| APrIGF 2026 Session Proposal Submission Form | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Part 1 - Lead Organizer | |||||||||||||||||||
| Contact Person | |||||||||||||||||||
| Ms. Crystal Hsu | |||||||||||||||||||
| Organization / Affiliation (Please state "Individual" if appropriate) * | |||||||||||||||||||
| Cisco Systems | |||||||||||||||||||
| Designation | |||||||||||||||||||
| Head, Government Affairs, Cisco Systems Taiwan | |||||||||||||||||||
| Gender | |||||||||||||||||||
| Female | |||||||||||||||||||
| Economy of Residence | |||||||||||||||||||
| Taiwan | |||||||||||||||||||
| Stakeholder Group | |||||||||||||||||||
| Private Sector | |||||||||||||||||||
| Part 2 - Session Proposal | |||||||||||||||||||
| Session Title | |||||||||||||||||||
| From Technical Debt to Strategic Liability: Artificial Intelligence, Cyber Resilience, and Internet Governance in the Asia-Pacific | |||||||||||||||||||
| Thematic Track of Your Session | |||||||||||||||||||
|
|||||||||||||||||||
| Session Format | |||||||||||||||||||
| Panel Discussion (60 minutes) | |||||||||||||||||||
| Where do you plan to organize your session? | |||||||||||||||||||
| Online only (with onsite facilitator who will help with questions or comments from the floor) | |||||||||||||||||||
| Specific Issues for Discussion | |||||||||||||||||||
| On 22 June 2026, cybersecurity agencies of the Five Eyes nations jointly warned that frontier AI is shrinking the window between vulnerability discovery and exploitation from years to months — and that legacy, end-of-life (EOL) systems are no longer technical debt, but strategic liabilities. This session examines what that warning means for Asia-Pacific internet governance. Governments and operators across the region face a compounding crisis: EOL devices, unpatched vulnerabilities, exposed services, and deferred lifecycle management silently erode digital resilience. As AI accelerates offensive capabilities, this infrastructure gap is no longer an IT problem — it is a governance failure with operational, financial, legal, and national security consequences. The session examines this challenge through three lenses. First, threat intelligence: how state-sponsored adversaries exploit unmanaged infrastructure as primary entry points, and how AI compresses the time defenders have to respond. Second, internet infrastructure governance: practical lessons from managing Taiwan's network infrastructure on lifecycle management, IPv6 transition, and building resilience beyond compliance checklists. Third, criminal procedure: how legacy forensic systems, outsourced data recovery, and weak chain-of-custody protocols undermine digital evidence reliability — a legal risk long misclassified as a technical one. The session concludes with a forward-looking discussion on post-quantum cryptography (PQC). With NIST standards finalized and quantum threats accelerating, the panel will examine what governance mechanisms — mandates, procurement rules, and regional cooperation — can drive migration before adversaries render today's encrypted infrastructure retroactively vulnerable. |
|||||||||||||||||||
| Describe the Relevance of Your Session to APrIGF | |||||||||||||||||||
| 直接貼入: *** This session directly addresses APrIGF 2026's overarching theme — *"Safeguarding a Resilient Internet in Times of Crisis"* — by examining one of the most systemic yet undergovernanced threats to regional internet resilience: the accumulation of technical debt in critical infrastructure. The session contributes to the Cybersecurity & Trust track by moving the conversation beyond incident response toward structural governance reform. Rather than addressing cyber threats reactively, the panel examines the upstream policy, legal, and technical conditions that make infrastructure persistently vulnerable — and proposes governance mechanisms to address them. The discussions will produce concrete, actionable outcomes relevant to the Asia-Pacific multistakeholder community: – For policymakers and regulators: a framework for mandatory EOL device retirement, procurement-based security requirements, and post-quantum cryptography migration timelines – For technical operators: operational lessons on reducing attack surface, managing device lifecycle, and incident reporting design – For civil society and legal communities: a critical examination of how infrastructure degradation undermines digital rights and judicial integrity — bridging a gap rarely addressed at internet governance forums – For the broader region: a replicable model for multistakeholder collaboration on infrastructure resilience, drawing on Taiwan's experience as a case study under sustained threat By integrating threat intelligence, infrastructure governance, and legal analysis into a single session, the panel reflects APrIGF's multistakeholder ethos and ensures that technical findings translate into policy-relevant outcomes — not just among specialists, but across government, industry, civil society, and the legal community. |
