Announcement No. 9/2568

Cybersecurity Policy

Announced on 1 August 2025. This page is an English translation of the Company's official Thai announcement; in the event of any discrepancy, the Thai version prevails.

Open the announced policy (PDF, Thai)

1. Introduction

INET Managed Services Company Limited (the “Company”) is committed to earning the confidence and trust of its customers by delivering IT infrastructure management and managed security services that are of high quality, dependable and secure. The Company recognises that cybersecurity is not merely a technical responsibility but a strategic component that bears directly on business success, customer trust, the protection of information as a valuable asset, and the sustainable growth of the organisation. To meet its strategic goals and the expectations of every stakeholder, the Company has established a clear organisational structure for cybersecurity governance, defining the roles and duties of the board of directors, senior management, personnel at every level, suppliers and business partners. The framework draws on international standards such as ISO/IEC 27001 and the NIST Cybersecurity Framework (CSF) Version 2.0, covering all six core functions — Govern, Identify, Protect, Detect, Respond and Recover — and complies with the Cybersecurity Act B.E. 2562 (2019) together with other applicable laws and regulations. This Cybersecurity Policy has been reviewed by the committee and approved by the Company's senior management to serve as the foundation for setting the direction and expectations for cybersecurity, and for managing risk in line with the level of risk the organisation is prepared to accept (risk appetite). The policy also emphasises building a strong cybersecurity culture, managing supply chain risk, and governing, monitoring, reviewing and improving continuously so that the measures in place remain appropriate, current and effective against a threat landscape that changes constantly.

2. Objectives

2.1 To ensure that the Company's IT Infrastructure and Managed Security Services are delivered with the highest level of security, preserving the confidentiality, integrity and availability of information and of the systems that are critical assets of customers and of the organisation, against unauthorised access, disclosure, alteration or destruction. 2.2 To adopt and apply a cybersecurity management framework based on the NIST Cybersecurity Framework (CSF) Version 2.0 systematically across the organisation, covering Govern, Identify, Protect, Detect, Respond and Recover, so as to raise the Company's ability to deal with cyber risk. 2.3 To govern and manage cyber risk in line with business strategy, the accepted level of risk and applicable law, with mechanisms for continuous monitoring and improvement, so that security measures remain effective and keep pace with changing threats. 2.4 To keep the Company's cybersecurity operations compliant with applicable laws, regulations, standards and contractual obligations, including the Cybersecurity Act B.E. 2562 (2019) and customers' specific requirements. 2.5 To enable the Company to detect, respond to and recover from cyber threats effectively, limiting the impact on business operations, on service delivery and on customer confidence. 2.6 To encourage management, personnel at every level, suppliers and business partners to understand and consistently follow the Company's cybersecurity practices.

3. Cybersecurity management strategy

So that the Company operates securely, in line with international standards, and earns the confidence of users, customers and partners, the Company sets the following cybersecurity management strategy. 3.1 Continuous risk assessment The Company regularly assesses the threats and risks relevant to its services, prioritising them by impact and likelihood so that protective measures can be designed and applied appropriately and effectively. 3.2 Proactive protection The Company employs modern technologies and tools such as threat intelligence, SIEM, SOAR and next-generation firewalls to strengthen its ability to defend against threats, tracks how new threats develop, and adjusts its protective measures accordingly on a continuing basis. 3.3 Detection and response The Company operates a Security Operations Center (SOC) able to detect, analyse and respond to security events 24 hours a day, every day, maintains playbooks for incident response, and runs a simulated incident exercise (cyber drill) at least once a year. 3.4 Vulnerability management The Company regularly examines and manages vulnerabilities both in the systems used to serve customers and in its internal systems, preparing a clear remediation plan and tracking progress until remediation is complete, so as to contain the risk those vulnerabilities present. 3.5 Developing the skills and capability of personnel The Company provides continuing information security training and skills development for personnel at every level, to build awareness and an understanding of each person's role and duty in protecting the Company's information resources. 3.6 Compliance with applicable laws, standards and requirements The Company complies with the laws and regulations that apply in Thailand, such as the Personal Data Protection Act (PDPA) and the Cybersecurity Act, and works to international standards such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 20000-1 and the NIST Cybersecurity Framework, so that its information security processes follow best practice.

4. Scope

This policy covers all of the Company's information assets, including information technology systems, infrastructure and data, and it applies to the Company's staff, to the suppliers and business partners who carry out business activities with it, and to all related personnel, internal and external, who work with or access the Company's resources.

5. Governance and responsibilities

The Company has defined a structure and duties for cybersecurity governance, divided into three levels on the “Three Lines of Defense” model, as follows. (1) First line of defense: the operating units, which work under the Cybersecurity Policy to govern, monitor, protect and inspect information assets and related systems, follow the incident response plans and restore data so that business operations continue. (2) Second line of defense: the risk management and compliance units, which oversee compliance with applicable laws and rules, advise on risk control, and govern and monitor adherence to policies, laws and regulations. (3) Third line of defense: the audit unit, whose principal role is to provide independent and impartial examination and assurance over the effectiveness of the risk management and control measures of the first and second lines.

6. Asset management

The Company identifies, inventories, classifies and assigns ownership of its information assets, data, hardware, software and systems, and manages them appropriately throughout their life cycle from acquisition and use to destruction or decommissioning, in accordance with the Information security and privacy policy and the guidance of NIST CSF 2.0, as follows. 6.1 Asset identification and inventory 6.2 Information and asset classification 6.3 Labeling 6.4 Ownership 6.5 Asset lifecycle management, which shall include: • Acceptable use policy: every user must follow the rules and conditions for the use of information and related information assets set out in the information security policy on the acceptable use of corporate assets. • Return of assets: on termination of employment, of a contract or of an agreement, all personnel and relevant external stakeholders must return every corporate asset in their possession. • Information deletion: information held in information systems, devices or any storage media must be securely deleted or destroyed once it is no longer needed, to prevent unauthorised leakage.

