Proposal

APrIGF 2026 Session Proposal Submission Form
Part 1 - Lead Organizer
Contact Person
Ms. Crystal Hsu
Email
Organization / Affiliation (Please state "Individual" if appropriate) *
Cisco Systems
Designation
Head, Government Affairs, Cisco Systems Taiwan
Gender
Female
Economy of Residence
Taiwan
Stakeholder Group
Private Sector
Part 2 - Session Proposal
Session Title
From Technical Debt to Strategic Liability: Artificial Intelligence, Cyber Resilience, and Internet Governance in the Asia-Pacific
Thematic Track of Your Session
  • Option

    • Primary: Digital Resilience and Building of Trust
    • Secondary: Digital Resilience and Building of Trust
Session Format
Panel Discussion (60 minutes)
Where do you plan to organize your session?
Online only (with onsite facilitator who will help with questions or comments from the floor)
Specific Issues for Discussion
On 22 June 2026, cybersecurity agencies of the Five Eyes nations jointly warned that frontier AI is shrinking the window between vulnerability discovery and exploitation from years to months — and that legacy, end-of-life (EOL) systems are no longer technical debt, but strategic liabilities. This session examines what that warning means for Asia-Pacific internet governance.

Governments and operators across the region face a compounding crisis: EOL devices, unpatched vulnerabilities, exposed services, and deferred lifecycle management silently erode digital resilience. As AI accelerates offensive capabilities, this infrastructure gap is no longer an IT problem — it is a governance failure with operational, financial, legal, and national security consequences.

The session examines this challenge through three lenses. First, threat intelligence: how state-sponsored adversaries exploit unmanaged infrastructure as primary entry points, and how AI compresses the time defenders have to respond. Second, internet infrastructure governance: practical lessons from managing Taiwan's network infrastructure on lifecycle management, IPv6 transition, and building resilience beyond compliance checklists. Third, criminal procedure: how legacy forensic systems, outsourced data recovery, and weak chain-of-custody protocols undermine digital evidence reliability — a legal risk long misclassified as a technical one.

The session concludes with a forward-looking discussion on post-quantum cryptography (PQC). With NIST standards finalized and quantum threats accelerating, the panel will examine what governance mechanisms — mandates, procurement rules, and regional cooperation — can drive migration before adversaries render today's encrypted infrastructure retroactively vulnerable.
Describe the Relevance of Your Session to APrIGF
直接貼入:

***
This session directly addresses APrIGF 2026's overarching theme — *"Safeguarding a Resilient Internet in Times of Crisis"* — by examining one of the most systemic yet undergovernanced threats to regional internet resilience: the accumulation of technical debt in critical infrastructure.

The session contributes to the Cybersecurity & Trust track by moving the conversation beyond incident response toward structural governance reform. Rather than addressing cyber threats reactively, the panel examines the upstream policy, legal, and technical conditions that make infrastructure persistently vulnerable — and proposes governance mechanisms to address them.

The discussions will produce concrete, actionable outcomes relevant to the Asia-Pacific multistakeholder community:

– For policymakers and regulators: a framework for mandatory EOL device retirement, procurement-based security requirements, and post-quantum cryptography migration timelines
– For technical operators: operational lessons on reducing attack surface, managing device lifecycle, and incident reporting design
– For civil society and legal communities: a critical examination of how infrastructure degradation undermines digital rights and judicial integrity — bridging a gap rarely addressed at internet governance forums
– For the broader region: a replicable model for multistakeholder collaboration on infrastructure resilience, drawing on Taiwan's experience as a case study under sustained threat

By integrating threat intelligence, infrastructure governance, and legal analysis into a single session, the panel reflects APrIGF's multistakeholder ethos and ensures that technical findings translate into policy-relevant outcomes — not just among specialists, but across government, industry, civil society, and the legal community.
Methodology / Agenda (Please add rows by clicking "+" on the right)
Time frame (e.g. 5 minutes, 20 minutes, should add up to the time limit of your selected session format) Description
5mins Introduction and scene setting by moderator (Crystal). Moderator frames the session around the Five Eyes 22 June 2026 joint warning on AI-accelerated threats and legacy infrastructure as strategic liabilities. Sets the three-lens structure for the panel.
7mins Speaker 1 — Joey Chen (Cisco Talos): Threat intelligence perspective. How state-sponsored adversaries exploit EOL devices and unpatched systems; how AI compresses defender response time.
7mins Speaker 2 — Rofan Yu (TWNIC CEO): Internet infrastructure governance perspective. Operational challenges of lifecycle management, IPv6 transition, and incident reporting in Taiwan and the broader Asia-Pacific.
7mins Speaker 3 — Aaron Lin (Taiwan Law and Society Association): Legal and criminal procedure perspective. How technical debt undermines digital evidence integrity and the admissibility challenges courts face.
4mins Moderator (Crystal Hsu): Policy synthesis and post-quantum cryptography outlook. What governance mechanisms — mandates, procurement rules, regional cooperation — can drive PQC migration.
5mins Prepared questions to panelists by moderator, including 1–2 live polling questions to online and in-person participants (e.g., "Does your organization have a documented EOL retirement policy?").
20mins Open floor Q&A. Moderator actively solicits input from online participants and ensures geographic diversity of contributors. Panelists respond.
5mins Final speaker points (one concrete governance recommendation per speaker) + facilitator summation and next steps.
Moderators & Speakers Info (Please complete where possible) - (Required)
  • Moderator (Primary)

