Cybersecurity and Information Security  

EGAT places great importance on cybersecurity and information security by implementing measures to prevent, respond to, and mitigate risks arising from increasingly complex and rapidly evolving threats that may affect the organization’s operations, stakeholders, and the security of the national power system.

Targets for 2025Performance 
● Effectiveness in managing the impacts of cyber threats on core missions is at Level 5, meaning that essential technology systems supporting key assets can continue operating at normal levels, as all cyber incidents can either be prevented or managed at a level that does not affect the operation of such systems.● Effectiveness in managing the impacts of cyber threats on core missions is at Level 5, meaning that essential technology systems supporting key assets can continue operating at normal levels, as all cyber incidents can either be prevented or managed at a level that does not affect the operation of such systems.

Policy and Commitment 

EGAT has established a cybersecurity and information security policy, which assigns key departments responsible for EGAT’s core missions and technology infrastructure functions to control and oversee cybersecurity and information security through risk identification, risk prevention, threat detection and monitoring, incident response, and the protection and recovery of damage caused by cyber and information security threats. In addition, EGAT has implemented other related policies and measures, such as the personal data protection policy, personal data security measures, and privacy notices for activities involving personal data.

Operational Structure 

EGAT has appointed responsible parties for cybersecurity and information security as follows:

  • Cybersecurity and Information Security Operations Working Group is responsible for identifying risks, establishing measures and implementing controls to prevent risks, monitoring and surveilling threats, responding to incidents, and protecting and restoring damage caused by cyber threats.
  • Cybersecurity and Information Security Management Working Group is responsible for formulating policies, standards, and guidelines for the security of operational technology and digital technology, as well as cyber threat response, and for overseeing compliance with such policies, standards, and guidelines.
  • Chief Information Security Executive is responsible for reporting significant incidents relating to the security of operational technology, digital technology, and cyber threats directly to the Governor and relevant committees, and for providing recommendations on cyber threats and risk management relating to the security of operational technology and digital technology to relevant committees.
  • Internal Audit Office is responsible for auditing cybersecurity and information security in accordance with the cybersecurity and information security audit plan, covering units with computer systems or critical information infrastructure related to electricity generation, transmission, and system control services. These activities are conducted under the annual audit plan, with audit findings subsequently reported to the EGAT Audit Committee.

Moreover, EGAT has units specifically responsible for cybersecurity and information security matters, such as the Risk Management and Digital Legal Compliance Department,
Cyber Security Operation Department, Control Center Technology Department, Control and Protection System Division, and Network Operation Security Section.

Management Approach

EGAT’s cybersecurity and information security operations are aligned with the Cybersecurity Act B.E. 2562 (2019), the Personal Data Protection Act B.E. 2562 (2019), and ISO 27001, as well as the NIST Cybersecurity Framework, which is an international cybersecurity framework for critical utility services in electricity generation, transmission, and distribution, and the NERC CIP (Critical Infrastructure Protection) standards, which govern the protection of power systems in transmission operation and power system control.

EGAT also conducts operational reviews by both internal and external parties and carries out assessments and analyses of its cybersecurity posture in order to continuously improve its people, processes, and technologies. 

In addition, EGAT prepares documents and agreements relating to cybersecurity and personal data protection so that suppliers are informed of, and comply with, EGAT’s policies and practices. EGAT also holds meetings and/or briefings to inform suppliers regarding improvements to EGAT’s operations that may relate to or affect supplier processes, and conducts reviews of operational processes that lead to enhancements in technologies used to monitor activities involving suppliers or other stakeholders, in order to prevent security breaches.

EGAT also promotes cooperation and share cyber threat information with other organizations, such as the Ministry of Energy, the Provincial Electricity Authority (PEA), the Metropolitan Electricity Authority (MEA), and PTT Public Company Limited, while continuing to expand collaborative networks with domestic and international partners in order to sustainably strengthen the security of the country’s critical infrastructure.

In 2025, EGAT carried out several key cybersecurity and information security initiatives, including the following:

  • EGAT organized the 2025 Cybersecurity Awareness in Daily Life training course for general employees and supported cybersecurity personnel in attending training programs to enhance their knowledge and capabilities. This included participation in practical training workshops for Data Protection Officers (DPOs) under the Government Platform for PDPA Compliance (GPPC) project, a collaboration between the Personal Data Protection Committee Office and the Office of the National Digital Economy and Society Commission, to promote implementation of the Personal Data Protection Act B.E. 2562 (2019).
  • EGAT applied digital systems and innovation to cybersecurity and information security management processes in order to enhance management capability, prevention, and response effectiveness, and used key outputs from these processes as inputs for planning.
  • EGAT prepared an Endpoint Management Plan to ensure the efficient management of the organization’s desktop and portable computing devices, and an access rights plan for Extended Detection and Response (XDR).”
Violation of Customer Privacy 
Item 202520242023
From outside parties From regulatory bodies From outside parties From regulatory bodies From outside parties From regulatory bodies 
Number of substantiated complaints concerning breaches of customer privacy and losses of customer data 000000
Number of identified leaks, thefts, or losses of customer data 000000
Total000000