Information Security, Cybersecurity and System Availability
Challenges and Commitments
In an era where information technology is advancing rapidly and becoming integral to global business operations, cybersecurity threats have emerged as a critical concern for all organizations.
GGC recognizes the importance of safeguarding data and technology systems from both external threats and internal data leakage, which may affect operational continuity and the security of information related to Employees, Customers, and Suppliers and Business Partners. To address these risks, GGC strengthens its information technology governance structure, strictly complies with personal data protection laws, and provides continuous training to Employees to enhance knowledge, understanding, and awareness regarding cyber security.
Key Stakeholders
Employee
Customer
Government
Supplier and Business Partner
For additional information on stakeholder engagement: Stakeholder Engagement
Goals
Key Performance in 2025
Management Approach
GGC has established an Information Technology Security Policy as a framework for developing a systematic information security management system, aligned with international standards such as ISO/IEC 27001 for Information Security Management and the Control Objectives for Information and Related Technologies (COBIT). The policy also incorporates clear operational procedures to enhance cybersecurity management, prevent undesirable incidents, and reduce risks and potential impacts on the organization effectively.
In addition, GGC has established an Artificial Intelligence (AI) Policy, which has been effective since May 2025, to provide a governance framework for the responsible use and development of artificial intelligence systems across the organization in alignment with applicable laws and internationally recognized standards.
The policy is built upon six key principles:
- Capability Development and Business Sustainability
- Compliance with Laws, Ethics, and International Standards
- Transparency and Accountability in the Use of AI
- Information Security and Personal Data Protection
- Fairness and Non-discrimination
- Reliability and Accuracy of AI Outputs
The policy applies to all employees across the organization, as well as contractors, subcontractors, suppliers, business partners, and other parties involved in the use or development of the Company's AI systems and tools.
The Structure of Overseeing Information and Cyber Security
GGC has established a governance structure for information and cyber security comprising three main levels: Board Level, Management Level, and Operational Level. Each level holds specific roles and responsibilities to oversee, audit, and manage information security risks effectively and systematically.
| Governance Level | Roles and Responsibilities |
|---|---|
| Board Level Audit Committee |
|
| GC Group’ s Digital & IT Steering Committee (DISC) |
|
| ISMS Committee |
|
| Enterprise Architecture (EA Committee) |
|
| Chief Information Security Officer: CISO |
|
| Management Level |
|
| Operation Level |
|
Mitigation Actions for Cyber Threats and Information Leaks
Independent External Audit of the IT Infrastructure and/or information security management system inspections
GGC, in collaboration with PTTGC, conducted an assessment in accordance with ISO/IEC 27001:2022 to ensure that GGC’s Information Security Management System (ISMS) operates effectively and aligns with international standards. The external audit scope covers Infrastructure as a Service, Infrastructure as a Service on Cloud, Internet Gateway Zone Management, and Application Management, which also plays a key role in supporting the external recruitment process.
Information and Cyber Security Management Program
GGC continuously enhances Information Security and Cyber Security through the development of security audit plans and the adoption of advanced information security technologies to address rapidly evolving cyber threats. GGC has developed a five-year IT Action Plan (2023–2027), identifying Cyber Security as a key priority, supported by clear and comprehensive operational guidelines.
The primary objective of this plan is to ensure that the Cyber Security program is regularly updated and maintained in alignment with international standards and best practices, thereby enabling secure and efficient business operations. Key activities under this plan include:
- Process and infrastructure assessment
- System enhancements to address vulnerabilities, including risk assessment scanning
- Phishing tests and tailor-made programs for specific functions
- Data Governance for GGC (Data Protection and Data Classification)
Process and Infrastructure
GGC has established an Information Security Management System (ISMS) in alignment with international standards and adopted asset security practices consistent with Cyber Security requirements. External agencies conduct annual inspections and reviews of GGC’s information and cyber infrastructure. The most recent inspection confirmed that all processes and infrastructures fully comply with international standards, with no issues or defects identified.
As a subsidiary of PTTGC, GGC has adopted the Cyber Drill Procedure as a standard operational guideline for all IT personnel. This ensures effective and secure incident response to IT or Cyber Security-related events while minimizing potential damage. Cyber drills are conducted at least twice a year, once during January–June and once during July–December.
GGC has also established an IT Security and Cyber Security Disaster Recovery Plan outlining procedures for responding to disasters affecting the primary data center. The plan specifies recovery timelines for various information types and detailed steps for resuming normal business operations. Disaster recovery testing is conducted at least twice a year during the same periods as the Cyber Drill to strengthen preparedness and response efficiency.
GGC's Information Security Management System (ISMS) has been independently audited and certified by Bureau Veritas Certification to ISO/IEC 27001:2022. Bureau Veritas Certification is accredited by the United Kingdom Accreditation Service (UKAS). The certification scope encompasses the Information Security Management System for Infrastructure as a Service (IaaS), Cloud Infrastructure, Cloud Platform, and the Cyber Zone/Internet Zone Network, together with the Company's external recruitment and procurement processes.
Vulnerability Assessment
GGC conducts external vulnerability assessments at least twice a year to evaluate risks and identify system improvement opportunities. The Business Continuity Plan is implemented to support operations during emergencies. In 2025, GGC conducted its annual Cyber Incident Response Tabletop Exercise to assess the stability and effectiveness of information and Cyber Security systems. The exercise simulated a cyber-attack by external intruders attempting to penetrate GGC’s IT security and gain access to sensitive information, posing a risk of data leakage. Each Vulnerability Assessment (VA) covers critical areas, including:
- Clickjacking
- Cookies not marked as HTTP Only
- Cookies with missing, inconsistent, or conflicting properties
- Programming error messages
- Version disclosure
- Content Security Policy misconfiguration
- Permissions-Policy header not implemented
GGC also performs internal and external vulnerability scans every six months to support protection and remediation planning. Vulnerability Severity Levels are categorized into three levels: High, Medium, and Low.
Information Security and Cybersecurity Awareness
GGC has strengthened awareness and readiness on Cyber Security for Employees at all levels by providing online learning (E-Learning) on the topic “Cyber Security Online”, accompanied by post-learning assessments to evaluate understanding. This enables Employees to effectively apply the acquired knowledge in their daily work.
Training & Boost-Up Program
The Training & Boost-Up Program is an online training initiative designed to align with the roles and responsibilities of each Employee and extended to Suppliers and Business Partners. The program incorporates performance indicators to assess learning outcomes. Where assessment results fall below the defined threshold, additional training is arranged to reinforce understanding and readiness in Cyber Security.
In 2025, GGC conducted a Phishing Test to assess Employee awareness and response to email-based threats. Employees who were unable to correctly identify and report Phishing emails were required to attend additional training to enhance their capability in managing Information Security risks
Outcomes and Benefits
- Employees are better prepared and more vigilant toward Cyber Security threats.
- The organization’s security systems have greater resilience and responsiveness to emerging risks.
- Potential long-term damage from Cyber Attacks is reduced.
Power BI Workshops

In 2025, GGC organized more than two Power BI training sessions for Employees in the GC Group during August and September. The workshops focused on helping participants understand data connectivity, the creation of interactive dashboards, and the design of visualizations that effectively communicate business insights through full-day, hands-on learning.
Subsequently, GGC continued training under the “Next-Level Insights with Power BI” program to elevate Employees’ Power BI capabilities to an intermediate level, with emphasis on advanced Power Query, advanced DAX, interactive report design techniques, and guidelines for publishing reports via Power BI Service.
Outcomes and Benefits
- Participants are able to independently design and develop Power BI dashboards.
- Participants understand key DAX and Data Modelling principles for in-depth data analysis.
- A learning network and community of practice in Data Analytics has been strengthened.
GGC AI Jump Start
The GGC AI Jump Start program was held on 13 June 2025 via Microsoft Teams with the objective of promoting and accelerating the practical adoption of Artificial Intelligence (AI) within the organization under the AI Adoption Framework, which covers three dimensions: People, Process, and Technology.
The program featured in-depth presentations and live demonstrations of Generative AI and Microsoft Copilot, along with guidance on License Management and real-life case studies showcasing AI applications in end-to-end work processes.
Outcomes and Benefits
- More than 80 Employees and related functions participated.
- Participants gained structured and secure understanding of AI adoption within the organization.
- Participants identified practical opportunities to apply Generative AI and Copilot to improve work efficiency.
Data Storytelling Workshop

The Data Storytelling Workshop was organized to enhance and develop skills in presenting business data in the form of “Data Storytelling” for Employees within the GC Group, thereby increasing their capability in effective data-driven communication. Participants received knowledge on data analysis and interpretation using the Problem–Reason–Action Framework, dashboard design that clearly conveys key insights, and tailoring presentations to different Stakeholder groups. This contributes to business value creation and strategic impact for the organization.
Outcomes and Benefits
- Participants can transform technical data into simple, compelling narratives that support business decision-making.
- Participants strengthened skills in Visual Communication and Dashboard Design for effective data presentation.
- The workshop supports the development of strategic thinking and innovation through the use of data.
IT/OT Convergent
The IT/OT Convergent project aims to integrate Information Technology (IT) and Operational Technology (OT) systems to operate seamlessly and efficiently. The initiative enhances operational agility, improves real-time, data-driven decision-making, reduces costs by improving efficiency and minimizing system downtime, strengthens security through centralized management, and enables the organization to adopt new innovations and technologies effectively.
The implementation roadmap is divided into several phases: planning and system assessment during Months 1–2 (including Cisco Security and Palo Alto Network assessments); system architecture design and security control planning during Months 3–4 (based on guidance from Gartner and the Purdue Model); followed by pilot deployment, broader implementation, Employee training, continuous monitoring, feedback collection, and iterative improvements for long-term scaling.The project also defined four Quick Win OT Security controls:
- Building a Cyber Security culture through the establishment of an OT Security Policy.
- Conducting OT Cyber Assessment to evaluate OT system Cyber Security.
- Piloting Smart Vibration Proof of Concept (PoC) to detect equipment anomalies as a preventive measure.
- Considering the SAM GUARD PoC to monitor and detect anomalies in ICS/SCADA systems, thereby enhancing the ability to prevent and respond to Cyber Security threats comprehensively.

Outcomes and Benefits
- Improved operational efficiency and reduced unplanned downtime.
- Strengthened OT security in line with international standards.
- Enhanced readiness for innovation and the digital transformation journey.
Supplier risk explorer
Supplier Risk Explorer is a strategic risk management tool used within the GC/GGC Group to systematically monitor, prevent, and mitigate risks arising from Suppliers and Business Partners. It includes ongoing tracking of risk indicators and compliance, as well as blocking high-risk emails and domains to enhance communication security. The tool also compares risk profiles with the PTT/GC Group to align with best practices.
Regarding the 2025 Cyber Security Resilience Survey, the Stock Exchange of Thailand (SET) officially postponed the survey to allow listed companies additional time to implement recommendations from the 2024 assessment. Should the survey be conducted again in 2026, advance notice will be provided. The survey forms part of a broader Cyber Security strengthening initiative, which includes adoption of the NIST framework, participation in PTT Group programs, and internal campaigns to raise awareness on phishing.
Outcomes and Benefits
- Reduced risks from Suppliers and Business Partners through proactive monitoring and analysis.
- Enhanced Cyber Security and communication security within the organization.
- Alignment with PTT/GC Group practices, reinforcing system resilience and stability.
Escalation process for employees to report incidents, vulnerabilities or suspicious activities
GGC has established procedures for reporting incidents, vulnerabilities, or suspicious activities, including Phishing Email alerts. The reporting process is initiated immediately when users or Employees detect such incidents, and the response follows the defined steps below.
Employee Report on Cyber Attack
- A user detects a Phishing Email and reports it to the Service Desk.
SOC Team Investigates the Incident
- The Service Desk escalates the report to the SOC Team.
- The SOC Team determines the severity level: Low Severity or High Severity (in the latter case, the incident is escalated to the SOC Manager and TF-IT Security Team).
SOC Team Coordinates Mitigation
- The SOC Team develops a mitigation plan.
- The SOC Manager informs the Communication Team that Phishing activity has occurred.
TF-IT Security Evaluates Outcomes
- After mitigation is complete, TF-IT evaluates the results and confirms system stability.
SOC + TF-IT Prepare Final Report
- Once the situation returns to normal, the SOC and TF-IT Security Teams prepare a final incident report.
- The Communication Team informs the organization that the issue has been fully resolved.
In 2025, a total of 277 Employees participated in the Phishing Test. Of these, 107 Employees correctly reported Phishing emails, accounting for 40.3% of all participants, while 4.9% of Employees fell victim to Phishing emails

Artificial Intelligence (AI) Policy
GGC has established an Artificial Intelligence (AI) Policy to provide a governance framework for the ethical and sustainable use and development of artificial intelligence. The policy is built upon six key principles: competitiveness and sustainable development; compliance with laws, ethics, and international standards; transparency and accountability; security and privacy; fairness; and reliability. The policy applies to all employees, contractors, suppliers, and business partners, and has been effective since May 2025.
