cookieOptions = {...}; 🏭 最高機密不在設備表:高科技廠房真正要管的是「人、事、時、地、物」(中) - 3S Market「全球智慧科技應用」市場資訊網

3S MARKET

3S MARKET
2026年9月9日 星期三


3S Market 探討報導


最高機密不在設備表:高科技廠房真正要管的是「人、事、時、地、物」(中)

從竊密、內賊、資產失竊到 OT 停線,看高科技廠房安控為什麼不能只靠設備

如果把一座先進晶圓廠的安控設備全部列成一張表,或許可以看到門禁、入侵偵測、對講、影像監控、生物辨識、訪客管理、感測、事件平台等一大串系統。

但即使拿到這張表,仍然未必知道這座廠房究竟安不安全。

因為高科技廠房真正令人頭痛的安全事件,往往不是電影裡戴著黑帽的陌生人翻牆闖進來,而是另一種更棘手的情況:進來的人本來就有資格;使用的帳號本來就是真的;出現在廠區也有理由;操作的設備甚至就是公司自己的。

問題只在於 —— 他做的事情,已經離開原來被授權的範圍。

這也是為什麼,高科技廠房的安全若要濃縮成一套最基本的管理邏輯,可以從五個字開始:人、事、時、地、物

誰進來?來做什麼?什麼時間?到哪裡?接觸或帶著什麼東西?真正的安全事件,往往就是這五件事其中幾項開始「對不起來」。

而高科技產業更有三條不能失守的底線:

技術不能外流、產線不能失控、營運不能中斷。

近年發生在台灣半導體與高科技產業的一連串事件,正好把這三條線完整地攤開來看。


一、最難防的人,可能本來就有權進來


2026 年 8 月,新北地檢署起訴一名南亞科技資深工程師。

依檢方調查,這名工程師在準備離職期間,曾三度利用假日夜間或凌晨進入公司,並把運動攝影機夾藏在零食中避過安檢;進入辦公室管制區後,再使用自己的帳號登入公司虛擬主機,大量讀取核心製程相關文件並翻拍,檢方認定取得 32 項涉及營業秘密的照片檔。

這個案例幾乎像是特別替「人、事、時、地、物」設計出來的教材。

不是外人,而是公司資深工程師。

本來具有工作上的系統使用需求,但「有資格使用」並不等於可以為其他目的大量取得核心資料。

假日、夜間、凌晨。

辦公室管制場域。

被藏進零食中的攝錄設備。

任何一項單獨看,都未必能直接判定有問題;但是當它們組合在一起:

準備離職的員工+非常態工作時間+管制區+攜入攝錄設備+大量讀取核心製程資料

安全意義就完全不同。

所以高科技廠房第一個必須突破的觀念是:

Identity 只能證明「你是誰」,不能證明「你現在做的事情是合理的」。

一張有效的員工證,只代表身分仍然成立;它不是一張「完全可信任」的通行證。

這也是為什麼員工調職、專案結束、承包商換約、離職前後等生命週期變化,都應該與 Physical Access、Virtual Access、資料權限同步思考。不是把即將離職的人都當成嫌疑人,而是重新確認:原來給他的權限,今天還有沒有業務上的必要?


二、高科技產業最像諜報電影的故事:偷走的東西根本看不見


如果說南亞科案件已經很有電影感,2025 至 2026 年台積電先進製程營業秘密案件,則把高科技產業最敏感的一面推到更高層次。

案件起於台積電發現內部異常並報案。檢方調查,一名前台積電工程師離職後,進入設備供應商東京威力科創,為改善設備表現與爭取更多先進製程設備機會,多次要求仍在台積電工作的工程師,提供關鍵技術資料,相關內容涉及 14 奈米以下製程、關鍵氣體、化學品,及設備技術等營業秘密。2026 年案件陸續判決,其中前台積電工程師陳力銘被判 10 年,最高法院於 7 月駁回上訴而定讞。

這類案件最值得注意的,不是「有人闖入資料中心」。

恰恰相反,資訊的取得可能發生在,看起來非常普通的工作環境:

  • 工程師向工程師詢問技術。
  • 設備商希望改善設備。
  • 在職員工本來就具備部分資料存取資格。

真正發生改變的是:

原本合法的 Access,被拿來執行未經授權的 Activity。

而且資料不像一台機器。機器不見了,很快就能看到空位。資料卻可以在原件完全還在的情況下,被複製出第二份、第三份甚至無數份。

因此,高科技廠房裡價值最高的「物」,可能根本沒有重量。

製程參數、設備調校方法、材料配方、設計規則、良率改善方法、客戶資料、研發結果,都屬於 Information Asset


三、900 多份檔案、USB、私人雲端、離線筆電:資料到底怎麼「走出」工廠?


