IT Security and Data Privacy

Goal 9:
Goal 16:
Management Guidelines and Practices
BEM has appointed the Information Security Management Committee to oversee and manage IT security.
The Information Security Management Committee reports performance through the Information Security Management Representative to (1) the Quality Management System Committee, which comprises high level executives (C-Level), i.e., the Managing Director, Deputy Managing Director for Operations and Engineering (Rail), Deputy Managing Director for Business Development and Expressway Operations, and the Deputy Managing Director for Administration, as the Chairman and members of the Committee, respectively.
Impact on Business and Stakeholders
The increasing use of technology to drive businesses has led to a higher risk of threats to the information system. Therefore, an external attack on the information system may cause disruption to the Company's service system and damage business operations, reputation, and reliability. Furthermore, leakage of key data or personal information of customers, suppliers and employees may violate privacy rights and destroy stakeholder confidence. This may also result in lawsuits being filed with regulatory authorities which may affect investor confidence in the long run.
Commitment, Challenges and Opportunities
BEM places importance on governing IT security and Data privacy to support internal operations and service expansions through the digital system.
The Company has made improvements to ensure that our IT system is secure and consistent with the ISO/IEC 27001 international standards. We have invested in the development of a more efficient system infrastructure to support the future increase in system usage. We have also formulated a plan to address cyber-attacks using cryptographic control and conducted various system tests to upgrade IT security. A safe and secure IT system also provides protection to the privacy of stakeholders against personal data leakage. More importantly, BEM has established operational guidelines related to data privacy in accordance with the Personal Data Protection Act B.E. 2562 (2019).
Targets and Performance Indicators
BEM aims to prevent information technology security breaches, ensure no impact on customers, employees or other stakeholders, and maintain a record of zero confirmed personal data breach complaints from customers, external organizations, or government agencies.
Information Technology Security Breach
Target
2025 Performance
Affected Customers, Employees, or Stakeholders
Target
2025 Performance
Confirmed Customer Personal Data Breach Complaints
Target
2025 Performance
Complaints by External Organizations
Target
2025 Performance
Complaints by Government Agencies
Target
2025 Performance
Note: 1/ One cyberattack was detected in 2025, but the Company contained them successfully, preventing any impact on services or personal data breaches.
Policy and Practices
Information Security Policy and Practices
BEM has announced an Information Security Policy and developed an Information Technology Security Manual as a guideline for employees, system administrators, and external parties working with the Company. The Company conducts audits and reviews of the policy at least once a year.
BEM has appointed an Information Security Management Committee to oversee and manage information technology security. The committee is chaired by the Assistant Managing Director of the Information and Technology Group, who acts as the management representative for information security. The committee conducts regular reviews and reports key information security issues to the Corporate Governance, Risk Management and Sustainable Development Committee on an annual basis. This ensures that the Company’s information security measures remain up to date and aligned with international standards.
Personal Data Protection Policy and Practices
BEM has established a Personal Data Protection Committee, overseen by the Deputy Managing Director of Administration, who serves as Chairman of the Personal Data Protection Committee, and Data Protection Officer (DPO) to oversee the development, review, and continuous implementation of personal data protection policies and practices.
To comply with the Personal Data Protection Act B.E. 2562 (2019), BEM has developed the Personal Data Protection Policy and Practices and communicated them to all employees for acknowledgement and strict adherence. The policy and practices are also shared with external stakeholders via the Privacy Data Center on the Company's website. In addition to legal penalties, employees who violate the policy and practices may face disciplinary action, including verbal or written warning, dismissal, and termination without severance pay as stipulated by law.
Role of IT Security and Personal Data Protection in the ESG Framework
Environmental Dimension

Reducing Resource and Energy Consumption
BEM promotes infrastructure optimization by migrating from on-premise servers to cloud computing. This transition eliminates hardware redundancy, lowers electronic waste (e-waste), and reduces cooling system energy consumption, thereby maximizing resource efficiently.

Supporting Digital and Remote Work
BEM promotes a digital workplace by developing cloud-based systems that support remote access to data and applications. This enables employees to work flexibly without location constraints while maintaining international information security standards, ultimately reducing the need for travel and lowering greenhouse gas emissions.