Responsible AI Program
GGC has implemented a range of initiatives to promote the responsible adoption of artificial intelligence (AI) across the organization. These initiatives encompass employee training, AI governance, quality assurance, fairness, and environmental sustainability to ensure that employees and relevant stakeholders can use AI appropriately, securely, and effectively.
1. Limiting access to sensitive AI capabilities (e.g. facial recognition, surveillance)
2. Distinct labeling of AI-generated content and outcomes of AI-driven decisions
3. Mechanisms to detect and correct drift or degradation of AI models over time
4. Regular assessments of deployed AI models for fairness/bias
All AI systems deployed by the Company are required to undergo a Proof of Concept (PoC) process in a non-production environment prior to deployment to evaluate their accuracy, fairness, and compliance with the Company's AI Policy. The Company adopts a phased implementation approach by initially deploying AI in small-scale use cases, such as Salesforce Q&A, ServiceNow Incident Approval, and the HR Policy Assistant, before scaling up to broader organizational applications.
In addition, AI applications within the GC Group, including those used by GGC, operate based on a Closed Knowledge Scope and leverage a retrieval-based approach (RAG-like concept) to generate responses using approved internal knowledge sources. Designated Data Owners are responsible for maintaining data quality control by continuously updating and validating the underlying knowledge sources to ensure that AI outputs remain accurate, reliable, and up to date.
Furthermore, Artemis, the GC Group's AI platform used by GGC, incorporates a built-in feedback mechanism that enables users to directly evaluate whether AI-generated responses are accurate and useful. This feedback is systematically collected and used to continuously improve the AI system and monitor the fairness of AI-generated outputs, helping to ensure that responses remain reliable, unbiased, and aligned with the Company's Responsible AI principles.
5. Initiatives (own/with suppliers) to lower the ecological footprint of AI data centers/models
GGC's AI infrastructure is hosted on Microsoft Azure, a cloud platform with well-established sustainability and environmental commitments. Microsoft's cloud infrastructure is supported by initiatives to improve data center energy efficiency, increase the use of carbon-free electricity, and reduce the environmental footprint of cloud operations, consistent with its commitment to become carbon negative by 2030. By utilizing Microsoft Azure as its AI platform, the Company seeks to minimize the ecological footprint associated with its AI infrastructure while supporting the responsible and sustainable deployment of AI technologies.
Reference document from Microsoft: Microsoft Sustainable Desgin: Innovating for energy efficiency in AI Part I https://blogs.microsoft.com/blog/2024/04/02/sustainable-by-design-advancing-the-sustainability-of-ai/
6. Appeals process for users/affected third parties to contest an AI decision or outcome
GGC provides channels through which users and individuals affected by AI-assisted decisions can submit feedback, challenge AI-generated outcomes, or request clarification. AI systems deployed by GGC enable users to immediately evaluate the accuracy of AI-generated responses.
In addition, individuals with concerns regarding personal data related to AI usage may contact the Data Protection Officer (DPO) directly. GGC also plans to further enhance its complaint handling and case-tracking process to ensure that all concerns are reviewed and addressed fairly, transparently, and systematically.
7. Quantification of the impact of AI initiatives/tools on sustainability outcomes
8. Training of employees on the ethical use and/or security of AI
The Company conducts organization-wide awareness and training programs on information technology, data governance, and artificial intelligence (AI) for employees at all levels. The training covers the ethical use of AI, compliance with the Personal Data Protection Act (PDPA), and the risks associated with using public AI tools in the workplace. To encourage practical adoption, the Company communicates clear guidance through the "Do Less / Do Now / Do More" framework, enabling employees to immediately apply responsible AI practices in their daily work.
This initiative forms part of the Company's Data Loss Prevention (DLP) Roadmap to Resilience, which aims to strengthen data protection and promote the secure use of AI technologies. The training also emphasizes the responsible and socially conscious use of AI by encouraging employees to use AI appropriately, exercise empathy, understand social context, and refrain from using AI to manipulate, exploit, or take unfair advantage of others.

Remark: *The graphic is AI generated