|
| Governance |
ThaiBev places great importance on Cybersecurity Governance in accordance with the NIST Cybersecurity Framework 2.0. The company has established clear policies, roles, and responsibilities at all organizational levels to ensure transparency and accountability in cyber
risk management.
- Expansion of ISO/IEC 27001 Certification Scope:
In 2025, ThaiBev expanded the scope of its
ISO/IEC 27001:2022 certification to include the FYI
Center, reinforcing systematic protection of critical information assets.
- Certification under NIST Cybersecurity Framework 2.0:
ThaiBev achieved certification for the NIST
Cybersecurity Framework 2.0 (NIST CSF 2.0),
which aligns with ISO/IEC 27001 and serves as the
company’s primary framework for managing cyber risks. The framework covers governance, identification, protection, detection, response, and recovery.
The company continuously monitors and improves
its systems to address evolving cyber threats and strengthen stakeholder confidence in the digital era.
- Annual Risk Assessment and External Assurance and Verification
To ensure cybersecurity measures meet international standards, ThaiBev conducts annual risk assessments and undergoes internal and external audits at least once a year by independent bodies. These assessments help identify and resolve vulnerabilities, drive continuous improvement, and ensure compliance with global best practices.
ThaiBev has adopted a robust cybersecurity strategy that not only identifies and addresses vulnerabilities but also continually strengthens its security posture against potential threats. Accordingly, we conduct ongoing external and internal audits of IT systems and networks on a regular basis to ensure that they have the highest level of security and resilience.
- Independent audits shall be performed at least annually to ensure that the organization addressesnonconformities with established policies, standards, processes, and compliance obligations.
- Audit plans shall focus on reviewing the effectiveness of security operations implementation.
- The internal audit results comply with the requirements of the ISO/IEC 27001:2022 standard.
- External Audit – Overall Conclusion:
The overall management system has been effectively implemented and is properly operated to ensure the achievement of its intended outcomes and In the past year, it has been certified by BSI.
- Risk Management Strategy:
ThaiBev identifies
information assets, threats, and vulnerabilities;
evaluates likelihood and impact; and categorizes
risk levels to develop effective mitigation plans.
This structured approach enables the company to
proactively manage threats, minimize vulnerabilities, and protect vital organizational data and systems.
- Communication Plan:
The company maintains timely, accurate, and comprehensive communication of
cybersecurity information to minimize confusion,
increase transparency, enable swift incident response, and build trust among all stakeholders.
- Supply Chain Risk Management:
ThaiBev has
established clear cybersecurity requirements for
third parties and business partners. All agreements are
formally governed by contracts, and partner risk
assessments are conducted regularly. Additional measures are implemented to mitigate supply chain risks, protect sensitive data, and strengthen stakeholder confidence across all levels.
- Environmentally Friendly Data Center:
ThaiBev utilizes the STT Bangkok Data Center, certified under ISO/IEC 27001:2022, ensuring robust data security. The facility has also earned the LEED Gold certification from the U.S. Green Building Council, reflecting ThaiBev’s commitment
to environmental responsibility and sustainability.
- Personal Data Protection Compliance:
ThaiBev complies with the Personal Data Protection
Act B.E. 2562 (PDPA) and the company’s internal policies to ensure systematic and transparent management
of personal data. This includes oversight of data
collection, consent-based data usage, access requests, and awareness initiatives. The company conducts PDPA training for new employees, annual refresher courses, and workshops to deepen practical understanding.
It also maintains a Personal Data Protection Handbook written in clear, accessible language to ensure consistent privacy compliance across all subsidiaries.
|
| Identify |
ThaiBev implements the Identify function of the NIST Cybersecurity Framework 2.0 to identify and understand information assets, business processes, and potential
cyber risks. This involves maintaining an asset inventory, conducting risk assessments, and prioritizing protection measures systematically to ensure efficient resource management and alignment with corporate strategies.
