Challenges and Opportunities

Presently, business operations need to apply information technology to maximize operational efficiency, effectiveness, and more creativity. On the other hand, increasing the risk of emerging risks of cyber-attacks or threats. The Company is enhancing and developing the cybersecurity and data privacy policy to protect data and trustworthiness for customers and stakeholders throughout the value chain.

Supporting the SDGs

Targets and Performance Highlights

  • Long Term Target by 2030

    • The company achieves international standards for cybersecurity and data privacy certifications.
  • 2025 Performance

    Achieved the 2030 target, with the company receiving NIST assessment scores for the 3rd consecutive year. The Company's average score is 4.22 (while National average score is 1.91)

    100% Complied with Charoen Pokphand Group and external party action list for cybersecurity and data privacy.

    Total number of information security breach case = 0 case

    Total number of clients, customers and employees affected by the cybersecurity and data privacy breaches = 0 person

    Total number of clients, customers and employees affected by the data privacy breaches = 0 case

    100% of employees have been trained in cybersecurity awareness and phishing E-mail.

    100% of data routes have been conducted the cybersecurity risk assessment.

    100% of web and mobile application have been conducted the security testing service.

Management Approach and Value Creation

The Company prioritizes cybersecurity and data privacy, started assessing risks to prepare a plan to deal with various cyber threats, and announcing policies for all Company personnel to be thoroughly informed, serving as a guideline for raising cyber awareness and attaining ISO27001, international information security standards and Charoen Pokphand Group.

Cybersecurity Policy Structure

The Company has updated its cyber security policy and cover more cybersecurity procedures.

Cybersecurity Management Program
Scope and Implementation 2025 Result
Information security-related business continuity plans
  • Following the framework of the ISO22301 to prepare for various crises that may occur and impact key business operations and the Company's risk management protocols. The BCP drills are conducted twice as the Cybersecurity Business Continuity Plan.
Information security vulnerability analysis
  • Information security vulnerability analysis was done (Verification and Vulnerability Analysis by External Party)
Independent external audit of the information security management systems
  • Annual NIST Function Rating. the Company's score is 4.22 of 5 which is highest rating of 202 participated companies.
  • External audit by KPMG for IT Controls Review
Escalation process for employees to report incidents, vulnerabilities or suspicious activities
  • 100% employee are trained and communicated the Policies, information, and practices through training, internal communication email, and bulletin.
Information security awareness training
  • 100% of employee has trained and communicated the cybersecurity policies
Total number of compliant of breaches
  • Zero Case
Cybersecurity Risk Management

Presently, cyber threats and attacks are more complex and impact cybersecurity risk. The company thus conducts 5-dimensional risk assessments cover a wide range of data routes that could be used to access company data, from head office, mobile phone applications, websites, as well as store and business partners.

Risk Assessment Guidelines Risk Assessment Scope
Connecting to public networks Company’s servers
Phishing and ransomware Employees
Identity theft System administrators and employees
Supply chain attack Information technology third parties
Information leakage Employees
Cybersecurity Awareness Training and Discipline

Awareness being the key to ensuring information system security against cyber threats and data leak prevention, approach is reinforced to raise corporate awareness; communication to introduce and create awareness, alerts to activate response awareness, and testing to assess cyber security awareness.

The cybersecurity is everyone's responsibility with being the one criteria of Annual Performance Evaluation and the year end bonus for employee both staff and manager levels must be reviewed the performance of discipline that related to cyber security and data protection policy.

Policy accessibility
100% employees, can access relevant policy through the organization's internal communications website.
Communication
100% employee are trained and communicated the Policies, information, and practices through training, internal communication email, and bulletin.
Response Instruction
100% alerts that alarm relevant parties to internet leakage, security breaches, or susceptible emails.
Testing
Identity theft phishing simulation (Phishing Test) to test employee awareness
Disciplinary
100% employee must be reviewed the performance of discipline that related to cyber security and data protection policy and acknowledged prior computer login as below picture.
Cybersecurity Business Continuity Plan

Following the framework of the ISO22301 to prepare for various crises that may occur and impact key business operations and the Company's risk management protocols. In 2025, the BCP drills are conducted twice.