如果要找一個更完整呈現資料外流路徑的經典案例,Micron、UMC 與福建晉華的 DRAM 營業秘密等的案件,非常值得回顧。

美國司法部 2018 年起訴資料指出,一名離開 Micron 台灣子公司的員工,在離職前,下載超過 900 份 Micron 機密與專有檔案,並將資料存放在 USB 外接硬碟或私人雲端空間。後續調查還發現 Micron 的智慧財產出現在 UMC 電腦上;美國司法部資料更指出,當 UMC 的 IT 部門發現相關資料後,曾核發兩台「off-network」筆電,使員工可在未被公司 IT 系統,進一步偵測的情況下,存取相關機密資料。2020 年 UMC 在美國就營業秘密竊取罪認罪,並同意支付 6,000 萬美元罰金。

如果把這個案子的安全路徑拆開,就會發現它早已超過,任何單一安控系統能夠回答的範圍:

員工身分→ 系統登入→ 檔案下載→ USB/外接硬碟→ 私人 Cloud→ 公司外設備→ 離線電腦→ 新的工作環境

Physical Security 如果只知道:「這名員工今天有進公司。」而這幾乎沒有意義。

Cybersecurity 如果只知道:「帳號登入成功。」而這也不夠。

真正的問題是:

這個人,為了這個工作,在這個時間,有沒有合理的理由,取得這麼多資料,又為什麼需要把這些資料送到這個 Device 或 Storage?(這就涉及了程序問題)

高科技廠房因此必須開始把:

Identity、Authority、Data、Device、Physical Access、Virtual Access

放進同一套風險邏輯。

這時可能用到的工具就不只傳統安控,也包括 Least Privilege、PAM、DLP、USB/可攜媒體管制、端點安全、異常大量下載分析等。

但工具仍然排在程序後面。

最先該回答的是:

公司的 Crown Jewels 到底是什麼?誰真正需要接觸?正常工作情況下應該怎麼接觸?


四、有權進廠,不代表有權把東西載出去


資訊資產看不見,但高科技廠房也會遇到最傳統、最直接的實體竊盜。

2026 年台積電嘉義先進封裝廠工地,發生一宗很值得研究的案件。

法院與檢方公開資料顯示,涉案者本身就是下游承包商與員工,利用可以進出工地的身分,多次在廠區竊取電纜;案件涉及超過 4.5 公里的電纜線,銷贓金額近 500 萬元。最後一次犯案時,貨車以「進入工地搬運工具」為由,取得放行;共犯躲在車斗內,進場後剪取電纜,遭保全發現後甚至撞毀閘門逃逸。2026 年 7 月法院一審分別判處主要涉案人員 4 年至 4 年 8 月徒刑。

這是一個非常典型的 Authority Gap,涉案者並不是「無權進入」。

問題是:

有權進入工地,不代表有權執行進場後的每一個行為。

保全看到的是:「這是一個熟悉的承包商。」

門禁看到的是:「這個 Credential 有效。」

但真正的安全管理,還必須知道:今天為什麼進來?

有沒有 Work Order?誰跟他一起進來?車上本來有哪些人?帶入哪些工具?正常情況下應該帶什麼出去?

這就是「事」。

真正成熟的 Contractor Management,應該逐漸把:

人員 → 工作單 → 施工區 → 時段 → 車輛 → 工具與材料 → 完工 → 離場 串成一次完整作業。

否則安全系統最多只能說:「他進來了。」

卻回答不了:「他進來以後,本來應該做什麼?」


五、京元電測試板失竊:有時不是保全先看到,而是「數據先不對」


另一宗值得注意的案例,發生在京元電子竹南廠。

2026 年 1 月,公司公開說明,一名工程師涉嫌竊取測試 IC 使用的電路板、光纖線等設備。真正值得關注的是,公司表示最初是發現測試電路板登錄系統數據異常,才啟動內部專案調查;之後再透過盤點,與相關影像紀錄確認嫌疑人。公司表示遭竊物品已追回超過八成,未造成技術機密外洩,也未影響公司營運。

這件事情提供了一個很好的提醒:

有效安控不一定是某一個設備在犯罪當下「抓到人」

有時真正先發現問題的,是 Asset Database

庫存不對。

一塊測試板應該在,卻不在。或一項資產的系統狀態和實際盤點對不起來。這時才開始往回查:

誰有接觸?什麼時間?在哪裡?是否經過出口?相關工作紀錄是什麼?必要時,再調用影像作為 Evidence。

於是 Traceability 的真正價值就浮現出來:

Asset Data + Identity + Access Log + Time + Event Record + Evidence

而不是把所有期待都丟給某一套設備。


六、晚上兩點和下午兩點,對安全來說真的一樣嗎?


再回頭看南亞科案件。

夜間或凌晨進公司,在 24 小時運轉的半導體產業,絕對不是犯罪跡象。設備維修、輪班、異常處置,都可能在半夜發生。

所以「時」不能粗暴地寫成:半夜=危險

真正的問題是:

這個人+這項工作+這個時間,是否符合正常情境?

一名本來值夜班的工程師凌晨進廠,很正常。

一名平常只上日班、即將離職的人,在假日凌晨進入敏感區並大量讀取資料,風險 Context 就不同。

因此 Time-based Access 不應只有「08:00~18:00 可進入」。

它還可能包含:

班表、Maintenance Window、臨時工作單、專案期間、特殊時段複核,以及權限自動到期。

但高科技廠房的「時」,還有另外一種更重要的狀態:

Emergency Time。

2024 年 4 月 3 日花蓮強震發生時,台灣多家半導體廠啟動人員撤離,與設備安全程序,部分產線受到短暫影響。

正常狀態下,一道門的重要工作可能是:防止沒有權限的人進入。

地震、火災或其他重大事故發生時,同一道門最重要的工作卻可能瞬間變成:不要妨礙裡面的人出去。

某些關鍵區域同時又不能因 Emergency Mode 而完全失去管理。

所以同一個高科技廠房至少存在:

