Digital Transformation
Digital Transformation
Challenges, Risks,
Thaioil Group foresees the potential of digital technology to enhance its competitive edge through the application of Artificial Intelligence (AI) innovation and digital transformation prioritizing security, user and customer-centric focus, and cost efficiency Additionally, the Company utilizes digital technology to drive and support its 2S1P strategic plan aiming to build efficiency in the existing core businesses, seeking opportunities for the future, and strengthen commercial competitiveness.
Regarding the promotion of core businesses, the Company applies digital technology and AI to optimize current business efficiency across all dimensions, including production, engineering, market analysis, and support for planning throughout the supply chain. Furthermore, AI is employed as a key assistant in the research and development of new businesses, as well as in supporting investment decisions. Additionally, digital technology is applied to enhance commercial capabilities by analyzing data to gain deep customer insights and experience, thereby continuously elevating the customer experience.
Nonetheless, sustainable digital transformation remains a significant challenge. The Company recognizes the importance of laying a foundation of reliable data and developing the digital competencies of its personnel. Accordingly, the Company has developed a Data Hub to collect and integrate central data for effective analysis and decision-making. Concurrently, data governance standards have been established to ensure proper data management and build confidence among all stakeholders. Moreover, the Company has defined a policy for the use of Generative AI to ensure that AI development and usage are safe, transparent and in compliance with laws and regulations. At the same time, the Company continuously strengthens knowledge and promotes data culture for employees through training and activities. This fosters the effective use of data and AI to serve as a critical factor in driving Thaioil Group’s digital strategy towards achieving its goals and ensuring sustainable growth in the digital era.
Thaioil Group is committed to enhancing competitiveness with digital operations and cybersecurity throughout the business activities across the supply chain. The Company has established the digital strategic framework in accordance with its business directions and strategies. This framework focuses on digital transformation, leveraging data-driven decision-making, implementing robust cybersecurity by using the NIST Cybersecurity Framework from the National Institute of Standards and Technology (NIST), USA, as a management guideline, fostering a modern working environment, and providing efficient IT services.
Targets
Digital Maturity Index - Establish a digital foundation to enhance competitiveness and empower employees with vital skills and capabilities to effectively utilize technology.
Targets 2025
Performer(1)
(Level 3 out of 4 levels)
Long-term Targets 2030
Strong Performer (2)
(Level 3 out of 4 levels)
Cyber-attacks that affect business operations (Damage to Business)
Targets 2025
Case
0
Long-term Targets 2030
Case
0
Internal Customer
Satisfaction
Targets 2025
Percentage
80
Long-term Targets 2030
Percentage
80
Employee pass rate for Phishing Email Exercise
Targets 2025
Percentage
Greater than or equal to
87
Long-term Targets 2030
Percentage
Greater than or equal to
87
Cybersecurity Maturity
Targets 2025
Cyber Maturity Score (Max 5 points)
3.2 points for Information Technology
2.9 points for Operational Technology
Long-term Targets 2030
Cyber Maturity Score (Max 5 points)
3.6 points for Information Technology
3.2 points for Operational Technology
Remarks
(1) “Performer” level indicates that the Company’ functions leverage on digital capabilities effectively.
(2) “Performer” level corresponds to an assessment score range of 50 – 74 points out of 100 points. The expectation is to elevate digital capabilities to the upper half of the Performer level specifically targeting a score of at least 62 points or higher (Strong Performer).
Management Approach
and Performance
Committees and Working Groups
Thaioil Group has established the Digital Steering Committee (DGSC) and the Cyber Emergency Response Team (CERT) to drive digital operations and enhance cybersecurity efficiently. The Company has appointed personnel with expertise to oversee cyber management throughout the management level and the operational level. Performance is regularly reported to the management executives while reporting the information security and cybersecurity risk management to the Risk Management Committee (Board level).
Committees and Working Groups
Thaioil Group Digital Steering Committee (DGSC)
Thaioil Group Digital Steering Committee (DGSC) was established in March 2022 to enhance the effectiveness and efficiency of our Digital Management.
