The National Cyber Security Agency (NCSA) and Microsoft co-organized the “Zero Trust Guidelines in Action Workshop” to strengthen cybersecurity readiness across Thailand’s public, private, and Critical Information Infrastructure (CII) sectors. The workshop focused on accelerating the adoption of Zero Trust security principles paired with AI capabilities to build proactive, sustainable defenses against modern cyber threats.
Today’s cyber threat landscape is rapidly growing more complex as digital technology and AI become central to organizational operations. At the same time, threat actors are leveraging AI and automation to scan for vulnerabilities and execute attacks faster than ever. As a result, response windows have collapsed dramatically, shifting from days in the past to just hours or even minutes.
Compromised credentials add to this risk, with Thailand accumulating nearly 300 million leaked accounts and passwords across public databases. With adversaries wielding stolen credentials alongside AI-powered tools, traditional security architectures relying solely on perimeter defenses or password authentication can no longer protect an enterprise’s digital assets.
Zero Trust: Staying Ahead of Evolving Threats
Emphasizing national policy directions and the urgency of Zero Trust adoption, AVM Amorn Chomchoey, Secretary-General of the National Cyber Security Agency, said: “Cyber threats are advancing too fast for organizations to rely on usernames and passwords alone. As Thailand’s primary cybersecurity authority, NCSA is pushing for Zero Trust guidelines to become a key standard for CII operators and local organizations over the next two years. This aligns with the ‘Assume Breach’ principle, which requires organizations to be ready to contain impact while verifying every access request without implicit trust.
Zero Trust isn’t just about buying new technology; it’s a strategic effort that must be led by executive leadership because cybersecurity is an enterprise risk management priority, not just an IT task. Co-hosting this practical workshop with Microsoft is an important milestone to help organizations assess their readiness, build clear roadmaps, and work together to secure Thailand’s digital ecosystem to global standards.”
Microsoft AI-First Security: Next-Generation Enterprise Protection
To help advance the national cybersecurity framework, Brett Lightfoot, Director of Industry Advisory for Asia at Microsoft, shared security concepts and solutions aligned with NCSA’s direction, grounded in Microsoft’s core Zero Trust principles that are critical to building digital resilience across enterprise environments:
- Verify explicitly: Always authenticate and authorize using all available data points to verify that user requests are legitimate. Verification applies equally to every request—with no shortcuts for internal corporate traffic, which could be spoofed by attackers inside the network.
- Use least privilege access: Limit access rights strictly to what users need for their roles, giving employees what they need to stay productive without creating unnecessary risk.
- Assume breach: Build networks, access controls, and real-time response systems to contain attack impact. Use end-to-end encryption and continuous analytics to spot suspicious activity early.
Microsoft’s AI-First Security architecture protects six key pillars across the organization: Identity, Endpoints, Applications, Data, Infrastructure, and Network. Microsoft also highlighted its end-to-end AI-First security platform, including Microsoft Security and Microsoft Sentinel. Powered by Microsoft Global Threat Intelligence, the platform helps organizations defend, detect, and respond to threats quickly and accurately in fast-changing environments.
The Zero Trust Guidelines in Action Workshop covered policy, technology, and compliance, tailoring Microsoft security tools to the operational environments of Critical Information Infrastructure (CII) entities. The event featured real-world insights from public-sector Zero Trust rollouts in the U.S. and Australia based on the NIST SP 800-207 framework. Experts also provided guidance on aligning with Thailand’s Cybersecurity Act B.E. 2562 (2019), connecting it to global standards such as ISO/IEC 27001 and NIST CSF. Industry-focused breakout sessions gave participants hands-on opportunities to assess their readiness and build tailored Zero Trust roadmaps for their organizations.
To learn more about NCSA’s Zero Trust guidelines, visit www.NCSA.or.th/standards. For details on Microsoft’s AI-First security platform and strategies, visit Microsoft Zero Trust Security and Strategy.
