Cropped Image

Cybersecurity

Cybersecurity

Policy & Commitment​

The Company is committed to building a resilient cybersecurity posture that protects critical Information Technology (IT) and Operational Technology (OT) systems, as well as digital assets and data, from evolving cyber threats. The Information and Cyber Security Policy serves as the foundation for safeguarding the Group’s information assets and applies to all business entities, employees, contractors, and third parties with access to our systems. Grounded in the CIA Triad (Confidentiality, Integrity, and Availability), the policy establishes a comprehensive Information Security Management System (ISMS) aligned with ISO 27001:2022. We are committed to compliance with applicable data protection regulations in the jurisdictions where we operate, the continuous improvement of our defense mechanisms, and the cultivation of a security-aware culture in which every employee serves as a first line of defense.

Management Approach​

Banpu manages cybersecurity through a multi-tiered structure that links Board oversight with management execution. At Board level, the Audit Committee oversees internal controls and cybersecurity audit findings, while ESG Committee provides oversight of cybersecurity as a material sustainability topic. At management level, Risk Management Committee evaluates cyber risks and ensures mitigation measures are in place across business units, the Business Continuity Management Committee ensures cyber resilience against disruptive events, and the Sustainability Committee oversees the integration into long-term business strategy.

The Company has appointed a Global Information Security Officer (GISO) and a Data Protection Officer (DPO) to oversee data privacy and cybersecurity strategy, supported by the ISMS Committee and a senior executive responsible for global enterprise architecture and cybersecurity, ensuring consistent implementation and alignment with international standards.

The cybersecurity framework covers both IT and OT environments across all operating countries, with emphasis on continuous vulnerability identification, third-party risk management, and proactive threat detection through the Security Operation Center (SOC). Annual Disaster Recovery Plan (DRP) exercises are conducted and independently assessed as part of Business Continuity Management System (BCMS) certification. The Bug Bounty Program enables 24/7 vulnerability assessments through ongoing collaboration with ethical hackers. Banpu also conducts annual audits, including ISO27001:2022 certification, and continues to enhance awareness efforts to foster a security-focused mindset and reinforce accountability at all levels.

Cybersecurity Incident Management

Banpu continually strengthens our cybersecurity capabilities through an enhanced cyber incident management framework, underpinned by decentralized Security Operations Centers (SoCs) that respond to dynamic business contexts across the Group while fostering active collaboration within our cyber community. The framework provides a structured, timely, and effective response to potential cyber threats through continuous monitoring, threat detection, and coordinated incident handling. It defines a comprehensive end-to-end process, covering identification, investigation, containment, recovery, and reporting of cyber incidents, enabling rapid decision-making and minimizing operational and business impact.

The framework also ensures seamless coordination among internal teams, external partners, and regional digital units through established communication protocols and information-sharing mechanisms within our cyber community. By promoting real-time exchange of cyber threat intelligence and shared incident learnings across regions, we strengthen our collective cyber defense posture while addressing emerging risks, including third-party risks within the digital supply chain and advanced threats. Together, these measures reinforce Banpu’s commitment to proactive risk management, regulatory compliance, continuous improvement, and resilient, secure operations across all business units.

Cybersecurity Governance

The Company manages cybersecurity through a multi-tiered structure that bridges Board-level oversight with management-level execution. At Board level, the Audit Committee oversees the integrity of internal controls, including cybersecurity and IT audit findings, while the ESG Committee integrates information security into the Group’s sustainability goals and ESG reporting framework.

At management level, 3 committees share responsibility for execution. The Risk Management Committee evaluates cyber risks and ensures that mitigation measures are in place across business units. The Business Continuity Management Committee ensures cyber resilience and readiness to respond to disruptive events. The Sustainability Committee incorporates secure digital transformation into long-term business strategies.

To translate governance into day-to-day practice, a Global Information Security Officer (GISO) has been appointed to lead the Company’s data privacy and cybersecurity strategy, supported by the Information Security Management System (ISMS) Committee, which ensures that related policies and practices are consistently implemented across business functions. To further strengthen digital governance, a senior executive for global enterprise architecture and cybersecurity has been appointed to work alongside the GISO and management team to further enhance cyber resilience and ensure alignment with international standards.

ISO 27001 Certification

Banpu’s Information Security Management System (ISMS) is certified to the ISO 27001:2022, covering the management of cloud-based Infrastructure-as-a-Service (IaaS) and the infrastructure that operates Internet of Things (IoT) devices. These foundational technologies are governed to ensure maximum resilience, availability, and secure operations amid evolving cyber risks. By safeguarding these essential digital assets, the Company enhances operational continuity and supports the reliability of services vital to business performance and stakeholder trust. This certification serves as independent validation of our commitment to maintaining the highest global standards for data integrity and infrastructure security.

Third-Party Cybersecurity Management

Banpu strengthens cybersecurity governance through structured third-party cyber risk management guidelines, which are embedded into procurement and vendor performance review processes. These guidelines help the Company assess and mitigate cyber risks arising from third-party and extended (Nth-party) relationships across the digital supply chain. The framework applies throughout the third-party lifecycle, from pre-engagement due diligence and contractual safeguards to onboarding, ongoing monitoring, and secure offboarding. It also incorporates Information Security Management System (ISMS) controls for externally connected vendor digital systems.

Key measures include risk-based vendor classification, cybersecurity assessments and certifications, contractual data protection and breach notification requirements, continuous security monitoring, and access control enforcement. Through these measures, Banpu strengthens the protection of sensitive data, supports operational continuity, ensures regulatory compliance, and reinforces resilience against supply-chain-related cyber threats, reflecting the Company’s commitment to responsible governance and sustainable digital operations.

Year in Review​

In 2025, Banpu strengthened our cybersecurity and digital resilience through an integrated set of governance, operational, and people-focused initiatives. These were delivered through close collaboration among regional digital teams, internal audit functions, and external security partners under a harmonized checks-and-balances approach that provides independent oversight, consistent risk assessment, and effective coordination across the organization. This model enables real-time monitoring, incident response, proactive risk mitigation, and adherence to industry standards.

By aligning internal operations with external assurance and expertise, we enhanced the protection of our digital ecosystems, supported operational continuity, and reinforced stakeholder trust in secure and sustainable digital operations. During the year, 100% of our critical IT systems were covered by vulnerability assessment, ensuring no blind spots in our digital defense. We also met all defined cybersecurity performance targets, with no significant cybersecurity incidents recorded.

In addition, the Company established cybersecurity targets for 2026–2030. The new targets cover process-controlled areas, such as critical IT systems with cybersecurity risk assessment and vulnerability assessment, as well as targeted training and simulation exercises, such as phishing resiliency rates, to further strengthen employee readiness against social engineering and AI-driven threats.

Performance Data

Feedback