The Committee Structure | ||
|---|---|---|
1. Chief Executive Officer and President | (CEO) Chairman | |
2. Senior Executive Vice President – Hydrocarbon | (SEVP) Vice Chairman | |
3. Executive Vice President – Corporate Commercial | (EVPC) Committee | |
4. Executive Vice President – Operation Excellence | (EVPE) Committee | |
5. Executive Vice President – Finance and Accounting | (EVPF) Committee | |
6. Executive Vice President – Corporate Governance and Sustainability | (EVPG) Committee | |
7. Executive Vice President – Manufacturing | (EVPM) Committee | |
8. Executive Vice President – Power, New Business and Digitalization | (EVPN) Committee | |
9. Executive Vice President – Organization Effectiveness | (EVPO) Committee | |
10. Executive Vice President – Strategy | (EVPS) Committee | |
11. Vice President – Digitalization | (DGVP) serves as the Committee’s Secretary
| |
Thaioil Group Digital Steering Committee Oversees
The DGSC oversees Thaioil Group’s technology development and incorporation of technological tools. The scope of works covers: The scope of works covers:
1. Digital Technology
2. Telecommunications
3. Operation and Refinery Control
4. Control Engineering of Measuring Tools
Roles and Responsibilities for the DGSC
- Determine the directions, policies, and strategies for Thaioil Group digitalization management.
- Supervise and manage digital operations in alignment with digital management policy and make decisions in the digital management strategy.
- Drive the policies, standards, and governance frameworks to increase operation’s efficiency and Thaioil’s competitiveness in the market.
- Oversee the risk management on digital and cyber security and act in compliance with domestic laws to gain and build trust from stakeholders.
- Participate in developing the master plan and budget allocation relating to digital technology matters.
- Provide advice and suggestions on digital technology to relevant operations.
- Analyze, review, and monitor the progress of digital practices and report to the Board of Directors as appropriate.
Thaioil Group Digital Steering Committee holds a meeting to consider matters related to their roles and responsibilities every quarter or as necessary. Also, the Committee reports the progress to the Board of Directors at least once a year or as appropriate.
Thaioil Group Digital Steering Committee holds a meeting to consider matters related to their roles and responsibilities every quarter or as necessary. Also, the Committee reports the progress to the Board of Directors at least once a year or as appropriate.
Cyber Emergency Response Team (CERT)
Cyber Emergency Response Team (CERT) was established in March 2022 to oversee and respond to digital emergencies. The purpose is to promptly recover from emergencies and return to normal system operations while maintaining Thaioil Group’s business continuity and minimizing any negative impacts or losses.
CERT Structure
1. Executive Vice President – Power, New Business and Digitalization as CERT Commander
2. Manager – Legal as Lawyer Team
3. Vice President – Corporate Strategic Risk as Risk, BCM and Insurance Team
4. Manager – Business Continuity Management as Risk, BCM and Insurance Team
5. Manager – Corporate Insurance Management as Risk, BCM and Insurance Team
6. Manager – Security as Physical Security Team
7. Manager – Employee Relation as Information Center Team
8. Manager – Public Affairs Coordination-Brand Management as Information Center Team
9. Manager – Refinery Relation Coordinator – Refinery Public Relation as Information Center Team
10. Manager – Investor Relations as Information Center Team
11. Manager – Domestic Commercial Operations – Petroleum & Petrochemicals as Information Center Team
12. Vice President – Digitalization as Response Management Team
13. Vice President – Engineering as Response Management Team
14. Vice President – Technology as Response Management Team
15. PTT Digital Computer Security Incident Response Team (CSIRT) (Response Team)
Roles and Responsibilities of the CERT Team
The Executive Vice President of Power, New Business, and Digitalization (EVPN) is positioned as the Chief Information Security Officer (CISO) or CERT Commander to oversee the Company’s cybersecurity in accordance with ISO27001 Information security management systems. The roles and responsibilities of CERT are:
1. Formulate management strategies to respond to emergency situations.
2. Develop the emergency management plan and assign the key responsibility for each activity to ensure that all those involved in the plan understand their roles and responsibilities.
3. Monitor and assess the situation to provide recommendations in responding to an emergency situation and returning to normal operations.
4. Report and communicate the emergency situations to relevant parties, including the executives and refineries, while providing information on the incident, action plans, current status, and the impact on the Company’s production or business operations.
Cyber Emergency Response Team (CERT)
Cyber Emergency Response Team (CERT) was established in March 2022 to oversee and respond to digital emergencies. The purpose is to promptly recover from emergencies and returning to normal system operations while maintaining Thaioil Group’s business continuity and minimizing any negative impacts or losses.