Normal → Incident → Emergency → Recovery

幾種不同的安全時間。

真正成熟的安控,不只是「平常守得住」,還必須在非常狀態下知道規則怎麼變。


七、「地」也不是地圖上一個永遠不變的框


2025 年 8 月,台灣美光后里廠化學品儲存區,自動抽除作業發生異常,氣體與壓力造成管線破裂及白色霧氣外洩,附近 4 名清潔與保全外包人員身體不適送醫。中科管理局表示,初步了解相關人員並未直接接觸該區化學品。事件後該工作場所被要求停工調查。

這不是安控設備造成的事故,也不能倒過來說「多裝安控設備就能防止化學品事故」。

Process Safety 還是 Process Safety。但事件一旦發生,Security 必須立刻加入。因為原本正常可以工作的 Location,可能瞬間變成 Restricted Zone。

這時安全系統應該協助回答:

  • 事故區附近現在有誰?
  • 哪些承包商、保全或清潔人員正在工作?
  • 哪些入口必須停止進入?
  • 誰需要立即通知?
  • 撤離之後,人是否全部到達集合點?
  • 哪些人仍然沒有確認?

於是「地」開始與門禁、環境感測、對講/廣播、大量通知、人員清點、事件管理平台產生關係。

影像可以協助事件確認和事後還原,但只是其中一環。

所以:

Location 不是固定的地圖,而是可能隨事件改變安全等級的 Risk Zone。

到了這裡,安全已經從基礎防護走向風險管理與韌性。


八、最經典的 OT 安全事件之一:一台「正常的新機台」,為什麼讓 Fab 停下來?


談到「物」,還有一種資產比電纜、測試板更值得高科技產業重新回顧。

2018 年 8 月 3 日晚間,台積電部分台灣廠區的電腦系統與 Fab Tools 遭到電腦病毒感染。事件不是外部駭客打進來。也不是有人拿 USB 偷偷植入。

台積電後來公開說明,原因是在新機台軟體安裝過程中發生操作失誤;該機台帶有公司事前未知的惡意軟體,一旦連上公司內部電腦網路,病毒開始擴散。公司當時亦指出,防火牆控制並未有效阻止惡意程式傳播。

事件一路發展成:

新設備→ 安裝軟體→ 連上內網→ Malware Spread→ 電腦系統與 Fab Tools 異常→ 部分設備停擺→ 晶圓生產受影響→ 出貨延遲

到了 8 月 5 日下午,約 80% 受影響機台恢復,公司預計 8 月 6 日完全復原。台積電當時估計第三季營收受到約 3% 影響、毛利率約減少 1 個百分點;2018 年年報最終列出的相關損失約為 新台幣 25.96 億元(8,500 萬美元)

最值得注意的是:

這起事件沒有造成資料完整性,或機密資訊遭破壞。

也就是說,沒有資料被偷。卻一樣造成幾十億元的營運損失。這就是為什麼它是台灣高科技產業非常經典的 OT Security 案例。

因為它明白證明:

安全不只是在保護 Confidentiality,也在保護 Availability。

高科技工廠最怕的,不只是機密被拿走。

產線停下來,本身就是重大安全事件。


九、一台機台進 Fab,其實有兩張「通行證」


重新看 2018 年事件,就會發現高科技廠房的「物」已經完全不同於傳統資產管理。

一台新設備搬進工廠,第一道問題是:

Physical Access

  • 這是什麼設備?
  • 誰送進來?
  • 要放哪裡?
  • 誰負責安裝?

但是它還有第二道入口:

Virtual Access

  • 它可以連哪個 Network?
  • Software/Firmware 狀態是否經過確認?
  • 誰核准它正式上線?
  • 它可以和哪些機台與系統通訊?
  • 出現問題能不能被隔離?

於是「設備」本身也開始有:

Identity、Authority、Status、Lifecycle。

而台積電在事件後採取的措施,包括建立自動化機制,避免未受保護的工具安裝,以及強化防火牆和網路控制,目的就是降低惡意程式,在設備與 Fab 之間擴散的可能性。

如果把今天的 OT Security 方法再放進來,還會繼續問:

  • Asset Inventory 完不完整?
  • 新設備 Commissioning 前有沒有安全檢查?
  • Network Admission 有沒有控制?
  • Production Network 是否適當 Segmentation?
  • 軟體變更是否經 Change Management?
  • 發生異常時能否快速隔離、復原?

這些事情已經不能由「安控部門」或「IT 部門」各做各的。

因為:

Physical Asset 一旦 Connected,就同時變成 Cyber Asset;Cyber Asset 一旦控制生產,就同時變成 Operational Asset。


十、所以今天高科技廠房的「物」,至少有三種


到了這裡,「物」已經不能再只理解成工具、產品或材料。

Asset

典型風險

前述案例

主要安全能力

實體資產 Physical Asset

失竊、非法搬移、私自帶出

台積電嘉義工地電纜、京元電測試板

InventoryAsset Tracking、車輛/物品進出、盤點、離場程序

資訊資產 Information Asset

拍攝、下載、複製、USBCloud 外流、營業秘密遭竊

台積電先進製程案、南亞科、MicronUMC

IdentityAuthorityDLPPAMDeviceMedia Control、異常存取

OT/Connected Asset

Malware、錯誤設定、未授權連線、橫向擴散、停線

台積電 2018 病毒事件

Secure CommissioningAsset InventoryNetwork AdmissionSegmentationOT DetectionRecovery


有些物可以用貨車載走。

有些物根本沒有重量,幾秒鐘就可以複製。

還有一些物哪裡都沒有去,只是停止工作,就足以讓整座工廠付出巨大代價。

這三種 Asset,才比較接近今天高科技廠房真正的「物」。


十一、五管不是五套系統,而是一張會互相碰撞的 Matrix


看到這裡,再重新整理:

五管

真正要回答的問題

你是誰?目前是員工、承包商、訪客還是設備商?

