ThaiBev has established a systematic approach to manage digital and technology governance that covers all departments, both domestically and internationally, in order to protect the organization from cyber threats and ensure compliance with cybersecurity regulations. This includes the establishment of the Digital and Technology Group and Digital and Technology Services Co., Ltd. who are responsible for strategic management as well as definition of operational frameworks according to international standards, such as ISO 27001. The focus is on cyber risk management as well as formulation of security policies. Accordingly, ThaiBev has set up Group Center, which is divided into three main management areas:
1. Commercial, Strategy and Governance Group
This group is responsible for defining technological framework to be consistent with the company’s business goals.
2. Technical Strategy and Architecture Group
This group sets guidelines for technology development and improvement, including structure and system design to achieve organizational goals.
3. Solution Design and Development Group
This group is tasked with establishing innovative technologies to meet user needs.
Commercial, Strategy and Governance Group has adopted the NIST Cybersecurity Framework, developed by the US National Institute of Standards and Technology, to prevent, detect, and respond to cyber threats at the highest level of effectiveness.
In addition, ThaiBev realizes that the potential risk of personal data breaches, unauthorized use of information, or cyberattacks leading to legal actions, compensation claims, and significant damage to our reputation and customers’ and other stakeholders’ trust. Therefore, we carefully manage the personal data of all stakeholders with great care. In the event of a breach or cyberattack, a report will be reviewed based on the obligations of relevant departments, in accordance with established criteria, and published on ThaiBev’s website, which is in compliance with the Personal Data Protection Act (PDPA) and the company’s policies. This approach aims to prevent human rights violations, legal penalties, and damage to the organization’s reputation.
Heading into 2025, ThaiBev is preparing to address increasingly complex challenges, including the continuous evolution of cyber threats and regulatory requirements.
A strategic plan has been developed, focusing on
technology and future trends, along with enhancing security infrastructure across all areas, particularly with regard to data security and privacy.
- Establish a Digital and Technology Policy Framework
to ensure comprehensive governance of digital and
information operations, supporting business goals,
risk management, legal and regulatory compliance,
and organizational performance measurement, in
alignment with the company’s objectives and strategies.
- Develop an Artificial Intelligence (“AI”) Policy to guide IT team members and external service providers in AI projects. The aim of this policy is to enhance operational
efficiency and reduce production costs by using AI
to process data for production planning, supply chain management, and environmental considerations, while aligning with the company’s values and adhering
to ethical and legal standards.
- Expand the scope of Operational Technology Network Cybersecurity Protection Systems to leverage real-time data analytics more effectively, aligning with the
increased connectivity of Operational Technology (“OT”) networks to the internet. The focus will be on protecting control systems and networks from any form of
cyberattacks.
- Develop a process to assess the cybersecurity resilience of business partners and suppliers to mitigate risks related to data leaks, cyberattacks, or security breaches that could impact the organization.
- Enhance cybersecurity measures through AI and machine learning to detect threats, analyze real-time data, and predict attacks from large datasets, while also reducing the workload of the cybersecurity teams.
- Develop cybersecurity systems to connect devices through networks or the Internet of Things, including firmware updates, data encryption, and monitoring systems to address potential threats.
- Continually develop automatic detection and response systems to improve the efficiency of threat response, by collecting data, monitoring, and executing rapid countermeasures. This approach will reduce the time spent on threat detection and management, enabling the organization to prevent severe attacks promptly.