CERT Structure includes
- Executive Vice President – Power, New Business and Digitalization as CERT Commander
- Manager – Legal as Lawyer Team
- Vice President – Corporate Strategic Risk as Risk, BCM and Insurance Team
- Manager – Business Continuity Management as Risk, BCM and Insurance Team
- Manager – Corporate Insurance Management as Risk, BCM and Insurance Team
- Manager – Security as Physical Security Team
- Manager – Employee Relation as Information Center Team
- Manager – Public Affairs Coordination-Brand Management as Information Center Team
- Manager – Refinery Relation Coordinator – Refinery Public Relation as Information Center Team
- Manager – Investor Relations as Information Center Team
- Manager – Domestic Commercial Operations – Petroleum & Petrochemicals as Information Center Team
- Vice President – Digitalization as Response Management Team
- Vice President – Engineering as Response Management Team
- Vice President – Technology as Response Management Team
- PTT Digital Computer Security Incident Response Team (CSIRT) (Response Team)
Roles and Responsibilities of the CERT Team
The Executive Vice President-Power, New Business and Digitalization (EVPN) is positioned as the Chief Information Security Officer (CISO) or CERT Commander to oversee the Company’s cybersecurity in accordance with ISO27001 Information security management systems. The roles and responsibilities of CERT are:
- Formulate management strategies to respond to emergency situations.
- Develop the emergency management plan and assign the key responsibility for each activity to ensure that all those involved in the plan understand their roles and responsibilities.
- Monitor and assess the situation to provide recommendations in responding to an emergency situation and returning to normal operations.
- Report and communicate the emergency situations to relevant parties, including the executives and refineries, while providing information on the incident, action plans, current status, and the impact on the Company’s production or business operations.
Digital Policy
Thaioil Group has announced the digital-related policies as follows:
- The TOP Group Digital Policy is established to govern business operations, provide business direction, adopt the digital technology, and communicate within Thai Oil Public Company Limited and its subsidiaries. The policy aligns with international best practices, the Company’s Enterprise Architecture, and the Data Governance Framework.
- The Cyber Security Policy is established to ensure that the information systems of Thai Oil Public Company Limited and its subsidiaries have prevention and effective cyber risk management.
- Social Networking Policy is established to govern and provide direction on data dissemination, access to social media and electronic services, and opinion expression.
- The Personal Data Protection Policy (PDPA) is established to provide criteria, mechanisms, and measures to manage personal data appropriately. The policy also highlights the right of privacy and personal data protection when conducting transactions with the Company.
- Generative AI Policy is established to define the direction for governance, usage, and development of Gen AI within Thai Oil Public Company Limited and its subsidiaries to ensure alignment with relevant international standards and clarify the effective use of Gen AI. The policy also enhances business competitiveness, promotes innovation, and remains within the boundaries of law and ethical standards of society.
Digital Master Plan 2022 - 2030
The Digital Master Plan has been developed to support business operations with short-, medium-, and long-term frameworks in different aspects, including:
Strengthen Business Competitiveness (Agile Domain Digital Platform)
Integrate digital technology throughout the Company’s value chain to support the business strategy, and link to the core work processes through the Value Chain Digital Platform (VCDP) project.
Evolving into a Data and AI Driven Decision-Making Organization
(Big Data & Artificial Intelligence (AI))
Ensure reliable and efficient data utilization and promote the use of artificial intelligence technology by selecting interesting use cases within the Company and conducting Proof of Concept (POC) projects before scaling up.
Cybersecurity Readiness
(Cyber Resilience)
Develop a cybersecurity system based on the Zero Trust principle and establish measures and practices to prepare for potential cyber threats regularly.
Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization (Digital Workplace)
Upgrade infrastructure systems, such as improving the Wi-Fi system for better performance, enhancing the capabilities of laptops, and upgrading the meeting room systems for increased convenience, to facilitate seamless and flexible hybrid work from anywhere.
Employee Digital Skills Development (People)
Establish a framework for enhancing digital literacy and skills through various initiatives, including conducting digital skills training for employees and inviting external experts to provide insights on emerging technologies.
Strengthen Business Competitiveness
(Agile Domain Digital Platform)
Enhance business processes with digital technology in the form of Business Digital Platform to integrate the working process.
