Category: Cybersecurity and compliance

  • When should a company in Thailand use an outsourced CISO?

    When should a company in Thailand use an outsourced CISO?

    In many companies in Thailand, cybersecurity is initially handled by the IT manager, an outsourced IT provider or a support team. This can be sufficient while the information system remains simple. It becomes more fragile as cloud applications, remote access, service providers, contractual requirements and sensitive data increase.

    The issue is not necessarily a lack of technical skills. More often, there is no clear owner able to turn risks into decisions, set priorities, coordinate stakeholders and report to management. This is the role an outsourced CISO can provide when a full-time position is not yet justified or is difficult to fill.

    Key takeaways

    • An outsourced CISO primarily provides governance and security leadership. The role is not simply another technical service provider.
    • The model becomes relevant when risks and external requirements grow faster than the organisation’s ability to manage them internally.
    • In Thailand, the PDPA, Cybersecurity Act and sector-specific rules may affect the security programme, but they do not all require every company to appoint a CISO.
    • An outsourced CISO does not replace management, the IT team, the DPO or operational providers. The role clarifies and coordinates their responsibilities.
    • Its value should be visible through a realistic roadmap, clear responsibilities, monitored controls and reporting that management can use.

    The need appears when security no longer has a clear leader

    A company may have a capable IT provider, backups, a firewall and well-administered cloud services while still having weak security governance. Tools do not answer questions such as acceptable risk, budget priorities, responsibility during an incident or whether a new supplier should be approved.

    An outsourced CISO provides this management function. The role helps leadership identify risks that require a decision, formalise useful rules, track action plans and verify that agreed controls are actually implemented. Responsibility for business decisions nevertheless remains within the company.

    This approach is consistent with governance principles promoted in Thailand. The Thai SEC Corporate Governance Code, for example, asks the boards of companies within its scope to include IT risk in risk management and ensure that IT security policies and procedures are in place. This is a sector-specific governance framework, not a general obligation for every SME.

    Situations where an outsourced CISO becomes relevant in Thailand

    The company has grown without a dedicated security function

    As new applications, SaaS services, remote access and providers accumulate, day-to-day operations can continue while nobody has a consolidated view of risk. An outsourced CISO can map critical assets and dependencies, clarify responsibilities and build an improvement programme that fits the company’s resources.

    A subsidiary must implement the requirements of an international group

    A Thai subsidiary may need to apply security policies, standards, questionnaires or controls defined by a foreign headquarters. The challenge is to adapt those requirements to local systems, suppliers and practices, then produce evidence that the group can actually use.

    A local outsourced CISO can act as the interface between management in Thailand, the IT team, service providers and the group security function. This helps avoid both mechanically applying a model designed elsewhere and treating group requirements as a purely documentary exercise.

    Customers and partners are asking for stronger assurances

    A security questionnaire, contractual clauses, a request for a formal policy or evidence of access management can reveal a lack of structure. These requests do not necessarily create a regulatory duty, but they may become a commercial condition.

    The outsourced CISO helps the company respond consistently and distinguish between controls that are genuinely in place and measures that are only planned. Commitments made to customers should match the organisation’s actual practices.

    An incident exposed weaknesses in the organisation

    After ransomware, a compromised account, a data leak or a major outage, restoring systems is not enough. The organisation must understand the causes, assign corrective actions and make sure they are completed.

    An outsourced CISO engagement can turn lessons from the incident into an improvement plan covering responsibilities, access, backups, suppliers, detection and incident response.

    The company enters a more regulated environment

    Not every Thai company is subject to the same cybersecurity obligations. The Cybersecurity Act B.E. 2562 notably establishes a framework for public-sector bodies and organisations identified as Critical Information Infrastructure. Some industries also have additional sector-specific requirements. The Thai SEC, for example, maintains specific IT and cybersecurity requirements for several categories of regulated operators.

    In these environments, an outsourced CISO can strengthen governance and readiness for reviews, but the scope of the engagement must be aligned with the rules that actually apply to the organisation.

    What an outsourced CISO should actually manage

    A sound engagement should not stop at a list of recommendations. It should create a management process that leadership can follow over time.

