Goal 9:
Industry, Innovation and Infrastructure
Goal 16:
Peace, Justice and Strong Institutions

Management Guidelines and Practices

BEM has appointed the Information Security Management Committee to oversee and manage IT security.

The Information Security Management Committee reports performance through the Information Security Management Representative to (1) the Quality Management System Committee, which comprises high level executives (C-Level), i.e., the Managing Director, Deputy Managing Director for Operations and Engineering (Rail), Deputy Managing Director for Business Development and Expressway Operations, and the Deputy Managing Director for Administration, as the Chairman and members of the Committee, respectively.

Impact on Business and Stakeholders

Customers
Customers
Shareholders
Shareholders
Employees
Employees
Suppliers or Contractors
Suppliers or Contractors
Regulators and Government Agencies
Regulators and Government Agencies

The increasing use of technology to drive businesses has led to a higher risk of threats to the information system. Therefore, an external attack on the information system may cause disruption to the Company's service system and damage business operations, reputation, and reliability. Furthermore, leakage of key data or personal information of customers, suppliers and employees may violate privacy rights and destroy stakeholder confidence. This may also result in lawsuits being filed with regulatory authorities which may affect investor confidence in the long run.

Commitment, Challenges and Opportunities

Commitment, Challenges and Opportunities

BEM places importance on governing IT security and Data privacy to support internal operations and service expansions through the digital system.

The Company has made improvements to ensure that our IT system is secure and consistent with the ISO/IEC 27001 international standards. We have invested in the development of a more efficient system infrastructure to support the future increase in system usage. We have also formulated a plan to address cyber-attacks using cryptographic control and conducted various system tests to upgrade IT security. A safe and secure IT system also provides protection to the privacy of stakeholders against personal data leakage. More importantly, BEM has established operational guidelines related to data privacy in accordance with the Personal Data Protection Act B.E. 2562 (2019).

Targets and Performance Indicators

Targets and Performance Indicators

BEM aims to prevent information technology security breaches, ensure no impact on customers, employees or other stakeholders, and maintain a record of zero confirmed personal data breach complaints from customers, external organizations, or government agencies.

Information Technology Security Breach
Information Technology Security Breach
Target
Short-Term Target, by 2024
0
cases
Mid-Term Target, by 2030
0
cases
Long-Term Target, by 2050
0
cases
2025 Performance
1 1/
cases
Affected Customers, Employees, or Stakeholders
Affected Customers, Employees, or Stakeholders
Target
Short-Term Target, by 2024
0
persons
Mid-Term Target, by 2030
0
persons
Long-Term Target, by 2050
0
persons
2025 Performance
0
persons
Confirmed Customer Personal Data Breach Complaints
Confirmed Customer Personal Data Breach Complaints
Target
Short-Term Target, by 2024
0
cases
Mid-Term Target, by 2030
0
cases
Long-Term Target, by 2050
0
cases
2025 Performance
0
cases
Complaints by External Organizations
Complaints by External Organizations
Target
Short-Term Target, by 2024
0
cases
Mid-Term Target, by 2030
0
cases
Long-Term Target, by 2050
0
cases
2025 Performance
0
cases
Complaints by Government Agencies
Complaints by Government Agencies
Target
Short-Term Target, by 2024
0
cases
Mid-Term Target, by 2030
0
cases
Long-Term Target, by 2050
0
cases
2025 Performance
0
cases

Note: 1/ One cyberattack was detected in 2025, but the Company contained them successfully, preventing any impact on services or personal data breaches.

Policy and Practices

Information Security Policy and Practices

BEM has announced an Information Security Policy and developed an Information Technology Security Manual as a guideline for employees, system administrators, and external parties working with the Company. The Company conducts audits and reviews of the policy at least once a year.

BEM has appointed an Information Security Management Committee to oversee and manage information technology security. The committee is chaired by the Assistant Managing Director of the Information and Technology Group, who acts as the management representative for information security. The committee conducts regular reviews and reports key information security issues to the Corporate Governance, Risk Management and Sustainable Development Committee on an annual basis. This ensures that the Company’s information security measures remain up to date and aligned with international standards.


Personal Data Protection Policy and Practices

BEM has established a Personal Data Protection Committee, overseen by the Deputy Managing Director of Administration, who serves as Chairman of the Personal Data Protection Committee, and Data Protection Officer (DPO) to oversee the development, review, and continuous implementation of personal data protection policies and practices.

To comply with the Personal Data Protection Act B.E. 2562 (2019), BEM has developed the Personal Data Protection Policy and Practices and communicated them to all employees for acknowledgement and strict adherence. The policy and practices are also shared with external stakeholders via the Privacy Data Center on the Company's website. In addition to legal penalties, employees who violate the policy and practices may face disciplinary action, including verbal or written warning, dismissal, and termination without severance pay as stipulated by law.

Role of IT Security and Personal Data Protection in the ESG Framework

Environmental Dimension

Reducing Resource and Energy Consumption
Reducing Resource and Energy Consumption

BEM promotes infrastructure optimization by migrating from on-premise servers to cloud computing. This transition eliminates hardware redundancy, lowers electronic waste (e-waste), and reduces cooling system energy consumption, thereby maximizing resource efficiently.

Supporting Digital and Remote Work
Supporting Digital and Remote Work

BEM promotes a digital workplace by developing cloud-based systems that support remote access to data and applications. This enables employees to work flexibly without location constraints while maintaining international information security standards, ultimately reducing the need for travel and lowering greenhouse gas emissions.

