Thailand's Cyber Threat Landscape and Quantum Readiness
Thailand's National Cyber Security Agency (NCSA) warned of the urgent need for government bodies to upgrade their cyber defenses in line with new national security standards published in the Royal Gazette. The agency reported that Thailand recorded over 3,172 cyber incidents, with government agencies and the education sector being the most targeted. To address these threats, the NCSA has issued the 2025 Website Security Standard, which requires all government agencies and operators of critical national infrastructure to conduct annual self-assessments and implement multi-factor authentication (MFA).
Key Takeaways:
- Thailand recorded over 3,172 cyber incidents, with government agencies accounting for 32% and the education sector at 23% of attacks.
- The most common attack types were fake websites and credential leaks.
- The NCSA has issued the 2025 Website Security Standard, which requires all government agencies and operators of critical national infrastructure to conduct annual self-assessments and implement MFA.
- The NCSA has outlined a national action plan to guide the country's transition into the quantum era, which includes developing a clear national roadmap, raising public and institutional awareness, and conducting a cryptographic inventory of critical assets.
- The NCSA set out key national targets: raise awareness of post-quantum cryptography (PQC) and establish working groups by 2025, require all new projects involving sensitive data to adopt PQC or hybrid encryption by 2030, and achieve full national migration to PQC by 2035.
- The NCSA is developing a self-assessment platform to evaluate agencies' readiness, with plans for large-scale training programmes and international collaborations with leading quantum technology developers.
Statistics:
- Over 3,172 cyber incidents were recorded in Thailand.
- Government agencies accounted for 32% of attacks, while the education sector accounted for 23%.
- 555 government agencies and 117 private organisations have been tested for vulnerability in critical national infrastructure.
- The 2025 Website Security Standard requires all government agencies and operators of critical national infrastructure to conduct annual self-assessments.
- The NCSA estimates that 2048-bit RSA encryption could be cracked within 177 days on a sufficiently advanced quantum computer.
Sources:
- The National Cyber Security Agency (NCSA)
- Royal Gazette
- Gutsan Report (2021)
- Digital Economy and Society Development Fund (DEF)
- United States cybersecurity standards
- United Kingdom cybersecurity standards