Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Business Law News

    Cybersecurity Act B.E. 2562 (2019): NCSA, CII, and Sector Obligations

    The Cybersecurity Act B.E. 2562 (2019) established the National Cyber Security Agency (NCSA) and the Critical Information Infrastructure (CII) framework. Designated CII organisations must register with NCSA, implement controls, and report incidents. This guide covers designation thresholds, obligations, and penalties.

    6/1/20269 min read read
    cybersecurity
    NCSA
    CII
    B.E. 2562 (2019)
    incident response

    TL;DR

    The Cybersecurity Act B.E. 2562 (2019) (พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์) established the National Cyber Security Agency (NCSA / สกมช.) and a tiered regulatory framework. Organisations designated as Critical Information Infrastructure (CII) across 8 sectors must register with NCSA, implement minimum controls, report incidents, and submit to NCSA inspection. Non-designated organisations have lighter obligations but may still be subject to incident reporting via the sectoral regulator. Penalties under Sections 70+ reach THB 200,000 per violation plus directors' personal liability.

    Eight CII Sectors

    1. National security
    2. Public services (utilities, water, electricity)
    3. Banking and finance
    4. Information technology and telecommunications
    5. Transportation and logistics
    6. Energy and natural resources
    7. Public health
    8. Other sectors designated by NCSA Notification

    CII Designation Criteria

    FactorIndicator
    Service significanceImpact on national security, economy, public services
    Customer / user baseScale of dependency
    System interconnectionCascade effect on other CII
    Sector concentrationLimited alternative providers

    Obligations of Designated CII Organisations

    • Register with NCSA and designate a Chief Information Security Officer (CISO).
    • Implement information security management system aligned with NCSA standards (commonly ISO/IEC 27001 family + sectoral overlays).
    • Maintain incident response capability and tested business continuity plans.
    • Annual risk assessment and reporting.
    • Incident reporting to NCSA within prescribed timelines (typically rapid — hours to days).
    • Submit to NCSA inspection and audit.
    • Cybersecurity awareness training for staff.

    Incident Reporting Timelines

    SeverityExamplesAction
    CriticalService disruption, data exfiltration affecting national securityImmediate notification; full report within 24 hours
    HighSignificant breach, ransomwareNotification within 24-72 hours per NCSA guidance
    Medium / LowContained incidentsPeriodic reporting via NCSA dashboard

    NCSA Powers

    • Inspect CII organisations.
    • Issue directives in major incidents.
    • Require remediation timelines.
    • Coordinate sector-wide response to systemic threats.
    • Cross-border cooperation with foreign cybersecurity agencies.

    Penalties

    • Administrative fines up to THB 200,000 per violation.
    • Director liability for failure to implement controls.
    • Compounding penalties for ongoing non-compliance.
    • Reputational and regulatory consequences in regulated sectors.

    Common Mistakes

    Avoid these traps:
    • Assuming non-designation now means non-applicability forever — NCSA can designate based on evolving criteria.
    • Treating cybersecurity as IT-only — Cybersecurity Act expects board-level governance.
    • Inadequate incident response — generic plans without tested playbooks fail under NCSA review.
    • Conflicts with PDPA obligations — breach notification may have different timelines under Cybersecurity Act vs PDPA.
    • Underestimating supply-chain risk — CII organisations are accountable for vendor security postures.

    FAQs

    1. How do I know if my organisation is designated CII?

    NCSA publishes designations sectorally. Confirm with NCSA or sectoral regulator. Designation can change.

    2. Is voluntary registration possible?Some sectoral regulators encourage voluntary disclosure or registration. NCSA cooperation programmes exist for non-designated entities.

    3. How does the Cybersecurity Act interact with PDPA?Both apply concurrently. Personal data breach reporting under PDPA (72 hours to PDPC) is separate from cybersecurity incident reporting under Cybersecurity Act (NCSA). Both may be triggered by the same incident.

    4. Are foreign-owned CII organisations subject to the same rules?Yes — application is jurisdictional, not nationality-based. Foreign-owned banks, telecoms, etc. operating in Thailand are within scope if designated.

    5. What standards does NCSA reference?ISO/IEC 27001/27002, NIST Cybersecurity Framework, sectoral standards (Bank of Thailand cybersecurity standards for banking; SEC for capital markets; etc.). NCSA also issues Thai-specific notifications.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful