Michael Caster (Head of Global China Programme) and I-Chen Liu (Asia Programme Officer) from ARTICLE 19 outline Chinese PRC’s influence over cybersecurity norms in their newest report, “Cybersecurity with Chinese Characteristics”.
This report focuses on three countries in Indo-Pacific: Indonesia, Pakistan, and Vietnam, and with a Taiwan alternative.
The Digital Silk Road is an umbrella concept that includes policies, priorities, tools, technologies, and tactics of a digital nature under China's Belt and Road Initiative. Launched in 2015, it’s how PRC promotes its cybersecurity and digital governance norms and technical standards across the world. It does this through public and private partnerships with Chinese tech companies that provide capacity-building initiatives internationally: 5G cyber security test labs in Malaysia, mobile payment in Thailand, data centers in Nepal, surveillance cameras in Phnom Penh and Kathmandu, submarine cables in Cambodia, and satellite systems for Thailand.
The PRC is pushing for multilateral cooperation through institutions like the UN, ASEAN, and other state-led forums. It has established additional bodies like the Global Security Initiative, Global Development Initiative, and Global Civilization Initiative to further the standardization of PRC-style norms.
The speakers warn of the impact on democracy and freedom of speech this could have on the recipient country. The PRC-style digital governance has become a toolkit for authoritarian actors to utilize cybersecurity laws in the name of promoting safety or national security; but in reality it introduces potentially humanitarian disaster laws that will impact the right to freedom of expression and the right to privacy.
The report ends with Taiwan’s democratic model of defending cybersecurity, which ensures the participation of civil society, as an alternative model to curb digital authoritarianism. This report follows “The Digital Silk Road: China and the Rise of Digital Repression in the Indo-Pacific” (2024) which includes case studies from Cambodia, Malaysia, Nepal, and Thailand.
Michael Caster (Head of Global China Programme) and I-Chen Liu (Asia Programme Officer) are researchers from the international non-profit organization ARTICLE 19, whose report “Cybersecurity with Chinese Characteristics” (2025) outlines PRC’s influence over cybersecurity norms in 3 Indo-Pacific countries: Indonesia, Pakistan, and Vietnam; and with a Taiwan alternative.
The Digital Silk Road is an umbrella concept that includes policies, priorities, tools, technologies, and tactics of a digital nature under the larger Belt and Road Initiative. Launched in 2015, it’s how PRC promotes its cybersecurity and digital governance norms and technical standards across the world.
It does this through public and private partnerships with Chinese tech companies that provide capacity-building initiatives: 5G cyber security test labs in Malaysia, mobile payment in Thailand, data centers in Nepal, surveillance cameras in Phnom Penh and Kathmandu, submarine cables in Cambodia, and satellite systems for Thailand. While receiving such technology, recipient countries have also adopted PRC-style censorship and regulations into their legal framework. Examples include Vietnam’s 2018 cybersecurity law, which regulates aspects including content moderation and data localization.
The PRC is now pushing for multilateral cooperation through institutions like the UN, ASEAN, and other state-led forums. It has established additional bodies like the Global Security Initiative, Global Development Initiative, and Global Civilization Initiative to further the standardization of PRC-style norms.
The researchers warn of the impact on democracy and freedom of speech this could have on the recipient country. “When China talks about multilateralism, they're doing it as a renouncing multi-stakeholderism approach; Denying civil society, the tech sector, academia, other independent actors. They're denying them a seat at the table”, says Caster.
The PRC-style of digital government becomes a toolkit for the authoritarian actor on how to use cybersecurity laws in the name of promoting safety or national security; but it’s actually introducing potentially humanitarian disaster laws that will impact the right to freedom of expression and the right to privacy.
Notable is the upcoming United Nations Cybercrime Convention in Vietnam, dubbed The Hanoi Convention, which has been rescheduled from July to October, 2025.
The Cybersecurity with Chinese Characteristics report ends with Taiwan’s democratic model of defending cybersecurity, which ensures the participation of civil society, as an alternative model to curb digital authoritarianism.
This report follows “The Digital Silk Road: China and the Rise of Digital Repression in the Indo-Pacific” (2024) which includes case studies from Cambodia, Malaysia, Nepal, and Thailand.
To access this report: https://www.article19.org/resources/china-taiwan-cybersecurity/
Support Ghost Island Media: http://patreon.com/taiwan
Follow and tag us on social media:
Ghost Island Media | Instagram | Facebook | Twitter
Emily Y. Wu | Twitter @emilyywu
A Ghost Island Media production: www.ghostisland.media
Support the show: https://patreon.com/Taiwan
See omnystudio.com/listener for privacy information.
Transcript
WU: At Article 19, you've been tracking how countries have been adopting China's style and standards of digital authoritarianism. You've analyzed cases of seven countries: Malaysia, Nepal, Thailand, Cambodia, Indonesia, Pakistan, and Vietnam. Before we talk about China's priorities and how they have shifted over the years, can you give us a bird's eye view on how this began?
CASTER: It began really a decade ago with -the sort of formal calling into existence of- the Digital Silk Road, which we argue isn't necessarily best thought of as a distinct foreign policy on its own, but an umbrella concept wrapping together all of the policies, priorities, tools, technologies, tactics of a digital nature under the larger Belt and Road Initiative (BRI).
In 2015, Digital Silk Road was formally established under the BRI, but its first instance came in 2014 when the Ministry of Industry and Information Technology (MIIT) first started calling for raising awareness of the need to take China's digital priorities and activities and efforts in informatization and put it under the BRI.
2014 is really a critical date in understanding a lot of this. Because it's also the year that the State Internet Information Office was rebranded as the Cyberspace Administration of China (CAC), and the first year that China hosted the World Internet Forum in Wuzhen.
So over the last decade, what we've seen is a combination of various state and party institutions like the CAC, the MIIT and others, working together with the erstwhile private sector - like Huawei and ZTE - and a range of other actors from United Front Work (UFWD) organizations, sort of people-to-people exchange. What we've seen is over a decade, China really going through its BRI partnerships, pushing a variety of digital priorities from digital infrastructure development, and with those, have often come the adoption of digital governance norms.
WU: As China helps developing countries build out their digital infrastructure, it's things like internet connectivity, mobile payment, cable networks. These are great technologies that can really benefit citizens on the ground. But what has been the risk for these countries? What does China get in return?
LIU: When China is persuading countries to adopt the Chinese version of digital governance norms, what we are seeing is actually a shift of global norms on digital governance. Before [this], I think the general consensus [had been] that the internet should be stateless, decentralized. But China is introducing a different digital governance norms by cooperation with these countries, by providing them with capacity building initiatives.
These countries may [have needed] to develop their own cyber security defense capabilities [...] But when they turn to China, they're adopting these practices, and eventually also promoting these norms that were different from what we originally pictured of digital governance norms that promote multi-stakeholderism in a more decentralized model.
WU: Is there an example from countries that really illustrate this?
LIU: Indonesia... [...] China provides capacity building to its cyber and crypto agency, State Cyber and Signal Agency (BSSN), and the Ministry of Information and Communication [...] After the 2017 MOU between BSSN, and CNCRT (National Computer Network Emergency Response Technical Team), it emphasized that [...] they will introduce cyber sovereignty in this data security governance. After that, joint trainings, programs, capacity building initiatives started. And a lot of practices are normalizing the PRC version of cyber security governance norms in Indonesia. (Editor's note: CNCRT is China's core coordination organization of the cybersecurity emergency response system)
Huawei plays a crucial role in introducing these norms when they are developing Indonesia's 5G networks. They also help shape Indonesia's cyber incident response and cybersecurity standards. [...] Also, there were concerns about how this may lead to backdoor access and dependence on PRC technologies.
CASTER: Thinking more from guidance from the party or directives from the party in 2020, the Central Committee also issued its opinions on strengthening the United Front work of the private economy in the new era [...] It required them to play a role in United Front work activities, which means promoting not just a positive image of China, but unswervingly following the party to quote, and to promote party priorities and policies in all of their engagements.
It directed them to take a more active role in BRI construction, which includes, Digital Silk Road related – and any number of other cooperations. But what we see from this 2020 document is really an explicit directive from the party to the so-called private sector in all of their engagements in digital cooperations, in developing out the tools and technologies with these countries; with a lens to how is it promoting the party; how is it especially promoting its priorities, which lead to adopting and normalizing its digital governance norms, which are very much away from universal values and principles and things like this.
WU: What was the point you really saw signs that China was ready to elevate from country-to-country bilateral relations to international systems, to the United Nations, to ASEAN?
CASTER: Early on in the documents, guiding opinions, five-year plans, documents that have come out over the last decade of Digital Silk Road activities. Early on, there was identifying China to regional blocks or multilateral bodies.
ASEAN is a critical sort of regional bloc that China has identified as having a strategic priority under this. The Indo-Pacific region. So while obviously pursuing development, cooperation, memorandums of understanding on anything from rolling out 5G to smart cities, a lot of this is done through the regional level. There's a value in that, because if China is engaging with ASEAN as a bloc of 10 member countries, then it seeks to normalize its practices for all 10. Then you scale that out to the global level, right? It's like the old Maoist adage: circling the city from the countryside around it.
What we identify in the latest report and what we argue is not just that multilateralism is a norm of China's digital governance, but what that means is very concerning [...] It means two things.
One is that when China talks about multilateralism, they're doing it as a renouncing multi-stakeholderism approach: denying civil society, the tech sector, academia, independent actors, denying them a seat at the table.
The second is that China's not just talking about working through the existing regional and multilateral bodies to pursue these objectives. They're creating and positioning their own to ultimately supplant those that have existed for decades, or some that go back all the way 80 years to the original post-war international rules based system. Examples of new China-created regional or global multilateral bodies are the Global Security Initiative, the Global Development or Global Civilization Initiatives, or the World Internet Conference.
WU: Later this year in July 2025, the United Nations Cybercrime Convention is expected to be signed. This is a resolution that was sponsored by Russia and backed by regimes like China, Cambodia, Belarus, Iran, Nicaragua, Syria, and Venezuela. How much of a landmark is this? And what should we be looking out for?
CASTER: The first UN General Assembly resolution calling for the creation of this cybercrime treaty goes back to 2019. This current process has been going on for a number of years. Article 19 has put out a number of analyses, and our colleagues and other teams have engaged in the process. We have been clear from the beginning that there's a number of concerning provisions; some have to do with normalizing the retention of user data law enforcement cooperation.
Cyber enabled crimes rather than cyber dependent crimes – which basically means things that can be done on or offline, but there is enhanced sentencing if they're done online – which are used often in countries from Thailand to Pakistan, for example, to further restrict freedom of expression online, and so forth.
There's a number of concerns within the convention itself. The fact that the resolution was first called to a vote by, basically a who's who in terms of Internet freedom predators. The history, the origins of this convention, are quite concerning. The fact also that Vietnam is hosting the signing and that it will presumably henceforth be known as the Hanoi Convention [...] The concern with this convention that's flawed to begin with, being signed now in Vietnam, will not just potentially risk whitewashing Vietnam's record. But because we see China's sort of shadowy influence along a lot of this normative shift, it will then further risk normalizing this approach to cybercrime and cybersecurity that China has been promoting.
So, countries like the United States and some others who begrudgingly perhaps accepted the text as it was last year, they of course did so with certain reservations that look at more human rights safeguards that can then be put into place at a state by state level. But the convention itself is what it is, and we know that globally it's normalizing a certain approach that will not see national level safeguards put into place by the countries that pushed it to be what it is today.
LIU: I think the case of Vietnam shows that China's influence is not only in the economic sectors and investments, but also influencing countries' legal frameworks and how they govern their own digital sphere and cybersecurity. In Vietnam's 2018 cybersecurity law, the legislation and legal frameworks a lot of times are very similar to the cybersecurity laws in the PRC. The influence of that can actually trace back to 2011, where an article was published in the Vietnamese newspaper where it analyzed the PRC laws and regulations on content moderation, real name registration, and also the use of firewalls in Vietnam.
A lot of the studies and research were already done from Vietnam, and also they can incorporate PRC's legal framework, which led to the controversial legislation of the 2018 cybersecurity law. In these cybersecurity laws, we see that not only in the murals, China cybersecurity laws requiring data localization, real name registration, and also providing governance on some kind of backdoor access for the user data. It encourages the provisions to combat anti-state speech, which may also lead to a stronger censorship and also other problematic human rights issues. [...]
WU: You mentioned real name registration when it comes to internet use. Do you look at how China continues to update those laws versus how it's being adopted abroad to make comparisons and recommendations?
CASTER: 2017 cybersecurity law in China placed the legal requirements for real name registration that were drawing on some previous guidelines. A few years after the cybersecurity law in China, the Ministry of Industry and Information Technology (MIIT) put out its guidelines on VPN registration, basically creating a whitelist of accepted VPNs. Some people have been imprisoned for up to five years for distributing VPNs that were not part of this whitelist. More recently – cut forward to just last year – the Cyberspace Administration of China (CAC) put forward draft guidelines. One of the newest would require a national internet ID.
We do see this as one of the normative shifts. The approach to digital governance that China has pushed is this effort to require identity verification at every step of possible online activity, which makes it almost impossible to have online anonymity. In a report a few years ago, the former Special Rapporteur on Freedom of Expression, David Kaye, was quite explicit that the right to freedom of expression is intrinsically linked to the ability to be secure and safe online. At times that requires anonymity or protection of article 17 of the International Covenant on Civil and Political Rights: Protection for the Right to Privacy.
This approach, it’s a chipping away of your right to privacy, it's supercharged surveillance, and it obviously disincentivizes people from expressing themselves or gaining information freely [...]
But it's not just happening in China. Through its cooperation agreements, its efforts to promote "best practices," which is a code for China's practices in these partnerships, we again see emulation of all of these types of things taking place. Just in our latest report, Cybersecurity with Chinese Characteristics, two of the country case studies we look at, Vietnam and Pakistan, we've seen a number of these same policies and requirements being put into force.
Vietnam has required through a few decrees under its cybersecurity law, the same type of requirement for real name registration. The Pakistan Telecommunications Authority has also, just as of last year, really been calling for an approach to whitelisting VPNs in the same way that we've seen from the MIIT in China.
We see this in a number of other places. For example, with the White Paper Protests in November two years ago, one of the ways that people were spreading information, promoting the protests, was through a feature in Apple AirDrop. It allowed people to quite freely share information in their close vicinity. To close this hole that was available for evading censorship in China, China put out policies requiring that particular type of protocol for AirDrop would require identity verification, contact listing, more ephemeral messaging.
So they put out a number of policies, but again, one of them relates directly to this issue about real name identity verification and requirements. Apple later rolled out some similar changes, which it was criticized for doing potentially in pressure from China. [...]
WU: If China's leading the charge in digital authoritarianism, who is leading the charge on the other side? What is the state of the internet divide going forward? In your report, I-Chen, you had a section on using Taiwan's case studies.
LIU: While China is framing the big needs for national security, Taiwan also suffers a very real national security threat, and a lot of threats in the cybersecurity governance. Taiwan is one of the most targeted countries for cyber attacks. According to the National Security Bureau, Taiwan suffers 2.4 million attacks per day targeting government agencies. So that's a lot of cyber attacks.
WU: 2.4 million a day. 2.4 million attacks?
LIU: 2.4 million attacks per day. Yeah.
I think that's double the number from a year before, so they have also upscaled their cyber attacks. Taiwan has been the country that’s most affected by disinformation, according to V-Dem (Varieties of Democracy) Institute. Not to mention, gray-zone tactics from cyber operations and the different disinformation influence campaigns. The newest trend is the attacks on the physical layer, where our undersea cables will be cut multiple times throughout the year. So the threat is very real for Taiwan.
But under these circumstances, Taiwan still develops its own cybersecurity governance norms that try to balance the threat and also the commitments to human rights.
The Cybersecurity Management Act was set as a cornerstone. When Taiwan was developing these legal frameworks and making amendments to fit the newest trends of cyber attacks, we see that public consultation is applied. When Cybersecurity Management Act is making new amendments, these amendments are put online on the Public Policy Participation Platform, which is a website for people to comment and respond. People would question whether amendments have too many audits or too little intelligence sharing. We do see that government officials, civil society, and people from the tech sectors will interact in online public consultation platforms. They will exchange ideas on how to balance concerns of human rights, public accountability, transparency, and how Taiwan should develop its own cybersecurity capabilities.
We're not trying to frame Taiwan as a perfect example. It’s a continual struggle to balance between national security and also human rights.
WU: What sense do you get of Taiwan's participation in the global cybersecurity discussions that are countering China's style? If China's leading this initiative, and they have signed agreements and partnerships with close to 100 countries, how should we be paying attention to this space to see that there is a counter on the global stage to China's dominance?
CASTER: One of our prevailing recommendations is for Taiwan to play a more engaged role in international internet and broader digital governance; which is not necessarily an easy thing to say. Because of course, through coordinated political, economic sharp power and other influence campaigns and threats from China, Taiwan has been intentionally isolated and sidelined in the global governance space.