你現在被授權做什麼?為什麼?

為什麼是這個時間?權限何時開始、何時結束?

你為什麼可以出現在這個區域?

你可以帶入、帶出、存取或連接什麼資產?


問題是,真正的安全事件從來不照表格一欄一欄發生。

高科技廠房真正要看的,是:

Person × Activity × Time × Location × Asset

單獨看都正常的資料,組合起來卻可能完全不正常。

  • 員工進公司:正常。
  • 凌晨進公司:可能正常。
  • 使用公司帳號:正常。
  • 進管制區:如果有權限,也正常。
  • 攜帶一個攝錄設備:有些區域可能允許。

但是:

準備離職的人+假日凌晨+管制區+攝錄設備+大量讀取核心技術資料

就不再是五個普通 Event。而是一個 Contextual Risk

所以安控下一個真正值得發展的方向,不只是:Event Detection

而是:Contextual Risk Detection。


十二、Traceability 不是「有紀錄」,而是紀錄能不能串起來


這也解釋了為什麼「有門禁紀錄」、「有工作單」、「有 Asset Database」、「有 Log」、「有影像」都不代表已經具備 Traceability。

如果五份資料各自在五個系統裡,發生事件時仍然只能靠人一套一套調資料。

真正成熟的 Traceability 應逐漸回答:Who did What, When, Where, with Which Asset?

更進一步還要回答:Why was it authorized?

也就是這項行為當初為什麼被允許。

京元電從 Asset Data 異常開始往回查,就是一個很好的例子;台積電 2018 事件,則需要從設備、軟體、Network、Fab Tool 與生產影響一路往回還原。

真正高階的 Event Management therefore不是收很多 Alarm,而是:

把原本分散的 Evidence 拼回一件事情。


十三、到了最後,才應該問:安控設備究竟要部署什麼?


如果沒有前面的五管,直接開始談設備,很容易得到一座:

系統很多、Alarm 很多、Log 更多,但發生事情時,仍然不知道該先查哪裡的工廠。

設備應該反過來對應問題。

場域問題

程序先處理什麼

可對應的安全能力

合法人員異常存取

職務、Need-to-know、權限生命週期

Identity、門禁、Virtual Access、事件關聯

承包商超出工作範圍

Work Order、施工範圍、人車物管理

Contractor Management、門禁、車輛與物料管理

非典型時間進入敏感區

時段規則、工作理由、臨時授權

Time-based Access、多重驗證、異常告警

機密資料大量取得

資料分級、Authority、使用目的

DLPPAMDevice Control、異常存取分析

重要資產異常移動

登錄、領用、搬移、離場與盤點

Asset Tracking、出入口管理、事件比對

區域突然成為事故區

Emergency SOP、撤離、封鎖、復原

感測、門禁、對講/廣播、通知、Muster

新設備連入產線

CommissioningChange Management

Device IdentityNetwork AdmissionOT Security


所以門禁有門禁的位置;入侵偵測有它的位置;對講、感測、影像監控、Identity、Asset Management、Cybersecurity、OT Security、事件管理平台,也都有各自的位置。

但沒有任何一種設備,可以代表整個安控。


十四、高科技廠房真正的最高安全等級,是出了事情仍然守得住營運


回到 3S Market 很重視探討的安全五層次,高科技廠房幾乎把五個層次全部逼到極致。

基礎安全提供辨識、管制、偵測、通訊與記錄。

程序安全定義誰能做什麼、如何申請、如何授權、什麼時候終止。

風險管理開始把人、事、時、地、物交叉比對,找出單一系統看不到的異常。

韌性安全處理的則是地震、火災、化學事故、OT 攻擊、系統故障與其他重大事件發生後,如何撤離、隔離、切換、復原,讓工廠不要因為一個安全事件全面失序。

到了 永續安全,這套方法還必須能帶到下一座廠、下一個國家、下一批承包商與下一代設備,不應只存在少數資深主管和工程師腦袋裡。

所以一座高科技廠房真正該追求的,可能不是:「我們裝了多少設備?」

而是當事情發生時,能不能迅速回答:

這是誰?他被允許做什麼?為什麼是這個時間?為什麼出現在這裡?他接觸了什麼?這個行為合理嗎?

如果不合理,我們能不能及時發現、處置並完整追溯?

而更高的一層則是:

發生事情之後,技術能不能守住?產線能不能控制?營運能不能繼續?

這才是高科技廠房的安控,為什麼可能代表目前最複雜、要求最高的安控解決方案之一。

它保護的已經不是一扇門、一部機器,甚至不只是一座工廠。

它保護的是:技術、產能,以及企業持續運作的能力。

而如果台灣在四十五年以上的高科技建廠歷程中,已經把這套「人、事、時、地、物+IT/OT+程序+工程+營運」磨成一種成熟 Know-how,那麼下一集真正要追問的,就不是台灣安控設備能不能出口,而是:這整套安全工程能力,能不能 Turnkey 輸出到世界?


English version


The Highest Secrets Aren’t on the Equipment List: What High-Tech Fabs Really Need to Manage Is “People, Activity, Time, Location, and Assets” (Part 2)

From trade-secret theft, insider threats, and asset loss to OT downtime: why high-tech fab security cannot rely on equipment alone


If all the security systems in an advanced semiconductor fab were listed on a single sheet, the list might include access control, intrusion detection, intercoms, video surveillance, biometrics, visitor management, sensors, event-management platforms, and many other systems.

But even with that complete equipment list in hand, we still might not know whether the fab is truly secure.

That is because the most difficult security incidents in high-tech facilities are often not caused by an unknown intruder climbing over a wall. The harder cases are usually much less obvious: the person entering the site is already authorized; the account being used is legitimate; there is a valid reason for that person to be on site; and the equipment being operated may even belong to the company itself.

The problem is that the activity has moved beyond the original scope of authorization.

This is why the most basic security logic of a high-tech fab can be reduced to five elements:People, Activity, Time, Location, and Assets.

Who came in? What were they there to do? At what time? In which area? What did they access, carry, connect to, or remove?

A real security incident often begins when several of these five elements no longer match.

For the high-tech industry, three bottom lines must never be compromised:

Technology must not leak.
Production must not lose control.
Operations must not be interrupted.

A series of recent incidents involving Taiwan’s semiconductor and high-tech industries clearly shows how these three lines can be breached.


1. The Hardest Person to Defend Against May Already Be Authorized


In August 2026, the New Taipei District Prosecutors Office indicted a senior engineer at Nanya Technology.

According to the investigation, while preparing to leave the company, the engineer entered company premises three times during holidays, at night, or in the early hours of the morning. He allegedly concealed an action camera inside a bag of snacks to get past security screening.

After entering a controlled office area, he used his own account to log in to the company’s virtual host, accessed a large volume of documents related to core manufacturing processes, and photographed them. Prosecutors determined that he had obtained 32 photo files involving trade secrets.

The case almost reads like a textbook example of People, Activity, Time, Location, and Assets.

People: He was not an outsider, but a senior company engineer.

Activity: He had legitimate work-related system access, but having the right to use a system does not mean having the right to obtain large amounts of core information for another purpose.

Time: Holidays, nighttime, early morning.

Location: A controlled office area.

Assets: A recording device concealed inside a snack bag.

Any one of these factors, viewed separately, might not be enough to indicate a problem. But when they appear together—

an employee preparing to leave + abnormal working hours + a restricted area + a concealed recording device + large-scale access to core process information

—the security meaning becomes entirely different.

The first concept high-tech facilities therefore need to break away from is this:

Identity proves who you are. It does not prove that what you are doing now is reasonable.

A valid employee badge only means that the identity is still valid. It is not a “fully trusted” pass.

This is why employee transfers, the end of a project, contractor renewal or termination, and the period before or after resignation should all be considered together with Physical Access, Virtual Access, and data privileges.

The point is not to treat every departing employee as a suspect. The point is to ask again:

Does the access originally granted to this person still have a legitimate business purpose today?


2. The Most Spy-Movie-Like Story in High Tech: What Was Stolen Could Not Be Seen


If the Nanya Technology case already sounds cinematic, the TSMC advanced-process trade-secret case from 2025 to 2026 pushed the issue to an even more sensitive level.

The case began when TSMC discovered internal anomalies and reported them.

According to prosecutors, a former TSMC engineer who later joined equipment supplier Tokyo Electron repeatedly asked engineers still working at TSMC to provide key technical information in order to improve equipment performance and win more business involving advanced-process equipment.

The information involved trade secrets relating to processes below 14 nanometers, key gases and chemicals, and equipment technology.

Judgments were issued in 2026. One former TSMC engineer, Chen Li-ming, received a 10-year sentence, and in July the Supreme Court rejected his appeal, making the sentence final.

What is most important about this kind of case is that nobody necessarily “broke into a data center.”

Quite the opposite. The information may have been obtained in what looked like a very ordinary working environment:

  • One engineer asked another engineer for technical information.
  • An equipment supplier wanted to improve equipment performance.
  • The employee still inside the company already had some legitimate data-access privileges.

What changed was this:

Legitimate Access was used to perform an unauthorized Activity.

Data is also fundamentally different from a machine.

If a machine disappears, the empty space is immediately visible. Data can be copied into a second, third, or unlimited number of copies while the original remains exactly where it was.

This is why some of the most valuable “assets” inside a high-tech fab may have no physical weight at all.

Process parameters, equipment-tuning methods, material recipes, design rules, yield-improvement methods, customer data, and R&D results are all Information Assets.


3. More Than 900 Files, USB Drives, Private Cloud Storage, and Offline Laptops: How Does Data Actually “Leave” a Factory?


A classic case that illustrates the complete path of data leakage is the DRAM trade-secret dispute involving Micron, UMC, and Fujian Jinhua.

According to a 2018 U.S. Department of Justice indictment, an employee who was leaving Micron’s Taiwan subsidiary downloaded more than 900 confidential and proprietary Micron files before departure and stored the data on USB external storage devices or in private cloud storage.

Investigators later found Micron intellectual property on UMC computers.

The U.S. Department of Justice also stated that after UMC’s IT department discovered the relevant information, two “off-network” laptops were issued so employees could access the confidential material without further detection by the company’s normal IT systems.

In 2020, UMC pleaded guilty in the United States to trade-secret theft and agreed to pay a US$60 million fine.

If we map the security path in this case, it quickly becomes clear that it extends far beyond what any single security system can answer:

Employee identity
System login
File download
USB / external storage
Private cloud
External device
Offline computer
New working environment

If Physical Security knows only that “this employee came to work today,” that information is almost meaningless.

If Cybersecurity knows only that “the account login was successful,” that is also not enough.

