As cyber threats develop rapidly, maintaining security in the digital world must cover preparedness, response, and the ability to move forward when an incident occurs. Recently, OPEN-TEC, a technology knowledge-sharing platform, powered by TCC Technology Group, hosted “open talk” to provide a stage for exchanging perspectives on cybersecurity. The event was honored by Air Vice Marshal Amorn Chomchoey, Secretary-General of the National Cyber Security Agency (NCSA), who shared his experience. Additionally, Air Vice Marshal Amorn views Thailand as being at an important stage in strengthening its cyber immunity, due to problems accumulated from the past, the arrival of AI, and new challenges from quantum technology.

NCSA: Building a Safe and Trusted Cyberspace
The NCSA was established under Thailand’s Cybersecurity Act B.E. 2019 with the mission of creating a safe and trusted cyberspace. Its responsibilities range from establishing policies, plans, and standards to working with regulatory authorities and Critical Information Infrastructure (CII), as well as developing personnel and raising awareness. Its work is built around three key pillars: People, Process, and Technology. These three elements must work together to address risks that are constantly evolving.
“Technology Debt”: A Legacy Challenge Thailand Must Address
One of Thailand’s major challenges is what is known as “Technology Debt.” Over the past 20 years, Thailand rapidly adopted the internet and IT technologies. At the time, however, cybersecurity did not receive the level of attention it deserved. As a result, many systems still contain vulnerabilities and limitations that have accumulated over the years. At the same time, organizations must continue their digital transformation and adopt new technologies. They therefore need to address legacy systems while simultaneously dealing with emerging threats. This includes strengthening system security, increasing users’ understanding of their security responsibilities, and improving the overall cybersecurity posture of both the public and private sectors.
AI: A New Tool for Both Defenders and Attackers
AI is significantly transforming the cybersecurity landscape, both in business and cybercrime. Risks to the public range from the use of AI to imitate voices, create deepfakes, and generate false or misleading information to increasingly sophisticated scams. At the organizational level, businesses must also prepare for AI-related threats, particularly Agentic AI, which could potentially be used to attack systems. Furthermore, as organizations increasingly adopt AI for business purposes, AI systems developed without cybersecurity considerations from the outset could create entirely new avenues of risk.
Security Must Start on Day One of AI Development
AI security must start on Day One of AI Development, covering everything from software and data to model training and post-deployment operations. AI development therefore requires continuous monitoring to ensure that systems continue to operate according to their intended business objectives. Organizations must also examine the data used to train AI models to prevent manipulated or altered data from compromising the system. In addition, algorithms should be designed and developed to process information, make decisions, and predict outcomes while minimizing bias without compromising system performance. AI remains an area in which security tools and approaches are still evolving. Organizations therefore need to keep up with emerging practices and continuously adapt their security processes to the unique characteristics of AI.
From “100% Prevention” to Cyber Resilience
For the country’s Critical Information Infrastructure, including energy, healthcare, transportation, and financial services, security must cover the entire lifecycle: prevention, detection, response, and recovery. No system can guarantee 100% protection against attacks. The concept of “Cyber Resilience” therefore focuses on an organization’s ability to withstand attacks, detect and respond to incidents quickly, recover systems, and restore critical services so that operations can continue.
Cybersecurity Culture: Security Is Everyone’s Responsibility
Beyond technology and processes, organizations must also build a strong Cybersecurity Culture. Simply raising awareness may not be enough to establish secure behaviors over the long term. For example, when an employee encounters a suspicious email, they should report it and alert others so that their colleagues can learn from the incident and exercise greater caution. This culture must extend across every level of an organization from users and developers to executives. Developers must consider security alongside product development, while executives must make security a priority in every decision.
Zero Trust is a journey
Another important approach to strengthening cybersecurity is Zero Trust, based on the principle of “never trust anything automatically.” Access to systems must therefore be verified based on factors such as the device, user, time, and required level of access. This is closely connected to the principles of least privilege and risk management. Zero trust is not so easy, it’s not a project, it’s a journey, and organizations should begin by the data governance, understanding their data, systems, and usage patterns before developing policies and fundamentally changing how access to systems is managed.
People Are a Critical Resource in the Cyber War
Amid the global shortage of cybersecurity professionals, Thailand needs to accelerate the development of the next generation of talent. The NCSA has therefore launched Thailand Cyber Top Talent, an initiative that gives young people, university students, and others interested in cybersecurity an opportunity to test their skills and discover whether they have an interest in pursuing a career in the field. The initiative also aims to build awareness that cybersecurity is a career of the future, one with strong demand and one that requires continuous learning as technology and threats evolve.
Public-Private Partnership as a Key Driver
Cyber threats are not confined to a single organization or country. Effective response therefore requires cooperation among multiple stakeholders. Public-Private Partnership (PPP) is one of the NCSA’s key mechanisms. It includes workshops and professional skills development, as well as collaboration with international organizations to exchange Cyber Threat Intelligence. Such cooperation can provide early warning and enable organizations to prepare for and respond to emerging threats more quickly.
Quantum Computing: A Major Challenge Before 2030
In addition to AI as mentioned before, another major challenge Thailand must prepare for is the increasing capabilities of Quantum Computers. If other countries develop sufficiently powerful quantum technology, the ability to break the cryptographic systems currently in use could change dramatically. Data intercepted and stored today could potentially be decrypted in the future once quantum technology becomes sufficiently capable. Thailand therefore needs to begin preparing today. This includes assessing existing cryptographic libraries, planning migration strategies, budgeting for system upgrades, ensuring web servers support TLS 1.3, and developing a roadmap toward quantum-resistant cryptography. The NCSA is looking toward the goal of becoming Quantum Ready by 2030, beginning with the public sector and working with critical organizations to prepare systems for the changes ahead.
“Scare, Aware, Care”: Three Words for the Cyber World
The approach to preparing for cyber threats can be captured in three key words: “Scare — Aware — Care.”
Scare means recognizing that cyber threats can cause damage to systems, data, and trust. Once confidence is lost, it can be extremely difficult to rebuild.
Aware means understanding what risks you face and how you should respond. This involves conducting a Risk Assessment and prioritizing appropriate measures based on the risks and resources available.
Care means taking action from prevention and risk reduction to preparing an Incident Response plan and building the ability to recover from incidents.
In a digital world where threats are evolving faster than ever, true security means ensuring that organizations and the country are prepared to respond when attacks occur. That is the essence of moving from Cybersecurity to Cyber Resilience: building systems, people, and organizations that can withstand threats and continue moving forward, even in the face of constantly evolving risks.
Source
