Major Taiwan semiconductor fabs ran a joint ransomware tabletop exercise Monday and Tuesday, simulating encryptors moving from compromised VPN accounts into manufacturing execution systems days before Golden Week staffing thins across Hsinchu Science Park and Southern Taiwan Science Park, according to organizers from the Ministry of Digital Affairs and industry group SEMI Taiwan.

Scenario

Participants—including packaging houses with U.S. export customers—walked through a fictional strain that pivoted from a phishing help-desk ticket to lateral movement on a file share touching recipe servers. The inject timed “encryption” to coincide with a night shift handoff, when many plants run half crews. Facilitators recorded how long operators took to isolate VLANs feeding lithography support tools versus office networks.

SEMI Taiwan said eight companies joined, covering advanced packaging, mask shops, and two foundry support vendors that asked not to be named. None of the drills touched live production controllers; red teams used mirrored environments maintained by the National Center for Cyber Security Technology (NCCST).

Findings

Debrief notes shared with InfoHandle show median detection at 47 minutes after simulated encryption began—fast enough to avoid fictional line stops in most plants, but slower than the 30-minute target several U.S. customers wrote into 2025 supplier questionnaires. Bottlenecks included on-call lawyers approving public statements before OT engineers pulled breakers.

Plants with centralized security operations centers in Taipei outperformed sites that still route alerts to local maintenance pagers. Two participants discovered backup jobs were not excluded from simulated encryptor paths, a configuration issue common in hybrid IT/OT estates.

Holiday risk

Golden Week leaves fabs with reduced IT headcount while customer pull-ins continue for smartphone launches. Organizers urged plants to pre-stage offline gold images for critical recipe servers and to test remote wipe policies on contractor laptops before travel bans expire.

Industrial Development Administration officials attended as observers, collecting anonymized metrics for a forthcoming sector resilience scorecard. They did not announce subsidies but said insurers are asking for drill attestations during renewals.

Limits

The exercise did not cover supply-chain firmware attacks or insider threats. Attribution and law-enforcement coordination were tabled for a fall session. For fabs, the takeaway is procedural: holiday skeleton crews can contain ransomware only if OT isolation steps are pre-approved, not debated on a chat app at 2 a.m.

Customer pressure

Two participants said U.S. handset customers asked for drill summaries before approving September wafer starts. Customer security questionnaires now request mean time to isolate OT segments, not only backup restoration times—a metric fabs rarely tracked before 2024 incidents abroad.

NCCST offered to host quarterly replays for vendors too small to maintain their own ranges. SEMI Taiwan will publish a sanitized playbook after Golden Week, redacting plant names but listing VLAN templates that worked.

Reporting chain

MODA officials said incidents during the exercise would have triggered notifications to the Administration for Cyber Security within four hours under current rules. Several fabs admitted their runbooks still list fax numbers for county police; facilitators recommended updating contacts to the national cyber hotline.

Encryptor payment policies remain unchanged: organizers told executives not to treat Bitcoin wallets as a business continuity step. Legal teams practiced preservation notices for chat logs where engineers debated whether to pull breakers—a debate that consumed 18 fictional minutes in one scenario.

Insurance underwriters attending the debrief asked for video attestations; fabs declined, citing customer NDAs. Underwriters said they would accept signed CISO letters if drill metrics improve next quarter.

OT segmentation

Facilitators scored plants on whether recipe servers could be air-gapped within 15 minutes without shutting down ion implanters—a bar only half the participants met. Several fabs said legacy serial links between metrology PCs and tools cannot be re-VLAN’d without vendor sign-off, pushing fixes into 2027 capital plans.

MODA urged companies to document those vendor dependencies in supplier risk registers before year-end audits. SEMI Taiwan will host a follow-on clinic on safe shutdown sequences so maintenance crews do not treat ransomware injects as routine power blips.

None of the participants triggered real customer line stops during the drill, but two delayed test wafer lots by a day to validate backups—an acceptable trade, executives said, compared with gambling on untested restores during Golden Week.