The real question is:

Did this person, for this job, at this time, have a reasonable reason to obtain this amount of data? And why did the data need to be transferred to this particular Device or Storage?

This is already a process issue.

High-tech facilities therefore need to place the following within the same risk logic:

Identity, Authority, Data, Device, Physical Access, and Virtual Access.

The tools involved may go well beyond traditional security systems and include Least Privilege, PAM, DLP, USB and removable-media controls, endpoint security, and abnormal bulk-download analysis.

But tools still come after process.

The first questions should be:

What are the company’s Crown Jewels?
Who truly needs access to them?
Under normal working conditions, how should they be accessed?


4. Being Authorized to Enter a Site Does Not Mean Being Authorized to Take Things Out


Information assets are invisible, but high-tech facilities still face the most traditional form of security problem: physical theft.

In 2026, a case at TSMC’s advanced-packaging construction site in Chiayi provided a useful example.

According to publicly available court and prosecutorial information, the suspects were themselves employees of downstream contractors. They used their legitimate access to the construction site to repeatedly steal electrical cable.

The case involved more than 4.5 kilometers of cable, with nearly NT$5 million in proceeds from resale.

During the final incident, a truck was allowed into the site under the stated purpose of “moving tools into the construction site.” An accomplice hid inside the truck bed. After entering, the suspects cut and removed cables. When security personnel discovered them, they allegedly crashed through the gate while escaping.

In July 2026, the court of first instance sentenced the principal defendants to between four years and four years eight months in prison.

This is a classic Authority Gap.

The suspects were not people with “no right to enter.”

The problem was:

Having the right to enter a construction site does not mean having the right to perform every activity after entering.

Security personnel may see:

“This is a familiar contractor.”

The access-control system may see:

“This Credential is valid.”

But real security management also needs to know:

Why is this person here today?
Is there a Work Order?
Who came in with them?
Who was originally inside the vehicle?
What tools were brought in?
What should normally be taken out?

That is the meaning of Activity.

A mature Contractor Management process should gradually connect:

People Work Order Work Area Time Window Vehicle Tools and Materials Completion Exit

into one complete operational sequence.

Otherwise, a security system can only say:

“He entered.”

It cannot answer:

“What was he supposed to do after entering?”


5. KYEC Test-Board Theft: Sometimes Security Does Not See the Problem First — the Data Does


Another noteworthy case occurred at King Yuan Electronics’ Zhunan facility.

In January 2026, the company disclosed that an engineer was suspected of stealing circuit boards used for IC testing, fiber-optic cables, and other equipment.

The most important part of the case was how the problem was first discovered.

The company said it initially detected abnormal data in its test-board registration system. That triggered an internal investigation. The company then used inventory checks and relevant video records to identify the suspect.

More than 80% of the stolen items were recovered, and the company stated that no technical secrets were leaked and operations were not affected.

The case provides an important reminder:

Effective security does not always mean that one device “catches the person” at the moment of the crime.

Sometimes the first sign comes from the Asset Database.

The inventory does not match.

A test board that should be present is missing. Or the system status of an asset does not match the physical inventory.

Only then does the investigation move backward:

Who had access?
At what time?
Where?
Did the asset pass through an exit?
What work records existed?

When necessary, video can then be used as Evidence.

This is where the real value of Traceability becomes clear:

Asset Data + Identity + Access Log + Time + Event Record + Evidence

rather than expecting one security device to answer everything.


6. Does 2:00 a.m. Mean the Same Thing as 2:00 p.m. in Security?


Return again to the Nanya Technology case.

Entering a semiconductor company at night or in the early morning is absolutely not evidence of wrongdoing. Semiconductor plants operate 24 hours a day. Maintenance, shift work, and abnormal-event response may all occur in the middle of the night.

So Time cannot be reduced to:

“Nighttime = dangerous.”

The real question is:

Does this person + this activity + this time fit a normal context?

An engineer who normally works the night shift entering the fab at 2:00 a.m. is completely normal.

An employee who normally works days, is about to resign, enters a sensitive area early on a holiday morning, and then accesses large volumes of technical data presents a different risk Context.

Time-based Access therefore should not consist only of rules such as “08:00–18:00 access permitted.”

It may also incorporate:

  • Shift schedules
  • Maintenance Windows
  • Temporary Work Orders
  • Project periods
  • Special-time secondary verification
  • Automatic expiration of privileges

But Time in a high-tech fab has another important dimension:

Emergency Time.

When the April 3, 2024 Hualien earthquake struck, several semiconductor plants in Taiwan initiated personnel evacuation and equipment-safety procedures, and some production lines were temporarily affected.

Under normal conditions, an important function of a door may be:

Prevent unauthorized people from entering.

During an earthquake, fire, or other major incident, the same door may suddenly need to do something very different:

Do not prevent people inside from getting out.

At the same time, some critical areas still cannot simply lose all control because the facility has entered Emergency Mode.

A high-tech fab therefore operates under several distinct security states:

Normal Incident Emergency Recovery

A mature security system does not merely “hold the line” during normal operations.

It must also know:

How should the rules change when conditions are no longer normal?


7. “Location” Is Not a Permanent Box on a Map


In August 2025, an abnormality occurred during an automated extraction process in the chemical-storage area of Micron’s Houli facility in Taiwan.

Gas and pressure caused a pipeline rupture and a release of white vapor. Four nearby outsourced cleaning and security personnel became unwell and were taken to hospital.

The Central Taiwan Science Park administration stated that, based on its preliminary understanding, those personnel had not directly handled the chemicals in the affected area. The workplace was subsequently ordered to stop operations pending investigation.

This was not an accident caused by security equipment, and it would be wrong to reverse the logic and claim that “installing more security equipment can prevent chemical accidents.”

Process Safety is still Process Safety.

But once an incident occurs, Security must immediately become part of the response.

A Location that was safe for normal work may suddenly become a Restricted Zone.

At that moment, the security system should help answer:

  • Who is currently near the incident area?
  • Which contractors, security staff, or cleaning personnel are working there?
  • Which entrances must be closed?
  • Who needs to be notified immediately?
  • After evacuation, has everyone reached the muster point?
  • Who remains unaccounted for?

At this point, Location begins to connect with access control, environmental sensing, intercom/public address, mass notification, personnel accountability, and event-management platforms.

Video can help confirm events and reconstruct what happened afterward, but it is only one part of the whole.

So:

Location is not a fixed map. It is a Risk Zone whose security level may change as events unfold.

At this stage, security has already moved beyond basic protection and into risk management and resilience.


8. One of the Most Classic OT Security Incidents: How Could a “Normal New Machine” Bring a Fab to a Halt?


When discussing Assets, there is another category that deserves even more attention than cables or test boards.

On the evening of August 3, 2018, computer systems and Fab Tools at several TSMC facilities in Taiwan were infected by malware.

The incident was not caused by an external hacker breaking into the company.

Nor was it caused by someone secretly inserting an infected USB drive.

TSMC later explained that the cause was an operational error during software installation on a new machine. The equipment contained malware that the company had not previously detected. Once the machine was connected to the company’s internal computer network, the malware began to spread.

The company also stated that firewall controls did not effectively prevent the malware from propagating.

The sequence became:

New equipment
Software installation
Connection to internal network
Malware spread
Computer systems and Fab Tools malfunction
Some equipment stops
Wafer production affected
Shipment delays

By the afternoon of August 5, about 80% of the affected tools had recovered, and the company expected full recovery by August 6.

TSMC estimated at the time that third-quarter revenue would be affected by about 3%, while gross margin would decline by approximately one percentage point.

Its 2018 annual report ultimately recorded related losses of about NT$2.596 billion, or US$85 million.

The most important point is this:

The incident did not result in the destruction of data integrity or confidential information.

In other words:

No data was stolen. Yet the company still suffered billions of New Taiwan dollars in operational losses.

That is why this remains one of Taiwan’s most classic OT Security cases.

It clearly demonstrates:

Security is not only about protecting Confidentiality. It is also about protecting Availability.

For a high-tech factory, the greatest fear is not only that secrets may be taken away.

A production line stopping is itself a major security incident.


9. A Machine Entering a Fab Actually Needs Two “Passes”


Looking again at the 2018 incident, it becomes clear that the meaning of an “asset” in a high-tech facility has changed completely from traditional asset management.

When a new machine is moved into the factory, the first questions concern:

Physical Access

  • What equipment is this?
  • Who delivered it?
  • Where will it be installed?
  • Who is responsible for installation?

But the machine has a second entry point:

Virtual Access

  • Which Network may it connect to?
  • Have its Software and Firmware states been verified?
  • Who approves it for production use?
  • Which tools and systems may it communicate with?
  • Can it be isolated quickly if something goes wrong?

A piece of equipment therefore begins to have its own:

Identity, Authority, Status, and Lifecycle.

After the 2018 incident, TSMC introduced measures including automated mechanisms to prevent unprotected tools from being installed and strengthened firewall and network controls to reduce the possibility of malware spreading between equipment and the Fab.

If today’s OT Security methods are added to the discussion, additional questions emerge:

  • Is the Asset Inventory complete?
  • Has the new equipment passed security checks before Commissioning?
  • Is Network Admission controlled?
  • Is the Production Network properly Segmented?
  • Are software changes subject to Change Management?
  • Can abnormal equipment be isolated and recovered quickly?

These questions can no longer be handled independently by the “security department” and the “IT department.”

Because:

Once a Physical Asset becomes Connected, it also becomes a Cyber Asset.
Once a Cyber Asset controls production, it also becomes an Operational Asset.


10. So Today, a High-Tech Fab Has at Least Three Types of “Assets”


At this point, Assets can no longer be understood only as tools, products, or materials.

Asset

Typical Risks

Cases Discussed Above

Core Security Capabilities

Physical Asset

Theft, unauthorized movement, illicit removal

TSMC Chiayi construction-site cables; KYEC test boards

Inventory, Asset Tracking, vehicle/item movement control, stock checks, exit procedures

Information Asset

Photography, download, duplication, USB/Cloud leakage, trade-secret theft

TSMC advanced-process case; Nanya Technology; Micron/UMC

Identity, Authority, DLP, PAM, Device/Media Control, abnormal-access detection

OT / Connected Asset

Malware, misconfiguration, unauthorized connection, lateral spread, production shutdown

TSMC 2018 malware incident

Secure Commissioning, Asset Inventory, Network Admission, Segmentation, OT Detection, Recovery

Some assets can be loaded onto a truck and taken away.

Some have no physical weight and can be duplicated in seconds.

Others never leave the factory at all.

They simply stop working—and that alone may be enough to impose enormous losses on the entire facility.

These three types of Assets are much closer to what “Assets” really means in a modern high-tech fab.


11. The Five Dimensions Are Not Five Systems — They Form a Matrix That Constantly Intersects


At this point, the five dimensions can be summarized again:

Dimension

The Real Question

People

Who are you? Are you currently an employee, contractor, visitor, or equipment supplier?

