At CYBERSEC 2026 in Taiwan, cybersecurity vendors are moving beyond single-product performance and focusing instead on operational resilience — helping enterprises maintain business continuity during attacks rather than merely after them. The shift is driving demand for managed detection and response (MDR), supply-chain verification, and lifecycle security compliance as companies confront increasingly complex threats and tightening regulations such as the EU's Cyber Resilience Act (CRA).
Integrated defense takes center stage
Held May 5–7 at the Taipei Nangang Exhibition Center, the event highlighted how cybersecurity priorities are evolving from traditional threat blocking toward coordinated resilience strategies.
Zyxel Group, together with subsidiaries Black Cat Information, Zyxel Networks, and Zyell Solutions, showcased an integrated cybersecurity portfolio spanning penetration testing, AI-assisted defense, and protection for critical environments.
The group said the market is shifting away from isolated security products toward architectures that combine proactive detection with real-time response and recovery capabilities.
Management gaps fuel MDR adoption
Edward Yu, chief information security officer at Zyxel Group and general manager of Black Cat Information, said many enterprises have already invested heavily in security hardware and software but still lack the expertise needed to operate those systems effectively.
Yu noted that the core challenge is no longer access to tools, but the ability to convert large volumes of alerts into explainable and actionable incidents.
That gap has become a key growth driver for Black Cat's MDR business, now the company's fastest-growing segment. Customers include government agencies, research institutions, and high-tech manufacturers, among them the Legislative Yuan, Academia Sinica, and Taoyuan Metro.
Yu said these organizations have already established baseline cybersecurity infrastructure, but still require continuous monitoring, incident interpretation, and response support — rather than simply receiving alert notifications from security equipment.
EU CRA reshapes priorities
Regulatory pressure is also accelerating cybersecurity investment. Yu pointed to the EU's CRA, whose notification obligations will formally take effect on September 11, 2026.
He noted that the regulation reaches beyond manufacturers directly selling into Europe and increasingly affects the broader B2B supply chain.
Under previous frameworks, products mainly needed to pass testing requirements. The CRA, however, requires internationally recognized testing methodologies and reports issued by qualified laboratories, significantly raising compliance standards.
For Taiwan's export-oriented manufacturers, Yu said, compliance will directly determine whether products can continue entering the European market.
Many companies, he added, still underestimate the regulation's impact and view it mainly as an extension of compliance management or vulnerability patching. In practice, the CRA emphasizes security governance across the entire product lifecycle — from development and testing to maintenance and incident disclosure.
Yu expects the regulation to drive demand for product security certification, threat modeling, and software composition analysis.
To prepare for that shift, Black Cat has obtained TAF ISO/IEC 17025 certification and can issue internationally recognized ILAC MRA reports.
Supply chain risks move into focus
Supply-chain security has also become a growing concern for Taiwanese enterprises. Yu said companies increasingly recognize that even strong internal defenses can be undermined by vulnerabilities among suppliers or downstream partners, creating indirect exposure to cyber risks.
As a result, cybersecurity strategies are expanding beyond protecting internal systems to encompass the security posture of the broader ecosystem. That trend is stoking industry interest in continuous monitoring, security testing, and certification mechanisms.
AI seen as assistant, not replacement
Despite rapid advances in AI-driven security tools, Yu said AI still has significant limitations in real-world cybersecurity operations.
AI systems can generate large numbers of alerts, but remain less capable of correlating multiple signals into reliable, explainable incident assessments. In some cases, AI can also produce conclusions that appear reasonable despite being based on incomplete or inaccurate information.
Yu said AI's near-term value lies primarily in supporting human experts rather than replacing them. For example, Zyxel Networks uses AI to analyze massive volumes of packet data and identify anomalies that human analysts may overlook, while final judgments are still made by security professionals.
Regulation, MDR, and AI security to drive growth
Looking ahead over the next three to five years, Yu expects Taiwan's cybersecurity growth momentum to center on three major areas: regulation-driven product security certification, managed services like MDR, and secure AI deployment.
Yu added that sectors with the highest sensitivity to data protection and compliance — particularly financial services and healthcare — are likely to lead the institutionalization of AI security governance.
By contrast, broader horizontal AI cybersecurity applications are expected to face slower adoption due to operational complexity and reliability concerns.
Article translated by Willis Ke and edited by Jack Wu