    • mapping risks, assets, applications, service providers and critical dependencies;
    • a roadmap prioritised by risk, effort, budget and operational constraints;
    • the policies and procedures that are genuinely needed, without producing unnecessary documentation;
    • governance of identities, privileged access and high-risk accounts;
    • third-party and cloud service risk management;
    • preparation and coordination of incident response;
    • security awareness for employees and business managers;
    • preparation for audits, customer questionnaires and sector-specific reviews;
    • regular reporting to management using indicators that are understandable and actionable.

    The exact scope depends on the organisation. A professional-services SME, a factory, a digital platform and a subsidiary of an international group do not have the same assets, threats or constraints.

    What an outsourced CISO does not replace

    An outsourced CISO does not replace a system or network administrator, the support team, a SOC, an MSSP, an auditor or a penetration-testing provider. Those functions operate or assess controls. The CISO organises governance, sets priorities and checks that actions address identified risks.

    The role does not replace the DPO either. Under the Thai PDPA, the appointment of a Data Protection Officer is subject to specific conditions. Data protection and cybersecurity overlap in areas such as security measures and breach management, but the functions remain distinct. The organisation should therefore define responsibilities between management, the CISO, the DPO, IT and service providers.

    Finally, the outsourced CISO does not make business decisions on behalf of management. The role can recommend, document and prepare decisions. Acceptance of significant risk, budgets and business priorities remain management responsibilities.

    PDPA and cybersecurity should be connected without being confused

    The Thai PDPA requires organisations within its scope to protect personal data with appropriate security measures. Resources from the Personal Data Protection Committee explicitly address Security Management and breach management. These topics require close cooperation between compliance and security functions.

    PDPA compliance alone does not create a complete cybersecurity programme. A company must also protect assets that are not necessarily personal data, including privileged accounts, technical secrets, intellectual property, system availability, backups and business continuity.

    The outsourced CISO should therefore work with the DPO where responsibilities overlap, without reducing cybersecurity to an extension of privacy compliance.

    Several outsourcing models are possible

    A mature organisation may need regular part-time security leadership. Another company may need a structured engagement to reset responsibilities, risks and the roadmap. A growing business may also use an outsourced CISO as a transition before recruiting an internal security leader.

    The appropriate model depends on the number and importance of decisions to be made, risk exposure, IT maturity, regulatory constraints and the ability of internal teams to execute actions. It should not be selected solely by purchasing a fixed number of consulting days.

    How to know whether the time has come

    Several questions help assess the situation:

    • Does management regularly receive a clear view of the organisation’s main cyber risks?
    • Is there an identified person who can prioritise security beyond day-to-day IT operations?
    • Are responsibilities between the company and its service providers clearly defined?
    • Are critical access rights, suppliers, backups and incident-response plans reviewed periodically?
    • Can requests from customers, the group or a regulator be handled without improvisation?
    • Are actions decided after an audit or incident tracked through to closure?
    • Does the organisation clearly distinguish the responsibilities of the CISO, DPO, IT function and management?

    If several answers are negative, the primary need is probably not another security product but a structured security leadership function.

    Choosing an outsourced CISO for an organisation in Thailand

    The selection should focus as much on governance capability as on technical expertise. The provider must be able to work with management, business owners, the IT team and suppliers. It should understand the Thai environment and know how to integrate international requirements when they genuinely apply to the company.

    For organisations operating across several countries, the ability to collaborate in the languages used by local teams and the wider group is also important. Deliverables should remain understandable locally while still being usable by headquarters or an international customer.

    The arrangement should also increase the organisation’s autonomy. Risk analyses, policies, action plans and reports should remain usable if the provider changes.

    A management role before a technical role

    Using an outsourced CISO in Thailand becomes relevant when cybersecurity requires regular leadership but the organisation does not yet have that function internally. Growth, an incident, group requirements, customer demands or a more demanding sector-specific framework can all be triggers. The common point is that security has become a management issue, not only an IT operations issue.

    The right approach is to define the mandate, responsibilities and expected outcomes before choosing the outsourcing model. Cybersiam approaches cybersecurity and compliance through governance, risk management and continuous improvement for organisations operating in Thailand.