Activity

What are you authorized to do now—and why?

Time

Why at this time? When does the authorization begin and end?

Location

Why are you allowed to be in this area?

Assets

What are you allowed to bring in, remove, access, or connect?


The problem is that real security incidents never occur neatly one row at a time.What high-tech facilities really need to examine is:

Person × Activity × Time × Location × Asset

Each data point may appear normal when viewed independently.

An employee comes to work: normal.

Entering at 2:00 a.m.: possibly normal.

Using a company account: normal.

Entering a restricted area: normal, if authorized.

Carrying a recording device: possibly allowed in some areas.

But:

**an employee preparing to resign

  • a holiday at 2:00 a.m.
  • a restricted area
  • a recording device
  • large-scale access to core technical information**

is no longer five ordinary Events.

It becomes a Contextual Risk.

The next direction security should therefore develop toward is not only:

Event Detection

but:

Contextual Risk Detection.


12. Traceability Does Not Mean “Records Exist” — It Means the Records Can Be Connected


This also explains why having:

  • access-control records,
  • Work Orders,
  • an Asset Database,
  • system Logs,
  • and video records

does not automatically mean a company has Traceability.

If those five sources of information remain isolated in five different systems, investigators still have to retrieve them one by one when an incident occurs.

Mature Traceability should gradually be able to answer:

Who did What, When, Where, with Which Asset?

And one step further:

Why was it authorized?

In other words:

Why was this activity allowed in the first place?

The KYEC case, where an Asset Data anomaly triggered the investigation, is a good example.

The 2018 TSMC incident required investigators to reconstruct the chain across equipment, software, Network, Fab Tools, and production impact.

Advanced Event Management therefore is not about collecting more Alarms.

It is about:

Reassembling dispersed Evidence into one complete event.


13. Only at the End Should We Ask: What Security Equipment Should Be Deployed?


If the five dimensions above have not been defined first, beginning directly with equipment usually produces a factory that has:

many systems, many Alarms, even more Logs—yet when something happens, nobody knows where to look first.

Equipment should instead be mapped backward from the problem.

Site Problem

Process Must Address First

Security Capabilities That May Support It

Abnormal access by legitimate personnel

Role, Need-to-know, privilege lifecycle

Identity, access control, Virtual Access, event correlation

Contractor exceeds authorized work scope

Work Order, construction scope, people/vehicle/material management

Contractor Management, access control, vehicle and material management

Entry into sensitive area at unusual time

Time rules, work justification, temporary authorization

Time-based Access, multi-factor verification, abnormal alerts

Large-scale acquisition of confidential information

Data classification, Authority, purpose of use

DLP, PAM, Device Control, abnormal-access analytics

Abnormal movement of important assets

Registration, issue, movement, exit, inventory

Asset Tracking, entrance/exit management, event correlation

Area suddenly becomes an incident zone

Emergency SOP, evacuation, lockdown, recovery

Sensors, access control, intercom/public address, notification, Muster

New equipment connects to production

Commissioning, Change Management

Device Identity, Network Admission, OT Security


Access control has its place.

Intrusion detection has its place.

Intercoms, sensors, video surveillance, Identity, Asset Management, Cybersecurity, OT Security, and event-management platforms all have their own roles.

But:

No single piece of equipment can represent the entire security system.


14. The Highest Level of Security in a High-Tech Fab Is the Ability to Keep Operations Running After Something Goes Wrong


Returning to the five levels of security that 3S Market has repeatedly explored, high-tech facilities push almost every level to its limits.

Basic Security provides identification, control, detection, communication, and records.

Procedural Security defines who may do what, how requests are made, how authorization is granted, and when privileges should end.

Risk Management begins to cross-reference People, Activity, Time, Location, and Assets in order to identify anomalies that no single system can see.

Resilient Security addresses what happens after earthquakes, fires, chemical incidents, OT attacks, system failures, and other major events:

  • How should people evacuate?
  • How should systems be isolated?
  • How should operations switch over?
  • How should the facility recover?

The objective is to prevent one security event from throwing the entire factory into disorder.

At the level of Sustainable Security, the methodology must be transferable to the next fab, the next country, the next group of contractors, and the next generation of equipment.

It cannot exist only inside the heads of a few experienced executives and engineers.

So what a high-tech fab should really pursue may not be:

“How much security equipment have we installed?”

Instead, when something happens, can the organization rapidly answer:

  • Who is this?
  • What were they authorized to do?
  • Why at this time?
  • Why in this location?
  • What did they access?
  • Is the activity reasonable?

If it is not reasonable:

Can we detect it, respond to it, and fully trace it in time?

And at an even higher level:

After an incident occurs, can the technology still be protected?
Can production remain under control?
Can operations continue?

This is why high-tech-fab security may represent one of the most complex and demanding security solutions in the market today.

It is no longer protecting only a door, a machine, or even a single factory.

It is protecting:

technology, production capacity, and the enterprise’s ability to continue operating.

And if Taiwan, over more than forty-five years of high-tech factory construction, has already refined this combination of:

People, Activity, Time, Location, and Assets + IT/OT + Process + Engineering + Operations

into a mature body of know-how, then the real question for the next installment is no longer whether Taiwan’s security equipment can be exported.

The question is:

Can This Entire Security Engineering Capability Be Exported to the World as a Turnkey Solution?


智慧鎖在商業節能的應用

按此回今日3S Market新聞首頁

0 comments: