The NCSA is preparing measures to address cybersecurity risks involving CCTV systems and other smart devices.

The National Cyber Security Agency (NCSA) is preparing the country to deal with emerging attacks involving smart devices, particularly CCTV systems and virtual power plants (VPPs) in the energy sector, while deeming data sovereignty a priority.

"We see the risks for digital surveillance by monitoring specific data points, such as what time and where a vehicle was moving in and out, which could determine precisely a target's location and routine," AVM Amorn Chomchoey, secretary-general of NCSA, told the Bangkok Post.

The agency plans to introduce Internet of Things (IoT) security guidelines in September covering consumer smart home devices to help consumers choose safer devices.

The guidelines recommend several crucial security features, such as no-default passwords -- devices must not come up with default passwords; users are required to set their own.

In addition, the products must support firmware updates to patch future security issues.

Devices must have a notification system to alert users when a security vulnerability is detected.

This initiative involves collaboration with the Thai Intelligent CCTV Association, AVM Amorn said.

There are discussions about making these security requirements mandatory, he said.

Regulatory agencies may adopt and enforce these rules, specifically to control the importation of devices and ensure that non-standard, vulnerable products are not brought into the market.

However, if the guideline becomes mandatory, there is concern about whether the new standards will be compatible with older measures and if the effect will drastically increase the prices of products, AVM Amorn said.

By the end of this month, the NCSA expects to discuss security with power utilities, manufacturers and service providers of VPPs.

According to Electricity Generating Authority of Thailand, a VPP is a cutting-edge energy management platform that aggregates multiple small, scattered power sources into a single, large-scale power network without constructing a physical facility.

The integration of VPPs is a priority, with the goal of incorporating electricity from numerous small, decentralised producers, he said.

However, this integration creates massive new cybersecurity vulnerabilities because the grid will be connected to numerous small producers, meaning the attack surface for hackers is vastly expanded, said AVM Amorn.

Data manipulation

The core vulnerability of a VPP lies in the intersection of data and physical electricity, which the system relies on to calculate and manage demand and response. If hackers alter this data either at the source or while it is in transit, it creates a dangerous discrepancy between the digital information the grid receives and the actual physical electricity being supplied.

To prevent a catastrophic grid failure, several mandatory security measures are needed for VPPs. One is a network segmentation approach. The system architecture must be strictly segmented to ensure if one energy provider or node is successfully attacked, the breach remains contained and does not cascade to impact others on the grid.

Devices and equipment used by both providers and producers must have clear mechanisms for system updates, and there must be monitoring systems in place to verify data integrity.

Data Sovereignty

AVM Amorn said the Digital Economy and Society Ministry is considering how to handle the influx of foreign data centre investments and whether data should be localised by being kept on servers physically within Thailand.

"True data sovereignty is about regulatory power and the authority to control access to information, rather than physically trapping servers within national borders," he noted.

To illustrate the dangers of strict data localisation, he pointed to Ukraine. Just months before the Russian invasion, Ukraine amended its laws to allow state data to be migrated to foreign cloud providers, which ensured their government services could continue running smoothly without the fear of local data centres being physically destroyed in the conflict.

Forcing a sudden return of all data to local Thai servers could overwhelm data centre capacities, incur massive migration costs and potentially disrupt critical services like banking.

Instead, AVM Amorn advocated for robust cross-border data protection laws, which would allow Thailand to reap economic benefits while ensuring the government retains strict oversight and access control.