Minimizing Hardware Redundancy
Minimizing Hardware Redundancy

BEM focuses on reducing hardware redundancy by migrating databases and computing systems from on-premise servers to centralized cloud management system. This maximizes the efficiency of computing and storage resources, minimizes maintenance burdens, and achieves long term cost savings.

Social Dimension

Protecting Employee and Customer Personal Data
Protecting Employee and Customer Personal Data

BEM promotes the development and application of advanced endpoint cybersecurity technologies, on Endpoint Detection and Response (EDR), to monitor, detect, and respond to cyber threats that may affect critical systems and data in a timely manner.

Enhancing Confidence in System Utilization
Enhancing Confidence in System Utilization

BEM promotes the foundation of robust access management systems together with the adoption of advanced technologies to create a safe digital space and foster a culture of responsible and secure technology utilization.

Promoting Equitable System Access
Promoting Equitable System Access

BEM promotes the development of user-friendly and inclusive access systems, ensuring that all user groups, including vulnerable groups or those with varying levels of digital literacy, can access the systems conveniently and securely. This initiative bridges the digital divide within the Company and ensures that data access is appropriately aligned with each user’s roles and responsibilities.

Governance Dimension

Enhancing Transparency and Accountability
Enhancing Transparency and Accountability

BEM promotes transparency and accountability in accordance with digital governance principles by implementing Role Based Access Control (RBAC) and the principle of Least Privilege. This framework allows the Company to clearly identify users and precisely define access boundaries for employee and customer personal data. When integrated with the EDR system, it ensures highly detailed and accurate tracking of system activities (Audit Logs), enabling immediate retrospective reviews in the event of anomalies. Consequently, this enhances the credibility of the Company’s decision-making and operational processes, ensuring alignment with international governance standards.

Mitigating Cyber Risks
Mitigating Cyber Risks

BEM focuses on risk mitigation to reduce the likelihood and impact of cyberattacks, data breaches, and system disruptions that could affect business operations.

Supporting Compliance with International Standards and Applicable Laws
Supporting Compliance with International Standards and Applicable Laws

BEM promotes operations that comply with relevant laws and standards, such as the Personal Data Protection Act (PDPA) and ISO/IEC 27001, thereby reducing legal risks and potential fines, strengthening corporate credibility, and enhancing data governance in alignment with international best practices.

The management of information security and personal data is therefore an integral part of supporting the organization's environmental, social, and governance criteria, alongside continuously enhancing operational efficiency and accountability.


IT Security and Data Privacy Operations

IT Security and Data Privacy Operations

In 2025, BEM continuously operated to enhance its information technology security, for example by applying advanced endpoint cybersecurity technology, specifically Endpoint Detection and Response (EDR) and enforcing control measures related to device systems, and network connectivity to manage cyber threat risks, build operational confidence in the digital era, and support business continuity.

Monitoring, Tracking, and Auditing via EDR
Monitoring, Tracking, and Auditing via EDR
BEM emphasizes the continuous enhancement of its information technology system security by implementing advanced endpoint cybersecurity technology, specifically Endpoint Detection and Response (EDR). In addition, data is integrated from multiple sources, including endpoints, networks, servers, and cloud platforms, enabling comprehensive monitoring, anomaly behavior analysis, detection, as well as rapid and precise response to cyber threats. This directly enhances data security, while minimizing the risks of data breaches or external attacks.
Access Control Measures for Data and Systems
Access Control Measures for Data and Systems
  • Physical Security & Privacy Control: BEM strictly implements access control measures for information equipment storage areas and data centers to prevent unauthorized access. Access to operational areas is managed through a standardized authentication system across the organization. Protecting the technological infrastructure secures personal data stored in both document and electronic formats, which enhances system confidence for employees and stakeholders.

  • Systemic Security & Data Privacy: BEM applies Role-Based Access Control (RBAC) together with the Least Privilege principle to ensure that access to personal data of employees and customers is limited strictly to a need-to-know basis. This minimizes the risk of data breaches and reinforces confidence in the Company’s digital governance.

Network Infrastructure Management
Network Infrastructure Management
BEM enhances its network infrastructure management to ensure robust security by designing a network segmentation architecture, together with access measures based on the principle of Least Privilege and Role-Based Access Control (RBAC), to restrict the scope of access to employees’ and customers’ personal data only to the necessary work units. Proper user grouping and access control ensure that internal data management is orderly, auditable, and compliant with security standards.
Information Security Analysis, Assessment, and Testing
Information Security Analysis, Assessment, and Testing

BEM regularly places importance on information security analysis, assessment, and testing, covering both Vulnerability Assessments and Penetration Testing for critical systems. This proactive analysis approach helps ensure that the Company's security systems remain consistently effective.

In addition, BEM conducts Phishing Drill exercises by simulating internal email deception scenarios to enhance cyber security awareness and assess employees' readiness to respond to phishing emails. The results of these drills are continuously utilized to improve measures, reduce risks, and enhance capabilities in handling deceptive emails.

Cybersecurity Incident Response Drills
Cybersecurity Incident Response Drills
BEM has established an Information Technology Security Incident Response Procedure to define the steps and sequence of actions when cyber threats occur. In this regard, the Company conducts various forms of Cybersecurity Incident Response on Critical Information Infrastructure (CII) Systems to enhance organizational readiness to effectively handle future cyber threat incidents.

Standard Certification

Standard Certification

In 2025, BEM continued to enhance its information technology security and data privacy. The Company achieved ISO/IEC 27001:2022 certification for various systems within its expressway business and rail business. These certified systems include data center systems, server systems, network systems, toll collection systems, intelligent traffic control systems, and back-office IT infrastructure. In total, the certified systems account for 40% of all Company systems.

Rail Business
Expressway Business

Related Documents