    • Name: Crystal Hsu
    • Organization: Cisco Systems
    • Designation: Head of Government Affairs
    • Gender: F
    • Economy / Country of Residence: Taiwan
    • Stakeholder Group: Private Sector
    • Expected Presence: Online
    • Status of Confirmation: Confirmed
    • Link of Bio (URL only): https://www.linkedin.com/in/crystal-hsu-91604424/
  • Moderator (Facilitator)

    • Stakeholder Group: Select One
    • Expected Presence: Select One
    • Status of Confirmation: Select One
  • Speaker 1

    • Name: Joey Chen
    • Organization: Cisco Talos
    • Designation: Lead of Threat Intelligence
    • Gender: M
    • Economy / Country of Residence: Taiwan
    • Stakeholder Group: Private Sector
    • Expected Presence: Online
    • Status of Confirmation: Confirmed
    • Link of Bio (URL only): https://www.linkedin.com/in/joey-chen-0873a797/
  • Speaker 2

    • Name: Rofan Yu
    • Organization: TWNIC
    • Designation: CEO
    • Gender: F
    • Economy / Country of Residence: Taiwan
    • Stakeholder Group: Technical Community
    • Expected Presence: Online
    • Status of Confirmation: Confirmed
    • Link of Bio (URL only): https://www.linkedin.com/in/jofanyu/
  • Speaker 3

    • Name: Aaron Lin
    • Organization: Taiwan Law and Society Association
    • Designation: Secretary-General
    • Gender: M
    • Economy / Country of Residence: Taiwan
    • Stakeholder Group: Civil Society
    • Expected Presence: Online
    • Status of Confirmation: Confirmed
    • Link of Bio (URL only): https://junrulin.weebly.com/
  • Speaker 4

    • Stakeholder Group: Select One
    • Expected Presence: Select One
    • Status of Confirmation: Select One
  • Speaker 5

    • Stakeholder Group: Select One
    • Expected Presence: Select One
    • Status of Confirmation: Select One
Please explain the rationale for choosing each of the above contributors to the session.
This panel reflects the full governance chain of technical debt — from exploitation to policy to law.

Joey Chen (Cisco Talos) provides global threat intelligence on how EOL systems are actively weaponized by state-sponsored adversaries.

Rofan Yu (TWNIC) brings operational experience on infrastructure lifecycle management and internet governance across the Asia-Pacific.

Aaron (Taiwan Law and Society Association) addresses the legal consequences of technical debt — how legacy forensic systems undermine digital evidence in criminal proceedings, a dimension rarely examined at internet governance forums.

Crystal (Cisco Taiwan) moderates and synthesizes findings into policy recommendations, drawing on direct experience advising government on cybersecurity legislation.

Together, the panel spans private sector, technical community, internet governance, and civil society.
If you need assistance to find a suitable speaker to contribute to your session, or an onsite facilitator for your online-only session, please specify your request with details of what you are looking for.
We are seeking one additional panelist from outside Taiwan — ideally a government official, parliamentarian, or technical expert from another Asia-Pacific economy — who can contribute a regional or global perspective on technical debt, EOL infrastructure governance, or post-quantum cryptography policy. Preferred backgrounds include national cybersecurity agency, legislative or parliamentary committee experience in ICT/cybersecurity, or a regional internet governance body. We are open to participation in either in-person or remote format.
Has AI been used to develop this proposal?
Yes
How:
The submission form has unusually strict and inconsistent character limits per field, which made it extremely time-consuming to repeatedly compress and rewrite the content to fit.
Please declare if you have any potential conflict of interest with the Program Committee 2026.
No
Are you or other session contributors planning to apply for the APrIGF Fellowship Program 2026?
No
Upon evaluation by the Program Committee, your session proposal may only be selected under the condition that you will accept the suggestion of merging with another proposal with similar topics. Please state your preference below:
Yes, I am willing to work with another session proposer on a suggested merger.
APrIGF offers live transcripts in English for all sessions. Do you need any disability related requirements for your session? APrIGF makes every effort to be a fully inclusive and accessible event, and will do the best to fulfill your needs.
No
Number of Attendees (Please fill in numbers)
    Gender Balance in Moderators/Speakers (Please fill in numbers)
      Consent
      I agree that my data can be submitted to forms.for.asia and processed by APrIGF organizers for the program selection of APrIGF 2026.