Thailand’s Cyber Risk Surge: The Decisions Boards Need to Make Now
Thailand’s cyber exposure is rising. Leaders need to quantify material scenarios and align investment, readiness and risk transfer.
Key Takeaways
- Cyber resilience starts by identifying scenarios that could materially affect enterprise value.
- Threat patterns differ by sector. Controls and response plans should reflect the operating model.
- Compliance is a baseline. Resilience requires tested plans, quantified exposure and informed risk transfer.
|
3,200
|
63%
|
2,618
|
|
cyber attacks per organisation per week in Thailand — 164% above the global average[1]
|
Thai organisations have experienced a data breach[2]
|
cyber incidents recorded in Thailand in 2026 to date[3]
|
Cyber Risk Has Become a Board-Level Issue
Thailand’s cyber threat environment is becoming more complex. The critical boardroom question is not whether attacks are increasing. It is whether leaders understand which cyber scenarios could have the greatest financial, operational and reputational impact.
Many organisations invest in cyber security in response to incidents, compliance requirements or technology priorities. This can lead to more tools, activity and control testing without a clear view of which investments reduce risk most effectively.
Leaders need to shift from activity-based cyber management to decision-based cyber resilience. This means identifying material exposures, quantifying potential loss, prioritising investment and testing whether the business can continue operating under stress.
“A stronger cyber conversation starts with understanding which scenarios could disrupt enterprise value and whether the organisation is making informed decisions before an incident occurs.”
Where the Threat Is Concentrated
SOCRadar’s Thailand Threat Landscape Report 2026 [4] indicates that attackers do not target every sector in the same way. The executive priority is to understand how the organisation’s operating model changes the consequences of an attack.
- Public institutions and education providers may face risks related to sensitive data, public trust and regulatory scrutiny.
- Manufacturers may face operational disruption, logistics delays, contractual penalties and lost revenue.
- Financial institutions may need to consider customer protection, regulatory confidence and systemic trust.
- Across sectors, leaders should identify the scenarios that matter most to enterprise value and align controls, response plans and risk transfer arrangements accordingly.
The report identifies data breach and compromise as the leading threat type at 37.83%, followed by denial and disruption at 31.67%. Espionage accounts for 27.84%. These findings reinforce the need to shape resilience around each organisation’s data profile, operating model, regulatory obligations, third-party ecosystem and tolerance for disruption.
Three Threats Reshaping the Landscape
1. Double-extortion ransomware
Ransomware can quickly become a revenue, reputation, legal, regulatory and customer confidence issue. Leaders should understand the full economic impact of a ransomware scenario and determine whether response plans, funding strategies and insurance limits can withstand stress.
2. AI-powered phishing and social engineering
AI can make deception faster, more localised and more credible. Awareness training remains important, but it should not be the only line of defence. Leaders should also review identity controls, payment authorisation processes, executive impersonation protocols and crisis communications.
3. Supply chain and third-party compromise
A cyber incident may begin with a trusted vendor, software provider, cloud platform or remote-access channel. Boards should ask whether the organisation has mapped critical dependencies, established meaningful contractual protections and tested practical contingency plans.
“The priority is not simply to buy more protection. It is to quantify the exposures that matter most, test resilience against realistic scenarios and make informed decisions about mitigation, retention and risk transfer.”
Test Resilience Before an Incident
Cyber events can become enterprise-wide issues. Preparation can influence whether an incident remains manageable or becomes a prolonged disruption involving customers, regulators, investors, business partners and the media.
The financial impact can extend beyond system recovery. Organisations may face business interruption, forensic costs, legal advice, notification obligations, customer remediation, contractual disputes, regulatory scrutiny and reputational damage. These impacts often sit across different functions and budgets, making them difficult to quantify after an event.
Scenario analysis, financial modelling, incident response exercises and insurance programme stress testing can help leaders understand exposure, assess where controls reduce potential loss and determine where risk transfer can help protect the balance sheet.
Regulation Is Necessary, but Not Sufficient
Thailand has established cyber security requirements for state agencies, supervising or regulating organisations and critical information infrastructure organisations. These requirements include risk-based security classifications and minimum standards for data and information systems.
The National Cyber Security Agency and Ministry of Energy have also established the Energy Information Sharing and Analysis Center to support cyber threat intelligence sharing across Thailand’s energy sector. [5]
Regulation creates a baseline, but it does not create operational resilience on its own. Leaders also need to strengthen identity controls, improve visibility across digital environments, manage third-party risk, test incident response plans and connect cyber priorities to business continuity, capital allocation and stakeholder trust.
How Aon Can Help with Cyber Resilience
Aon helps organisations turn cyber risk into clearer business decisions. We help leaders understand how cyber events could affect strategy, operations, the balance sheet and stakeholders. This insight supports decisions about where to invest, what to improve, what to retain and what to transfer.
Our approach brings together cyber risk advisory, analytic insight, insurance market insight and claims experience. This helps clients develop an integrated view of resilience, supported by stronger readiness and a risk transfer strategy aligned with the organisation’s exposure.
Leaders can move the cyber conversation from “Are we protected?” to “Are we making the right decisions with the risk information available?” This is how resilience can strengthen business confidence.
Contributed by -
Siri-on Luangaroonlerd – Head of Specialty & Cyber Solutions, Thailand, Aon
Pratya Pongrungruang – Associate Director, Cyber Solutions, Thailand, Aon
References
1. Thailand Threat Landscape Report 2026, SOCRadar
2. Thailand Lays Out New Cybersecurity Standards, Tilleke & Gibbins
3. Cyber Threat Statistics 2026 — ThaiCERT / National Cyber Security Agency
4. Thailand Threat Landscape Report 2026 – SOCRadar
5. NCSA and Ministry of Energy Launch Energy ISAC, ThaiCERT