- Information Asset Inventory:
ThaiBev regularly
develops and reviews its information asset inventory under the ISO/IEC 27001 standard. Each asset has a
designated owner and detailed records, including type, tag/serial number, purchase date, location, and
responsible personnel. This supports effective digital management, user support, and system recovery
in the event of an incident.
- Cybersecurity Risk Assessment:
The company
conducts comprehensive cybersecurity risk
assessments to identify, analyze, and prioritize
threats that may impact its systems, data, and critical infrastructure. This process includes identifying
information assets, analyzing vulnerabilities, assessing likelihood and impact, and defining control measures
to maintain risks within acceptable levels.
- Supply Chain Risk Assessment:
ThaiBev emphasizes cybersecurity risk assessments across its supply chain, establishing clear requirements for external parties and partners under ISO/IEC 27001. This ensures that all partners maintain rigorous cybersecurity standards to protect shared information assets.
|
| Protect |
Under the Protect function of the NIST Cybersecurity Framework 2.0, ThaiBev implements preventive measures to strengthen the security of its information systems
and critical data. These include access control, user rights management, data encryption, backup and recovery,
and staff training to safeguard confidentiality, integrity, and availability of data.
- Zero Trust Security Model:
ThaiBev applies a Zero
Trust approach, requiring strict authentication and
authorization for every access attempt. Access rights are granted based on necessity (least privilege principle) and centrally managed to reduce unauthorized access risks.
- Secure Virtual Private Network (VPN):
The company uses Secure VPN connections to ensure data
confidentiality and integrity, prevent interception, authenticate users and devices, and enforce role-based access control—supporting secure remote work
environments.
- Firewall Systems:
Firewalls serve as the first line of defense to control data flow, segment networks,
and prevent unauthorized access. ThaiBev continuously reviews, updates, and logs firewall activities for
monitoring and auditing purposes.
- Access Rights Management:
The company enforces strict access control processes following the least
privilege and role-based access principles. Access is immediately revoked upon employee termination,
and periodic reviews ensure rights remain appropriate.
- Cyber Threat Prevention and Intelligence:
ThaiBev utilizes Threat Intelligence and proactive monitoring systems such as Web Application Firewalls (WAF) to detect and block cyberattacks exploiting application vulnerabilities.
OT Network Security: Operational Technology (OT) systems are protected through network segmentation, real-time monitoring, and anomaly detection to prevent cyberattacks targeting production control systems and machinery.
- Email Threat Protection:
ThaiBev employs advanced email filtering systems to detect and block phishing, malicious links, attachments, and malware, preventing data breaches through email channels.
- Virus and Malware Protection:
With Trend Micro
Endpoint Security and Endpoint Detection and
Response (EDR) tools, ThaiBev detects, prevents,
and removes cyber threats promptly. The system’s threat database is continuously updated to address emerging risks.
- Phishing Simulation Exercises:
Regular phishing simulations are conducted to enhance cybersecurity awareness among employees. These exercises help
staff recognize suspicious emails, verify links and
attachments, and report incidents correctly.
- Secure Software and Hardware Management:
The company enforces strict software and hardware management measures—removing unauthorized software, maintaining hardware, and applying security patches—to minimize vulnerabilities.
- IT Capacity Management:
ThaiBev practices
capacity planning, monitoring, and reporting to optimize IT resources (hardware, software, and infrastructure), ensuring scalability and business continuity.
- Penetration Testing:
Certified cybersecurity experts perform penetration tests to simulate internal and external attacks, identify vulnerabilities, and develop corrective actions to reduce risks of cyberattacks
and data breaches.
- Vulnerability Assessment:
Continuous vulnerability assessments are conducted to identify and address system weaknesses. The process includes scanning, reporting, remediation, and applying compensating controls when immediate fixes are not feasible, ensuring all vulnerabilities are effectively mitigated. Source Code Scanning: During development, source code scanning detects vulnerabilities early, allowing developers to fix issues promptly and enhance application reliability and security.