|||||||||||||||||||
| Methodology / Agenda (Please add rows by clicking "+" on the right) | |||||||||||||||||||
|
|||||||||||||||||||
| Moderators & Speakers Info (Please complete where possible) - (Required) | |||||||||||||||||||
|
|||||||||||||||||||
| Please explain the rationale for choosing each of the above contributors to the session. | |||||||||||||||||||
| This panel reflects the full governance chain of technical debt — from exploitation to policy to law. Joey Chen (Cisco Talos) provides global threat intelligence on how EOL systems are actively weaponized by state-sponsored adversaries. Rofan Yu (TWNIC) brings operational experience on infrastructure lifecycle management and internet governance across the Asia-Pacific. Aaron (Taiwan Law and Society Association) addresses the legal consequences of technical debt — how legacy forensic systems undermine digital evidence in criminal proceedings, a dimension rarely examined at internet governance forums. Crystal (Cisco Taiwan) moderates and synthesizes findings into policy recommendations, drawing on direct experience advising government on cybersecurity legislation. Together, the panel spans private sector, technical community, internet governance, and civil society. |
|||||||||||||||||||
| If you need assistance to find a suitable speaker to contribute to your session, or an onsite facilitator for your online-only session, please specify your request with details of what you are looking for. | |||||||||||||||||||
| We are seeking one additional panelist from outside Taiwan — ideally a government official, parliamentarian, or technical expert from another Asia-Pacific economy — who can contribute a regional or global perspective on technical debt, EOL infrastructure governance, or post-quantum cryptography policy. Preferred backgrounds include national cybersecurity agency, legislative or parliamentary committee experience in ICT/cybersecurity, or a regional internet governance body. We are open to participation in either in-person or remote format. | |||||||||||||||||||
| Has AI been used to develop this proposal? | |||||||||||||||||||
| Yes | |||||||||||||||||||
| How: | |||||||||||||||||||
| The submission form has unusually strict and inconsistent character limits per field, which made it extremely time-consuming to repeatedly compress and rewrite the content to fit. | |||||||||||||||||||
| Please declare if you have any potential conflict of interest with the Program Committee 2026. | |||||||||||||||||||
| No | |||||||||||||||||||
| Are you or other session contributors planning to apply for the APrIGF Fellowship Program 2026? | |||||||||||||||||||
| No | |||||||||||||||||||
| Upon evaluation by the Program Committee, your session proposal may only be selected under the condition that you will accept the suggestion of merging with another proposal with similar topics. Please state your preference below: | |||||||||||||||||||
| Yes, I am willing to work with another session proposer on a suggested merger. | |||||||||||||||||||
| APrIGF offers live transcripts in English for all sessions. Do you need any disability related requirements for your session? APrIGF makes every effort to be a fully inclusive and accessible event, and will do the best to fulfill your needs. | |||||||||||||||||||
| No | |||||||||||||||||||
| Number of Attendees (Please fill in numbers) | |||||||||||||||||||
| Gender Balance in Moderators/Speakers (Please fill in numbers) | |||||||||||||||||||
| Consent | |||||||||||||||||||
I agree that my data can be submitted to forms.for.asia and processed by APrIGF organizers for the program selection of APrIGF 2026. |
|||||||||||||||||||
I agree that my data can be submitted to forms.for.asia and processed by APrIGF organizers for the program selection of APrIGF 2026.