Evolving into a Data and AI Driven Decision-Making Organization
(Big Data & Artificial Intelligence (AI))
Promote and facilitate the adoption of developed AI / Generative AI for wider use (Adoption at Scale).
Cybersecurity Readiness
(Cyber Resilience)
Examine and adopt new innovative technologies to improve cybersecurity, both in defense and incident response (Automated Defend & Response).
Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization (Digital Workplace)
Develop an IT service system as a centralized “One-Stop Service Platform” and providing services with standardized ITSM (IT Service Management)..
Employee Digital Skills Development (People)
Establish digital proficiency as the foundation and basic qualification for employees at all levels.
Strengthen Business Competitiveness
(Agile Domain Digital Platform)
Achieve business excellence (Intelligence Business) by adopting digital technology as an automated tool to support every working process.
Evolving into a Data and AI Driven Decision-Making Organization
(Big Data & Artificial Intelligence (AI))
Seek new business opportunities of the Big Data from organization-managed information.
Cybersecurity Readiness
(Cyber Resilience)
Consistently develop cybersecurity system to become the leader on cybersecurity in the oil and gas industry.
Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization (Digital Workplace)
Boost productivity and enhance employee well-being by providing and advancing IT and digital infrastructure.
Employee Digital Skills Development (People)
Educate employees to continuously pursue digital skills and strive towards “Digital Natives”.
Digital Management Approach
In 2025, Thaioil Group successfully implemented core focus areas as the part of the Company’s digital strategy as follows:
Digital Transformation
The Company prioritizes the integration of digital technology to enhance business competitiveness. The Company has established a strategic plan and executed various projects related to digital technology. Moreover, the Company monitors the project performance and reviews the plan on a regular basis. This aims to ensure that the adaptation of digital technology is aligned with the business targets during the changing situation. The following are key projects:
Agile Domain Digital Platform
COMNXT Project: Electronic Nose (E-Nose) Application is the use of AI to monitor, detecting, and notifying the unpleasant odors that arise from the production process and other activities and may affect the employees, contractors, or surrounding communities. The system is active 24 hours a day, allowing the Company to identify the sources of unpleasant odors and manage them appropriately.
Outward Remittance Process Enhancements with Banking Business Net Project: Support the Company’s international remittance processes, such as crude oil purchasing payments, which involve foreign exchange (FX) rate. The developed system features Host-to-Host connectivity with multiple banks providing increased transaction options to ensure more competitive exchange rate and enhance the Company’s potential for value creation.
Supplier Portal Project (A Centralized Procurement Data Hub for Thaioil Group’s Suppliers): Allow suppliers to track procurement status, verify documents, and access reports by themselves. The system also supports multi-dimensional supplier background checks, including Media Pre-screening, Sanction Checking, and Compliance Checking, which mitigate risks, reduce instances of non-compliance, and effectively supports the Company’s decision-making process regarding supplier selection.
TOPLABCS Project: Enhance automation within laboratory operations, covering End-to-End processes ranging from Equipment Performance monitoring and Inventory Management to Staff Competency assessment and development. This project facilitates systematic integration of laboratory operations and enables effective centralized process management in alignment with the laboratory quality management system.
