gets compromised, the attacker cannot easily jump sideways into our critical control rooms.
Second, where data only needs to flow one way, we deploy data diodes (unidirectional gateways). These are hardware-enforced barriers that physically prevent data from traveling backward. Even if an external system is compromised, it cannot send malicious commands back into our protected broadcast network.
These architectural controls are compensating measures, not an excuse to hoard obsolete gear. We remain committed to upgrading our tech stack, but while legacy equipment is still required on air, we make it as hard to reach and as easy to monitor as possible.

Continuous Risk Governance and Layered Defence
No security setup is completely bulletproof, so we don’t rely on a single line of defence. We regularly run vulnerability scans, penetration tests, and asset inventories so we always know what technology is running, where it sits, and who manages it.
Our operational resilience relies on three distinct layers:
- People: Staff awareness is not a annual compliance checkbox — it is an ongoing habit. We enforce strict policies around removable media like USB drives, run unannounced phishing simulations, and restrict system permissions strictly based on job roles.
- Data: We enforce a strict multi-tiered backup model across three different media types. This includes two off-site backups and an active hot-site capability so we can recover data even during a catastrophic failure.
- Transmission: Restoring servers is useless if you can’t broadcast. To guarantee signal continuity, we maintain mobile Satellite News Gathering (SNG) trucks as a fallback. If fixed terrestrial links or main control facilities go down, we can mobilise and re-establish a broadcast signal from alternative locations.
We cannot always rip and replace these legacy systems overnight. Instead, we build strict guardrails around them. For us, the practical question is often not whether an old system should be replaced – we already know it should – but how to protect it safely while it is still required for daily broadcasting.
The Frontline Reality: Cyber Threats Meet Information Manipulation
In Taiwan, cybersecurity planning increasingly has to consider the possibility that a cyber incident may occur alongside information manipulation. A technical disruption can affect not only system availability, but also create an opportunity for false or misleading information to spread.
Recent analysis from Taiwan’s National Security Bureau highlights how fast this landscape is shifting. Between 2023 and 2024, manipulated or disputed online activity surged across major platforms—rising 40% on Facebook, 151% on video platforms, 244% on X, and a massive 664% on online discussion forums. Subsequent 2025 assessments tracked over 45,000 abnormal accounts and 2.31 million pieces of contentious content, heavily driven by AI-generated audio/video deepfakes and hijacked legitimate social media accounts.
This changes what we have to protect. The goal of an attacker isn’t always to wipe a server—sometimes it’s to hijack our brand, spread fake announcements, or trick the public into doubting official news sources altogether.
Our Second Security Perimeter: Information Integrity and AI Verification
Because of this, we treat information integrity as a second line of defense. We aren’t interested in producing counter-propaganda; our goal is simply to ensure that when crisis strikes, citizens can instantly verify what is real and trust what comes from PTS.
To support our newsroom, we are building NewsLLM—an AI-assisted news verification tool trained on decades of Traditional Chinese news archives, transcripts, and verified reporting from PTS and partner public media outlets.
Subscribe toour newsletter
Keep updated with the latest public
media news from around the world
Disinformation often relies on recycled context—re-using old photos from years ago, misquoting past government policies, or altering the timeline of a real event. By making our massive historical archive semantically searchable through a domain- specific Large Language Model, journalists can quickly cross-check fresh claims against documented history.
Crucially, NewsLLM is designed with hallucination detection and strict evidence-checking features. If the historical data is inconclusive, the AI does not guess; it flags the uncertainty and points journalists back to verified primary sources. The human editor remains entirely in control of the final story.
Grounding Resilience in Public Trust
You can buy firewall hardware and install backup software, but you cannot patch or replace public trust once it is lost.
That is why keeping our newsroom editorially independent remains paramount. As PTS integrates more deeply into Taiwan’s national critical infrastructure and cybersecurity frameworks, we ensure those technical protocols never infringe on our journalistic autonomy. A broadcaster that is technically secure but politically compromised cannot fulfil its public service mandate.
Building security at PTS hasn’t been about creating an invincible fortress. It’s about building a reliable organisation that can take a hit, adapt quickly, keep the signal alive, and deliver accurate news when the public needs it most. In an era of digital uncertainty, maintaining a steady, trustworthy stream of public information is one of the most vital forms of democratic defence we have.
About the author

Dennis Chen is a senior executive with over 30 years of experience in strategic planning, digital transformation, and organisational leadership, having successfully driven change across the financial services, technology and media sectors. With a proven track record as a CIO for a major financial holding group, VP for Public Media and other private enterprises, Dennis has led multi-million dollar core system migrations and enterprise-wide digitalisation initiatives that delivered measurable business outcomes. Dennis brings a blend of regional operational experience and a passion for nurturing next-generation technology and talent.
Related Posts
11th December 2025
Data privacy and national security the top concerns for PSM in AI procurement
A new industry report explores how…

