31 December 2025
Governance and Economic

Cybersecurity Awareness Program

The Company places importance on building cybersecurity awareness among employees at all levels through the Cybersecurity Awareness Program and training provided through KM activities at least once or twice a year. These activities enhance employees’ knowledge and understanding of cyber threats, malware prevention, phishing attacks, appropriate practices for using information systems, and the protection of corporate data.

In addition, the Company encourages employees to participate in monitoring and reporting information security incidents through the Service Desk Management System, which serves as the Single Point of Contact (SPOC) for incident reporting. This enables incidents to be tracked, resolved, and managed promptly and efficiently while reducing potential impacts on business operations.

The Company maintains preparedness through its Business Continuity Plan (BCP) and information security incident response to strengthen the security of its data, information systems, and operations on a sustainable basis.

Benefits from the Program

  • Executives and employees who attended the training and passed the Cybersecurity Awareness test accounted for 50% of all executives and employees, with an average correct response rate of 79%.
  • Training hours for executives and employees increased by one hour per person per year.

The Company detected two data breach incidents involving certain items of data relating to members and personnel within the Group. The Company promptly contained and managed the incidents through an Incident Response process aligned with the requirements of the Personal Data Protection Act (PDPA). The incidents did not affect customer data or involve any of the Company’s core systems.

Following the management of the incidents, the Company further strengthened its cybersecurity measures by permitting the use of authorized personal devices only. It also coordinated with cybersecurity experts to investigate the causes, remediate vulnerabilities, and enhance security measures for its networks and information systems, thereby strengthening confidence in its cybersecurity over the long term.