Verification and Vulnerability Analysis by External Party

The company has conducted the external audit & Vulnerability Analysis by external party as NIST and external auditor to verity effectiveness of cybersecurity management system, infrastructure, and process.

DATA Privacy Protection

Governance

The Company has appointed a Data Protection Officer (DPO) with responsibilities to monitor and evaluate compliance with data protection laws, raise awareness and provide training on personal data practices, advise the Board, executives, and employees, act as the primary contact point for data subjects and the Personal Data Protection Commission, and maintain the confidentiality of personal data in the performance of duties. The DPO plays a pivotal role in governing privacy matters in close collaboration with relevant functions and senior management, who place strong emphasis on ensuring that privacy and data protection are taken seriously and embedded into the Company’s governance and operations.

Data Privacy Governance Driven by Risk Management Framework (Risk Management Structure)

Privacy policy is applied to the entire Company and its subsidiaries, supplier, vendor, contractor, including any foundations or funds established or to be established by the Company in the future. They are also applied to suppliers, where applicable, through contractual obligations and in compliance with the Personal Data Protection Act (PDPA).

Personal Data Protection Policy
Privacy Notice for Customer
Privacy Notice for Suppliers
Privacy Notice for Investors
Consent Preference
Cookies Policy
CCTV Policy

To ensure effective management of privacy risks, the Company has established a Privacy Compliance Program as a key initiative to mitigate privacy risk, which is recognized as a significant corporate risk. This program reinforces the Company’s commitment to ensuring that privacy risks are properly identified, managed, and monitored across all relevant functions.

The Company implements measures to prevent unauthorized access and mitigate potential breaches of personal information. In line with the Personal Data Protection Act (PDPA), the Company prioritizes the protection of Personally Identifiable Information (PII) and has announced comprehensive Personal Data Protection Policy along with supplementary documents. Data management tools such as data classification and labelling for confidentiality, along with data loss prevention (DLP) systems, have been implemented to automatically detect and prevent potential data leakage.

The effectiveness of these measures is regularly monitored and reported, with statistical tracking such as the number of employees assessed, the number of employees found in breach of data protection requirements, and other relevant performance indicators. These monitoring results are consolidated and reported under the Company’s risk management framework to ensure accountability and continuous improvement in line with international practices.

The Company also promotes a strong speak-up culture by providing multiple secure whistleblowing channels for employees and suppliers. Reports, including data privacy concerns, can be made confidentially and anonymously, with the option to use an independent third-party channel. All reports are treated with strict confidentiality, with a strong commitment to non-retaliation and the protection of whistleblowers’ rights.

The Company places the highest importance on protecting our customers’ personal data. In line with the Personal Data Protection Act (PDPA), we ensure transparency in how customer information is collected, used, disclosed, and safeguarded. Beyond compliance, our commitment reflects genuine care for our customers and stakeholders, ensuring their rights are respected and their trust is maintained. In our Privacy Notice for Customers, the topics below are covered:

Scope of the Privacy Notice
Personal Information We Collect When We Interact With Customers
Purposes of Collection, Use and Disclosure
Disclosure of Customer Personal Information
Sending or Transfer of Customer Personal Information to Overseas
Retention Period of Customer Personal Information
Customer Rights
Updating Customer Personal Information
Security Measures for Customer Personal Information
Marketing Research and Communications
Cookies and Similar Technologies
Redirecting to Other Parties’ Websites
Changes to the Privacy Notice
Notification of Customer Data Breach and Leakage
Contact Us
Data Protection Officer

The Company requires all employees to complete mandatory annual training with a 100% pass rate. In addition, a variety of e-learning modules are available throughout the year, enabling employees to refresh their knowledge and strengthen their understanding of data privacy and compliance at their own pace. The Company also extends privacy awareness to suppliers through contractual obligations aligned with the PDPA, including the Supplier Code of Conduct, as well as ongoing communication channels.

By fostering continuous learning among employees and reinforcing privacy awareness with suppliers, the Company ensures that the personal information of customers and stakeholders is protected with vigilance, accountability, and care.