In brief

Thailand's National Cyber Security Committee (NCSC) has released draft amendments to the Cybersecurity Act B.E. 2562 (2019) ("Draft Amendment") for public consultation and will be submitted to the Cabinet and Parliament for consideration. If enacted, it will proceed for Royal Assent and publication in the Government Gazette.

Key amendments include:

  • Introduction of a clear distinction between "cyber threat" and "cyber threat incident"
  • Expansion of cyber incident reporting obligations to certain private-sector organizations to be prescribed by future regulations
  • Indirect regulation of external service providers that provide services to Critical Information Infrastructure (CII) organizations
  • Potential blacklisting of external service providers that fail to comply with cybersecurity standards or the Cybersecurity Act
  • Introduction of the "industrial sector" as a new CII category

In more detail

1. Distinction between "cyber threat" and "cyber threat incident"

The Draft Amendment would introduce a clear distinction between the terms "cyber threat " and "cyber threat incident."  Other provisions would also be revised to reflect this distinction.

Under the Draft Amendment, a "cyber threat" would refer to any unlawful act or activity involving the use of computers, computer systems, or computer data, whether occurring within or outside Thailand, that may harm or affect the operation, image, reputation, property or personnel of a government agency, regulator, CII organization, or private-sector organization. A "cyber threat incident" would refer to an event that may compromise the confidentiality, integrity, or availability of a computer, computer system, computer data, or other data as a result of such cyber threat.

2. Expanded cyber incident reporting obligations

Certain private-sector organizations, to be prescribed under future subordinate regulations, may be required to report cyber incidents that affect, or may affect, cybersecurity (e.g., national security, military security, economic security, international relations, or public order). Failure to submit a required report without reasonable grounds may result in criminal penalties.

3. Indirect regulation of cloud, outsourcing, and other service providers

The Draft Amendment would require CII organizations to oversee and monitor their external service providers to ensure compliance with prescribed cybersecurity standards and the Cybersecurity Act. If a service provider fails to remedy the non-compliance within 60 days, the NCSC may require the CII organization to consider discontinuing the relevant services from such non-compliant providers.

4. Regulatory blacklist

The Draft Amendment would require the NCSC to notify government agencies, relevant supervisory authorities, and CII organizations of the names of such non-compliant providers, effectively creating a regulatory blacklist mechanism of non-compliant providers without any opportunity for the service providers to respond before inclusion on the blacklist.

5. Other amendments

Notable amendments include:

  • The introduction of a new industrial-sector CII category
  • Increased penalties for certain non-compliance that results in a cyber threat incident, further damage, or the death of another person
  • A criminal settlement mechanism for certain offenses

Next steps

Businesses providing services to CII organizations (e.g., enterprise software licenses and maintenance services, AI-related services, and cloud services) should closely monitor the Draft Amendment, as they could become indirectly subject to cybersecurity standards and Cybersecurity Act requirements imposed through their relationships with CII customers, including through contractual terms in a service agreement, proposals, terms of reference, or purchase orders.

* * * * *

Aue-angkul Santirongyuth, Teetouch Dilokgomon, Phocharaphol Yingamphol, and Pirun Suttiprapha, Associates, have contributed to this legal update.

Explore More Insight