Obviously, to say that Taiwan should be playing a more active role is challenging to follow through on. But certainly, things like the UN Internet Governance Forum taking place explores opportunities to ensure that representatives from Taiwan can join into these critical conversations. That's happening later this year in Norway, for example. Last year it was in Saudi Arabia. So the global digital rights community largely boycotted the proceedings. The year before that it was in Japan. Unlike some previous years, the Japanese government and local organizers did make some concessions to allow for participants from Taiwan to join. This is one forum. Certainly, there's a number of other places where this is taking place.
What we would like to see is greater inclusion at the regional and at the global level. It's not just the Taiwanese government, but Taiwanese civil society [...] I think certainly this is one place where there is a large gap in terms of the knowledge, the experience, the expertise that can be brought into global conversations that just isn't happening [...]
In terms of who's leading the charge - unfortunately, to engage in such a massive mission of both digital infrastructure development and the promotion of governance norms - requires vast amounts of resources that require a state to have the political will behind allocating necessary resources and participation, and adherence to universal values and international norms. Previously, the United States was putting effort into cybersecurity and other infrastructure development. Unfortunately, those efforts were already inadequate to properly combat China's influence in this space. Now most recently, because a lot of those efforts were actually overseen by and funded by the US Agency for International Development, USAID, the slashing of their budget will have a negative impact on the US role in a lot of the efforts to counteract what China's doing, from the infrastructure to the governance space.
The European Union has a Global Gateway initiative, which is firstly promoted as sort of a European values driven counter to the Belt and Road Initiative, but has digital components in it as well. This is one place where we would like to see greater attention placed on ensuring that the human rights based digital governance norms are mainstreamed in the other digital infrastructure and other infrastructure cooperation that the EU has through the Global Gateway Initiative.
Japan is a major development partner, not just in the Indo-Pacific but around the world. Traditionally, they have been very quiet. They haven't been as self-promoting as China has; which again is because development is very much part of China's soft power projections and narrative and information operations. So while Japan has in some cases actually invested more money in development around the Indo-Pacific, the awareness of that level of support isn't necessarily there. But in recent times, the Japanese development strategies have also shifted to more support for digital-related development cooperations. Then also, with certain companies that might be the ones engaged in, say, 5G rollout like Ericsson from Sweden and others, as well as ensuring that multi-stakeholder approach is there.
This is not just a matter of marshaling high budgets from states. We also need to ensure that civil society, academia, other independent actors, certainly journalists, have a critical role, not just in ensuring that there's transparency around procurements, or sites of satellite base stations, or fiber optic landing stations. All of this on the ground.
In Taiwan, we talk about the whole of society approach. But really, in terms of the global resistance to ensuring that human rights are maintained, that internet freedom principles are maintained, we also need a global, whole of society approach. Because certainly, the assault championed by China is systematic and coherent and strategic, attacking at all sorts of pillars, and so we need to be equally strategic in our response.
WU: What can we look out for next from Article 19?
CASTER: We do have a report forthcoming on transnational repression. We're looking at, in particular, China's acts of transnational repression against protesters around the world. We have case studies in 11 countries or so in Asia, North America, and Europe, looking at Hong Kong or Uyghur, Tibetan, other diaspora communities protesting around Chinese state visits outside of embassies and consulates, forms of digital transnational repression against protesters, as well as some of the psychosocial impact that comes with that.
This report is forthcoming, so we're excited about that. We're also doing a bit more building out some work in terms of lessons learned in Taiwan from FIMI in Taiwan, and then linkages with some of the lessons learned from Ukrainian civil society and being targeted by Russian FIMI.
LIU: We are starting a project to bridge Ukrainian expertise and Taiwanese civil expertise countering FIMI. Since Ukrainians are the people that know Russian FIMI the best, and Taiwanese may be the people who knows PRC FIMI the best, I think it's great that we have an opportunity to bridge these two groups and combine forces on learning not only how Russia and China is having a convergence in terms of information operations, but also exchange skillsets and provide capacity building initiatives providing better opportunities for the civil societies on both sides. As the conflict in Ukraine continues, I believe a lot of Taiwanese will still have the urge to learn from Ukraine, but also to help Ukrainians in their circumstances.
Episode Credits: Producer and host, Emily Y. Wu. Research and writing, Zack Chiang. Video and audio editing, Wayne Tsai. Transcription, Charis Hayward.

Host - Emily Y. Wu
Host - Emily Y. Wu
Emily Y. Wu is the executive producer of Ghost Island Media, a podcast network she founded in 2019. She is the presenter of The Taiwan Take podcast, Game Changers with Emily Y. Wu television series, and a co-host on the Metalhead Politics podcast.
