The Cybersecurity Act in Thailand

Thailand Cybersecurity Act B.E. 2562 (2019) was enacted to safeguard national security and protect Critical Information Infrastructure (CII) organization across various key sectors. The Act establishes a regulatory framework, outlining obligations for risk assessment, data protection, incident reporting and penalties for non-compliance. Its primary objective is to prevent, mitigate, and respond to cyber threats that may impact national stability, economic security, military readiness, or public order. The Act has been in effect since May 28, 2019, with a strong focus on enhancing the cyber resilience of IT and operational systems that support national-critical operations.

Select Language
  • English
  • ไทย

What’s new in 2025?

Effective January 18, 2025, two key subordinate regulations have been enforced by the National Cyber Security Committee (NCSC) under the Act:

  • Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023)
  • Minimum Standards for Data and Information Systems B.E. 2566 (2023)

These regulations require Critical Information Infrastructure (CII) operators to classify their data and information systems according to security categories and implement minimum cybersecurity protection standards based on that classification. Organizations handling national security, public safety, economic security, or critical public infrastructure are now expected to take a proactive approach to cybersecurity governance and regulatory compliance.

Who must comply?

Agencies and Organizations classified as Critical Information Infrastructure (CII) are required to comply with Thailand’s Cybersecurity Act. These include:

  • National Security
  • Information Technology and Telecommunications
  • Energy & Public Utilities
  • Public Health
  • Banking and Finance
  • Substantive Public Services
  • Transportation and Logistics
  • Other sectors deemed critical to national interests

While the regulatory requirements are clear, different CII sectors face different challenges – from limited visibility across systems, uncertainty about compliance readiness, to a lack of clarity on how the regulations apply to their operations. These challenges can delay action and expose critical systems to risk. At ABB, we help you navigate compliance with confidence by deepening your understanding of current cybersecurity practices and overcome industry-specific risks.

Discover how our tailored solutions align your operations with the requirements of Thailand’s Cybersecurity Act and the latest NCSC notifications.

Speak to an ABB Cybersecurity Expert in Thailand

How it impacts the CIIs?

Thailand Cybersecurity Acts, along with the newly two 2025 NCSC Notification on Minimum Standards for Data and Information Systems, the obligations of CIIs have been significantly expanded by requiring them to implement a comprehensive set of cybersecurity controls aligned with confidentiality, integrity, and availability principles.

CIIs must now establish documented risk management strategies, incident response plans, asset management processes, vulnerability assessments, access controls, system hardening procedures, awareness programs, crisis communication plans, and third-party management practices. These requirements ensure that CIIs adopt a proactive and structured approach to safeguarding critical systems, enhancing national cyber resilience, and maintaining operational continuity against evolving cyber threats.

What steps to be taken for CIIs?

1

Asset management

Maintain an up-to-date inventory of assets supporting CIIs’ services.

ABB can assist you in creating procedures that promote a culture of cybersecurity and ensure the asset inventory is properly maintained.
2

Risk Assessment and Risk Management Strategy

Conduct a cybersecurity risk assessment annually or when major changes impact CIIs, following the committee’s risk management policy.

ABB conducts IEC 62443-based risk assessments of any production system independent of the ICS vendor.
3

Access Control

Limit CIIs’ access to authorized personnel, activities, equipment, and interfaces; supervise interface/logical access; and regularly review access logs.

ABB helps implement security by default, defense in depth and least privilege.
4

System Hardening

Establish security baseline configuration standards for all operating systems, applications, and network devices of critical services, aligned with their cybersecurity risk profile.

ABB helps implement security by default, defense in depth, least privilege.
5

Remote Connection

Ensure all remote connections to critical services have effective cybersecurity measures to prevent and detect unauthorized access.

ABB helps implement cryptographic measures, including encrypted communication, signed software packages, and secure remote access.

How ABB can help:

  • Secure Remote Access
6

Removable Storage Media

Ensure strict controls on connecting removable media and portable devices to critical services.

ABB helps implement security by default, defense in depth:
7

Cybersecurity Awareness

Prioritize cybersecurity awareness programs for employees, contractors, and third-party providers with access to CIIs.

ABB improves your team's capacity to recognize and tackle cyber threats.

How ABB can help:

8

Cyber Threat Detection and Monitoring

Establish mechanisms and processes to:

  1. Detect all cybersecurity incidents related to critical services,
  2. Classify and analyze detected incidents, and
  3. Determine if they involve cyber threats to critical services.
9

Cybersecurity Incident Response Plan

Develop, communicate, drill, review, and update the cyber threat response plan at least annually to ensure its effectiveness.

10

Cybersecurity Resilience and Recovery

Develop a Business Continuity Plan (BCP) to ensure critical services remain operational during cyber incidents, validate third-party plans for alignment, and ensure consistency in scope, MTPD, RTO, and RPO.

ABB helps with contractual commitments of resources with appropriate response times and creating technical recovery plans.

How ABB can help:

 

Why is cybersecurity important?

critical-infra-icon
Protecting critical infrastructure

Power plants are vital to national energy supply. Cyber security helps prevent disruptions or attacks that could affect the energy grid, ensuring continued power delivery to businesses and communities.

preventing-damage-icon
Preventing damage

Cyberattacks on OT systems can directly affect the physical components of the plant, such as turbines or generators, leading to costly damage, safety hazards, or environmental disasters.

operational-continuation-icon
Ensuring operational continuity

OT systems are essential for monitoring and controlling plant processes. Effective cybersecurity ensures that these systems run without interruption, reducing downtime and maintaining plant efficiently.

compliance-with-regulations-icon
Compliance with regulations

Compliance with standards like NIST, ISO 27001, IEC 62443, and Thailand's Thai Cybersecurity Act ensures power plants meet legal and regulatory cybersecurity requirements, safeguarding critical infrastructure.

security-lifescycle
Ransomware attacks surged by 151% in 2021, costing OT environments an average of $4.82 million per incident. Yet, 48% of organizations are unaware if their systems have been compromised. Another study from Sophos found that 62% of critical infrastructures, including energy sector, were impacted by ransomware attacks as compared to 49% across other sectors such as manufacturing, construction, and IT. Hence, cybersecurity is no longer optional—it's essential for protecting operations, ensuring uptime, and maintaining business resilience.

At ABB, we provide guidance to help you prepare for ransomware attached before they happen. Our proactive cyber security approach enables early detection of vulnerabilities, real-time threat monitoring, and implementing preventive measures. Download the e-book to learn how to protect your operations and build ransomware resilience.

ABB’s Risk Reduction Roadmap

We have a complete portfolio of offerings that help our customers manage OT cyber security risks and support Thailand Cybersecurity Regulation.
risk-reduction-roadmap

Success stories

Resources

Wondering where to start?

Wondering where to start?

You likely have questions about the regulatory requirement and how it impacts your organization. ABB Ability™ Cyber Security offers a comprehensive solutions. Our cyber security experts can guide you through the compliance transitions.

Let’s collaborate to ensure your organization are compliance with the new Thailand's Cybersecurity Act updates.

Wondering where to start?
  • Contact us

    Submit your inquiry and we will contact you

    Contact us
Select region / language