ThaiBev conducts Vulnerability Testing to identify the system weaknesses or flaws that unauthorized parties might exploit. This proactive approach allows administrators to address vulnerabilities before a problem occurs.
- Vulnerability assessment has been conducted and vulnerabilities have been remediated.
- Vulnerability scanning: VA scan reports are provided to system/service owners.
- Remediation: At the completion of each vulnerability scan, system/service owners must review the vulnerability report and ensure that vulnerabilities are remediated.
- Risk-compensating controls shall be performed if applicable.
The purpose of the scan is to identify vulnerabilities in 688 IT assets. The audit results are presented using Tenable software.
The vulnerability scan revealed 109 unique vulnerabilities across 47 assets, categorized by critical, high, medium, and low severity levels, as shown in the table below.
- Attack Surface Management:
Using tools such as
Security Scorecard and Vulnerability Assessment, ThaiBev monitors its digital attack surface—including networks, applications, and public services—to detect weaknesses, prevent data leaks, and reinforce cyber resilience.
- Data Loss Prevention (DLP):
DLP systems monitor,
prevent, and control the unauthorized transfer of
sensitive information, protecting key organizational data from loss or misuse.
- Data Backup and Recovery:
Regular data backup
and restoration testing ensures data integrity and recovery capability in case of cyberattacks or disasters, reinforcing transparency and stakeholder trust.
- Cybersecurity Awareness Training:
ThaiBev provides cybersecurity training for executives and employees
at all levels. Participants must achieve at least 90%
on post-training assessments. Over 15,000 employees were trained in the past year, fostering a strong security awareness culture throughout the organization.
- Digital Communication and Skills Training:
The company also offers digital communication training to improve collaboration, safe information sharing,
and accessibility under connectivity limitations.
Employees’ digital skills are assessed to guide
continuous learning and skill enhancement initiatives.
|
| Detect |
ThaiBev implements the Detect function under the NIST Cybersecurity Framework 2.0 to continuously monitor
and identify cybersecurity incidents in a timely manner. The company employs advanced threat detection and analytics systems combined with behavioral analysis to enable early alerts and effective responses, minimizing potential damage to systems and data.
- Security Monitoring:
ThaiBev conducts continuous
security monitoring using Security Information
and Event Management (SIEM) systems and Threat Intelligence tools to collect, analyze, alert, and respond to incidents. These measures ensure the integrity
and protection of corporate data.
- Centralized Log Management:
Event logs are collected, validated, stored, and analyzed centrally to enhance
visibility and simplify incident investigation. Centralized log storage consolidates data from all systems,
improving traceability and accelerating response times.
- Firewall Activity Monitoring:
Firewall operations are continuously monitored to track network traffic, review access rules, and detect unusual activities. Logs and alerts are reviewed regularly to ensure system integrity.
- Cybersecurity Threat Intelligence:
ThaiBev leverages Cyber Threat Intelligence (CTI) to monitor, analyze,
and predict cyberattacks. Intelligence sources include internal monitoring tools, vulnerability databases,
information-sharing communities, and external
providers. Proactive threat hunting helps the company anticipate and prevent attacks, reducing detection
and response times.
- Cybersecurity Alert Research and AI Analytics:
ThaiBev develops AI-driven cybersecurity solutions using Machine Learning to analyze behavior, identify
anomalies, and intelligently manage alerts. This reduces false positives and enhances detection accuracy,
enabling faster and more contextual responses to emerging threats.
- “Eagle Eye” Cyber Monitoring Center:
ThaiBev
established the Eagle Eye data and infrastructure monitoring center to track real-time cybersecurity and IT infrastructure status. The platform enables immediate incident response, supports executive decision-making, and drives continuous improvement in cybersecurity operations.
|
| Respond |
ThaiBev follows the Respond function of the NIST
Cybersecurity Framework 2.0 to manage and mitigate the impact of cybersecurity incidents effectively. The company maintains a formal Incident Response Plan (IRP) that includes communication protocols, root cause analysis, corrective measures, and continuous improvement processes to control situations quickly and transparently.