  • GDPR and PDPA: what Thailand-based companies with European clients need to know

    GDPR and PDPA: what Thailand-based companies with European clients need to know

    For a company based in Thailand, the relationship between GDPR and PDPA in Thailand depends on the processing activity. The Thai PDPA is the main framework, while the European GDPR may apply to certain activities. Simply having European clients does not make the GDPR applicable to every processing activity. The analysis must consider the company’s establishment, the people targeted and the services offered. It must also cover data flows between the European Union and Thailand.

    For a Thai company working with Europe, the issue is not choosing between two regulations. It is building clear data governance. That governance must identify which law applies, to which processing activity and with which obligations.

    Key takeaways

    • The PDPA is the main data protection framework for processing activities falling within the operations of a company established in Thailand.
    • The GDPR may also apply where there is an EU establishment, a targeted offering to people in the Union, or monitoring of their behaviour.
    • Having a European client alone does not automatically make the GDPR applicable to all of a company’s processing activities.
    • Personal data transfers from the EEA to Thailand must be identified and appropriately safeguarded when GDPR Chapter V applies.
    • A common governance framework for processing, rights, contracts, incidents and risks helps address GDPR and PDPA requirements without unnecessary duplication.

    The PDPA is the reference framework in Thailand

    The Personal Data Protection Act B.E. 2562 (2019), generally known as the PDPA, is Thailand’s main personal data protection law. Its principal provisions have been fully applicable since 1 June 2022. It governs, among other things, the collection, use, disclosure, retention and security of personal data.

    Like the GDPR, the PDPA is built around several core principles. Organisations need a lawful basis, clear information for data subjects and justified limits on purposes and retention. They must also protect personal data and enable individuals to exercise their legal rights. Consent is therefore not the only possible legal basis for processing.

    A company established in Thailand should first identify the processing activities subject to the PDPA and its role as controller or processor. It should then document the lawful bases used, any sensitive personal data involved and the associated security measures.

    When can the GDPR apply to a Thai company?

    The territorial scope of the GDPR is defined by Article 3. For a company based in Thailand, three situations in particular should be distinguished.

    The company has an establishment in the European Union

    The GDPR may apply when processing takes place in the context of the activities of an establishment in the European Union. This remains true even when the technical processing is carried out in Thailand. The physical location of the servers is therefore not decisive on its own.

    The company targets people who are in the European Union

    A company with no establishment in the Union may also fall within the GDPR when it processes data relating to people who are in the Union. The processing must be connected with an offer of goods or services to those people. Whether payment is required does not change this criterion.

    The company monitors the behaviour of people in the European Union

    The GDPR may also apply when a company outside the Union monitors the behaviour of people in the Union. This can include certain profiling or online tracking activities. Those activities may be used to analyse or predict preferences, behaviour or movements.

    By contrast, having a French, German or other European client does not automatically make the GDPR applicable. Nationality is not the test under Article 3. The actual context of the processing must be assessed.

    GDPR and PDPA share a common foundation

    The two frameworks share enough core principles to support coherent governance. Under both regimes, organisations must identify processing activities and purposes, select an appropriate lawful basis and inform individuals. They must also manage retention and rights requests. Security measures must remain proportionate to risk.

    • Map processing activities and data flows.
    • Identify controllers, processors and recipients.
    • Document purposes and lawful bases.
    • Organise privacy information for data subjects and the handling of their rights.
    • Define justified retention periods.
    • Implement technical and organisational measures proportionate to risk.
    • Prepare procedures for managing and documenting personal data breaches.

    This similarity does not mean that the two regulations are interchangeable. Specific obligations, exemptions, supervisory authorities and international transfer mechanisms must be assessed separately.

    Differences should be handled as compliance gaps

    The GDPR and the PDPA do not use exactly the same mechanisms or wording. A sound approach is therefore to build a common baseline and then perform a gap analysis for each jurisdiction.

    • Supervisory authorities and procedures differ. In the European Union, competence depends on the country and processing context. In Thailand, the framework falls under the Personal Data Protection Committee and its Office.
    • The conditions for appointing a Data Protection Officer must be assessed separately under each regime.
    • Documentation, record-keeping and risk assessment obligations are not formulated identically.
    • International transfer mechanisms differ and must be coordinated when data flows between Europe and Thailand.
    • Sanctions, administrative procedures and avenues of appeal are governed by distinct legal frameworks.