7. Cyber risk assessment and management

The Company identifies, analyses, evaluates and manages cyber risk, rates the cyber risks it faces, and sets out how decisions are made in choosing the appropriate risk treatment, so as to reduce the likelihood and impact of threats to a level the organisation can accept (risk appetite), consistent with the risk management strategy (GV.RM) and the risk assessment process (ID.RA) of NIST CSF 2.0. The Company therefore requires the following. 7.1 Risk management strategy and process 7.2 Risk identification and analysis 7.3 Risk evaluation and treatment plan 7.4 Residual risk acceptance and communication 7.5 Risk review and monitoring

8. Protection

Appropriate protective measures are defined with regard to the availability, integrity and confidentiality of the organisation's important information and information systems. These measures are intended to limit or contain the impact of any cybersecurity threat event, and are put into practice by every party concerned within the scope set out in this policy. The Company therefore requires the following. 8.1 Access control Access control policies and processes are enforced so that users can reach only the information and systems needed for their assigned duties (principle of least privilege), with identity management, secure authentication, and management of access rights and privileged access rights that is rigorous and proportionate to the level of risk. 8.2 Awareness and training Appropriate and continuing cybersecurity training is provided to all personnel and to others concerned, so that they understand the policies, the procedures and the relevant threats, and can carry out their work securely. 8.3 Data security The Company classifies data by importance in order to protect it, preserve its confidentiality and integrity and keep it available throughout the data lifecycle — from creation or receipt through storage, processing, transfer and retention to destruction — proportionately to that classification, by means of cryptography, data leakage prevention, backup and the secure handling of storage media. 8.4 System maintenance The Company maintains its information systems, hardware and software on a maintenance cycle that begins with the installation of software on operational systems, the management of technical vulnerabilities — patch management, for example — and the management of system security settings (configuration management), so as to reduce the risk of exploitable vulnerabilities. 8.5 Protective technology The Company adopts protective technology that is appropriate and current for each area in order to strengthen its ability to prevent, detect and respond to cyber threats, with a Security Operations Center (SOC) and teams specialised in each area of security managing the technology in use so that it performs at its best and answers threats in good time.

9. Detection

Appropriate processes, tools and technologies are in place to detect cybersecurity events and anomalies arising within the organisation's information systems, networks and related assets. A Security Operations Center (SOC) able to detect, analyse and respond to security events, together with specialist teams, operates 24 hours a day, seven days a week, so that threats are detected and tracked continuously, effectively and in good time. Fast and accurate detection is essential if the organisation is to respond to threats appropriately.

10. Incident response

The Company has defined the structure of the teams concerned and the authority of each function so that planned and prepared procedures can be carried out effectively in response to a cybersecurity threat event, in order to limit damage and the impact on operations, assets and the organisation's reputation, to restore systems and services to normal as quickly as possible, to communicate appropriately with everyone affected, and to feed the lessons learned back into continuous improvement of security measures. These arrangements are reviewed and rehearsed at least once a year, or when a change makes it appropriate.

11. Recovery

The Company requires data backup and restoration, with planning, defined process steps and appropriate resilience procedures, so that critical information systems, data and operations can be restored quickly and effectively after a cyber threat event or another severe disruption. The purpose is to limit the impact on business operations, to maintain continuity of service and to keep availability within the service level agreement, communicating appropriately with those concerned. These arrangements are reviewed and rehearsed at least once a year.

12. Supply chain risk management

A framework and systematic practices are in place to identify, assess, manage and monitor the cybersecurity risks that may arise from or through suppliers, external service providers and other parties in the Company's supply chain, in order to reduce the likelihood and impact of threats to the Company's data, assets, systems and operations. The Company therefore requires the following. 12.1 A supply chain risk management process A cybersecurity risk management process is applied continuously for the whole period of business with suppliers and external service providers, from assessment and selection, contracting, service commencement or product acceptance, through operation, monitoring and review, to the end of the contract. 12.2 Supplier and vendor risk identification and assessment The cybersecurity risk of suppliers and service providers is assessed before the relationship or work begins, and reassessed on a defined cycle or whenever there is a significant change. 12.3 Security requirements in agreements Information security requirements that are clear, appropriate and enforceable are set out in agreements or contracts with suppliers and service providers. 12.4 ICT supply chain security Cybersecurity risk is assessed for suppliers and service providers involved in information and communication technology (ICT) — products, software or services that may have a high impact on the security of the organisation's systems and data — for the whole period that product, software or service is in use. 12.5 Monitoring, review, and change management of supplier services Changes to the services of suppliers and service providers are monitored, reviewed and managed regularly according to the level of risk assessed, including changes in their services or environment that may affect the Company's security.

13. Policy review and updates

The Company's Cybersecurity Policy, together with its subordinate policies, procedures and all related documents, is reviewed and updated so that it remains suitable, adequate and effective in supporting business objectives, risk management and continued compliance with applicable requirements, at least once a year or whenever there is a change or a significant trigger. Changes are communicated to all personnel and relevant stakeholders so that everyone is informed, understands them and can comply with the new requirements correctly.

14. Compliance with this policy

All employees and everyone concerned must comply strictly with this policy. A breach of the policy will be subject to disciplinary consideration under the Company's regulations or under applicable law.

Announced on 1 August 2025 (นายอรรถวุฒิ คำประดิษฐ์) Managing Director INET Managed Services Company Limited