-
Information Security Incident Response Process
ThaiBev’s Incident Response Process ensures efficient incident detection, reporting, classification, escalation, and resolution in line with international standards. All incidents are logged in the system and tracked until closure. The process is tested at least once annually and continuously improved based on lessons learned to enhance response readiness and stakeholder confidence.
Thaibev ensure a consistent and effective approach to managing and responding to information security incidents and events.
- Communication Strategy Information security events shall be reported , recorded and applicable legal, statutory, or regulatory compliance obligations.
- Criteria for Classifying High-Severity Information Security Incidents
- Monitoring of Reported Security Incidents
- Information Security Incident Response
- The testing process must be conducted at least once a year.
- Service Improvement Through Knowledge Gained from Information Security Incidents
Measurement and Reporting: Information security event reports must be responded promptly
information Security Incident Response Workflow
|
| Recover |
In line with the Recover function of the NIST Cybersecurity Framework 2.0, ThaiBev ensures rapid recovery of systems and operations following cybersecurity incidents.
The company maintains a comprehensive Recovery Plan and conducts regular Backup and Restoration Testing
to ensure business continuity, minimize downtime,
and strengthen organizational resilience.
- Data Backup System:
ThaiBev performs scheduled data backups and regular restoration tests to safeguard against data loss from
unforeseen events. These efforts ensure smooth
business continuity and operational stability.
- Disaster Recovery Data Center–STT Bangkok:
The STT Bangkok Data Center serves as ThaiBev’s
disaster recovery site, ensuring continuity in case the primary center becomes unavailable due to incidents such as fires, floods, power failures, or cyberattacks.
This minimizes disruption and maintains critical
business operations.
- Service Continuity Management:
ThaiBev implements Service Continuity and Disaster Recovery Management to maintain business operations even during disasters. The process includes defining policies, scope, resources, and recovery structures; risk assessment and strategy selection; plan development, execution, and testing; and regular awareness and training programs. Employees involved in business continuity planning participate in at least two drills per year, and the outcomes are documented with improvement recommendations. Progress updates and recovery statuses are communicated transparently to internal and external stakeholders.
The objective is to bring additional value by keeping the services uninterrupted in the event of a disaster and to maintain the availability targets as agreed.
-
Initiation Phase:
Define the scope of the policy, allocate necessary resources, and establish the project and control structure.
-
Requirements, Strategy, and Tactics:
Business Impact Analysis (BIA), selection of continuity/recovery strategies, risk assessment, and risk treatment planning
-
Implementation Phase:
Develop the Service Continuity Plan (SCP) and implement the selected continuity and recovery strategies.
-
Ongoing Operation and Testing:
Education, awareness, and training; review, testing, and change control.
Maintain test records and conduct testing of the Service Continuity Plan at least twice a year to ensure its effectiveness and readiness.
During the recent test the DHCP server was activated at the DR Site (STTGDC) and FYI Center network service was activated with SCP Plan.
All staff involved demonstrated an understanding of the Business Continuity Plan (BCP), and testing results were documented.
Recommendations for improvement were identified to address any observed weaknesses and enhance the continuity response.
Scope Expansion and Impact
Cybersecurity, data privacy, and risk management governance are core missions in ThaiBev’s effort to expand cybersecurity measures across its business units, including F&N, GRG, and SABECO. The goal is to establish a
centralized cybersecurity standard that enhances
efficiency, reduces complexity and errors, and fosters collaboration across all entities under a unified framework.
Throughout the past year, ThaiBev adopted the NIST Cybersecurity Framework as its principal cybersecurity standard, implementing consistent control measures and practices across subsidiaries. The company integrates advanced security technologies for effective cyber threat prevention and personal data protection.
Each business unit undergoes independent ISO/IEC 27001 and NIST Cybersecurity Framework standard assessments by third-party auditors to validate compliance and the effectiveness of implemented controls. This coordinated approach ensures that all ThaiBev Group entities operate with international-level security, reliability, and resilience.