    Data transfers between the European Union and Thailand are a central issue

    For many companies, the most practical issue goes beyond the territorial scope of the GDPR. It also concerns the transfer of personal data from the European Economic Area to Thailand.

    Thailand does not currently benefit from an adequacy decision from the European Commission. When the GDPR applies, a transfer from the EEA to Thailand must therefore rely on a mechanism provided for in Chapter V.

    In ordinary commercial relationships, the European Commission’s Standard Contractual Clauses are frequently one of the tools used. Depending on the circumstances, an assessment of the transfer conditions and additional safeguards may also be required. Thai rules governing international transfers must be considered in parallel.

    In practical terms, a company must identify which data leaves Europe, its purpose, its recipient, the relevant contractual role and the safeguards used. This mapping is essential before selecting a legal transfer mechanism.

    A DPO and an EU representative are not the same thing

    Two functions are frequently confused. A Data Protection Officer or DPO supports the organisation when appointment is mandatory or voluntary. An EU representative, required by Article 27 in certain situations, represents an organisation that is not established in the Union. That organisation must nevertheless fall within Article 3(2) of the GDPR.

    A Thai company affected by the GDPR’s extraterritorial scope must assess two obligations separately. It must determine whether it needs an EU representative and whether it falls within a case requiring a DPO. One role does not replace the other.

    Data breaches: the 72-hour benchmark exists in both frameworks

    Contrary to a common assumption, the main notification timeframe is not a major difference between the GDPR and the PDPA. The GDPR requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours. This duty does not apply when the breach is unlikely to result in a risk to individuals’ rights and freedoms.

    The Thai PDPA also provides for notification without delay and, where feasible, within 72 hours. This obligation depends on the assessment of risk. Where the risk is high, affected individuals may also need to be informed.

    The operational challenge is to maintain a common incident-management process. It should identify the data involved, assess risk and determine which authorities or individuals must be informed. It should also document decisions and ensure that the requirements of each regulation are met.

    A common method reduces duplication

    When an organisation genuinely falls under both frameworks, managing the GDPR and the PDPA as separate projects often creates duplication. Inventories, procedures and controls may then be repeated unnecessarily. A more efficient approach is to build a common data governance baseline and add the jurisdiction-specific requirements to it.

    1. Map processing activities, applications, providers and data transfers.
    2. Determine the company’s role and the regulation applicable to each processing activity.
    3. Document lawful bases, privacy information and retention periods.
    4. Review processor contracts and international transfer mechanisms.
    5. Assess requirements relating to the DPO, EU representative and impact or risk assessments.
    6. Formalise procedures for data subject rights and breach management.
    7. Establish ongoing monitoring rather than treating compliance as a one-off exercise.

    This approach follows a compliance management model. Legal obligations are connected to the company’s processes, responsibilities, tools and security measures.

    Questions to assess for your organisation

    Before concluding that a Thai company is or is not subject to the GDPR, several questions should be documented.

    • Does the company have an establishment or stable presence in the European Union?
    • Does it intentionally offer goods or services to people who are in the Union?
    • Does it monitor the behaviour of people in the Union?
    • Does it receive personal data transferred from the EEA to Thailand?
    • Which processing activities fall under the Thai PDPA?
    • Do contracts with clients and providers correctly describe roles and data transfers?
    • Have the requirements relating to the DPO, EU representative and data breaches been assessed?

    Building coherent compliance between Europe and Thailand

    A coherent approach to GDPR and PDPA in Thailand can build on their common principles without ignoring their differences. A company based in Thailand should identify its processing activities and international data flows precisely. It can then apply the relevant legal framework to each one.

    Cybersiam supports this approach by connecting cybersecurity and compliance with mapping, governance, security measures and clear responsibilities. The objective is to build a coherent management system. It should cover European and Thai requirements where they genuinely apply.

    This article presents general principles. The exact application of the GDPR, the PDPA and international transfer mechanisms depends on each organisation’s legal and operational circumstances.