Minimizing Hardware Redundancy
BEM focuses on reducing hardware redundancy by migrating databases and computing systems from on-premise servers to centralized cloud management system. This maximizes the efficiency of computing and storage resources, minimizes maintenance burdens, and achieves long term cost savings.
Social Dimension

Protecting Employee and Customer Personal Data
BEM promotes the development and application of advanced endpoint cybersecurity technologies, on Endpoint Detection and Response (EDR), to monitor, detect, and respond to cyber threats that may affect critical systems and data in a timely manner.

Enhancing Confidence in System Utilization
BEM promotes the foundation of robust access management systems together with the adoption of advanced technologies to create a safe digital space and foster a culture of responsible and secure technology utilization.

Promoting Equitable System Access
BEM promotes the development of user-friendly and inclusive access systems, ensuring that all user groups, including vulnerable groups or those with varying levels of digital literacy, can access the systems conveniently and securely. This initiative bridges the digital divide within the Company and ensures that data access is appropriately aligned with each user’s roles and responsibilities.
Governance Dimension

Enhancing Transparency and Accountability
BEM promotes transparency and accountability in accordance with digital governance principles by implementing Role Based Access Control (RBAC) and the principle of Least Privilege. This framework allows the Company to clearly identify users and precisely define access boundaries for employee and customer personal data. When integrated with the EDR system, it ensures highly detailed and accurate tracking of system activities (Audit Logs), enabling immediate retrospective reviews in the event of anomalies. Consequently, this enhances the credibility of the Company’s decision-making and operational processes, ensuring alignment with international governance standards.

Mitigating Cyber Risks
BEM focuses on risk mitigation to reduce the likelihood and impact of cyberattacks, data breaches, and system disruptions that could affect business operations.

Supporting Compliance with International Standards and Applicable Laws
BEM promotes operations that comply with relevant laws and standards, such as the Personal Data Protection Act (PDPA) and ISO/IEC 27001, thereby reducing legal risks and potential fines, strengthening corporate credibility, and enhancing data governance in alignment with international best practices.
The management of information security and personal data is therefore an integral part of supporting the organization's environmental, social, and governance criteria, alongside continuously enhancing operational efficiency and accountability.

IT Security and Data Privacy Operations
In 2025, BEM continuously operated to enhance its information technology security, for example by applying advanced endpoint cybersecurity technology, specifically Endpoint Detection and Response (EDR) and enforcing control measures related to device systems, and network connectivity to manage cyber threat risks, build operational confidence in the digital era, and support business continuity.
Monitoring, Tracking, and Auditing via EDR
Access Control Measures for Data and Systems
-
Physical Security & Privacy Control: BEM strictly implements access control measures for information equipment storage areas and data centers to prevent unauthorized access. Access to operational areas is managed through a standardized authentication system across the organization. Protecting the technological infrastructure secures personal data stored in both document and electronic formats, which enhances system confidence for employees and stakeholders.
-
Systemic Security & Data Privacy: BEM applies Role-Based Access Control (RBAC) together with the Least Privilege principle to ensure that access to personal data of employees and customers is limited strictly to a need-to-know basis. This minimizes the risk of data breaches and reinforces confidence in the Company’s digital governance.
Network Infrastructure Management
Information Security Analysis, Assessment, and Testing
BEM regularly places importance on information security analysis, assessment, and testing, covering both Vulnerability Assessments and Penetration Testing for critical systems. This proactive analysis approach helps ensure that the Company's security systems remain consistently effective.
In addition, BEM conducts Phishing Drill exercises by simulating internal email deception scenarios to enhance cyber security awareness and assess employees' readiness to respond to phishing emails. The results of these drills are continuously utilized to improve measures, reduce risks, and enhance capabilities in handling deceptive emails.
Cybersecurity Incident Response Drills

Standard Certification
In 2025, BEM continued to enhance its information technology security and data privacy. The Company achieved ISO/IEC 27001:2022 certification for various systems within its expressway business and rail business. These certified systems include data center systems, server systems, network systems, toll collection systems, intelligent traffic control systems, and back-office IT infrastructure. In total, the certified systems account for 40% of all Company systems.