Big Data & AI – Developing a Data-Driven and AI-Based Decision-Making Organization
The Company established a new department named the ‘Digitalization – Data and AI Section’ to drive the use of data within the Company, implement Artificial Intelligence (AI) technology more concretely, and promote use cases within the Company to increase their widespread adoption. The following are key projects:
| Projects | Details | Achievement Indicators | Relevant ESG |
| Electronic Nose Project | Electronic Nose (E-Nose) Application is the use of AI to monitor, detect, and notify the unpleasant odors that arise from the production process and other activities and may affect the employees, contractors, or surrounding communities. The system is active 24 hours a day, allowing the Company to identify the sources of unpleasant odors and manage them appropriately. | Reduce community complaints regarding odor pollution. |
|
| Inspection Corporate Gen AI (IK-Q) Project | IK-Q Inspection (Intelligence – Knowledge – Query) is the use of Generative AI developed to serve as Domain Expert Agent across various fields, such as engineering, technical query resolution, Oil Market analysis, and other specialized knowledge areas. Additionally, the system is capable of performing data analysis and providing preliminary recommendations to support both engineers and general employees. | Reduce work time | Human Capital Development |
| Predictive Maintenance Analytics Project | Predictive Maintenance Analytics powered by AI covers various equipment within the production unit. It predicts the likelihood of equipment damage leading to hydrocarbon leaks and spills and help avoid unplanned shutdowns and maintenance while reducing the risks associated with potential failures. | Reduce the likelihood of chemical spills and equipment damage due to lack of prior protection. protection. | Risk Management |
Cybersecurity Management
Thaioil Group has adopted the National Institute of Standards and Technology (NIST) Cybersecurity Framework from the United States, and Zero Trust Architecture protection guidelines into its management approaches. The approaches include login examination and granting users the minimum necessary permissions to ensure that Thaioil Group has appropriate cyber risk controls for its size and diversity. Key activities include:
- Engage external consultants to assess security gaps in accordance with the NIST 0 framework and develop an improvement plan to ensure the Company’s readiness in governance, detection and prevention systems, as well as sustainable processes for addressing cyber threats.
- Implement anomaly detection systems within the main DCS of the Operation Technology (OT) production system to ensure rapid and continuous monitoring of potential threats to production systems.
- Develop a Cloud Security improvement plan and implement systems to detect misconfigurations or vulnerabilities within the Cloud system. This facilitates the adjustment of configurations and the remediation of vulnerabilities in Cloud-based applications to ensure security.
- Upgrading digital systems and applications affected by obsolescent technology (Application Obsolescence) ensures they are modern and current. This helps prevent cyber risks and threats arising from vulnerabilities in obsolete systems and applications, providing users with confidence in safe and secure usage.
- Implement Multifactor Authentication (MFA) for all internet-facing applications accessed from outside the Company.
- Implement Data Classification and Data Handling Adoption, specifically targeting high-risk user groups, such as executives.
- Enforce Data Encryption on database systems containing sensitive personal data.
Cyber Emergency Response
- Monitor and respond to cyber events and cybersecurity threats, supplementing the external service provider (Manage Defense and Response: MDR) through the Security Operating Center (SOC), with continuously monitoring and managing cyber risks for 24 hours a day.
- Arrange for a service to search for risks of accessing applications or various IT services on the internet (Attack Surface Management) to increase the ability to detect threats or anomalies rapidly.
- Arrange for services to monitor, alert, investigate, and remediate cyber threats by experts in anomaly detection (MDR) to build confidence in handling such threats, in addition to the main service provider which is the Cyber Operation Centre (SOC).
- Conduct vulnerability assessments every 3 months and ensure that the remediation of defects is completed.
- Conduct Penetration Testing and Red Teaming to find vulnerabilities by external experts on an annual basis.
- Conduct Ransomware Assessment to ensure preparedness for handling cyber incidents regarding data ransom by reviewing processes and operation manuals (Cyber Emergency Response Procedure and Playbook) to update them to be current and conduct practice drills at least 2 times per year. This covers both Information Technology and Operation Technology and integrates into the Business Continuity Plan. It includes communication to external units and stakeholders when such incidents occur, as well as reporting operational results to executives regularly, including reporting on risk management regarding information security and cybersecurity to the Risk Management Committee.
Digital Knowledge and Cybersecurity Awareness Promotion for Employees (Digital Cultivation)
- Disseminate knowledge through various media channels to foster employee interest and raise awareness regarding cybersecurity.
- Conduct awareness training tailored to specific user groups, including executives, general employees and system administrators.
- Raise awareness of phishing email threats to new employees through the New Staff Orientation Program and conduct unannounced phishing email tests for employees approximately every three months and subsequently report the test results to the executives. Employees who do not pass the tests are required to attend additional training on the prevention of phishing email threats.
- Communicate and educate on digital laws, such as the Computer Crime Act and the Copyright Act.
- Develop online training courses to enhance understanding and provide basic guidelines regarding the Personal Data Protection Act (PDPA) requiring all employees to attend and complete the testing. Additionally, communicating the Personal Data Retention Guideline (covering collection, deletion, or destruction of personal data) through the Compliance Newsletter.
2025
Performance
Performance | ||
|---|---|---|
Financial Capital
| Cases of cyberattacks affecting the business operations | 0 case |
Number of breaches of information security | 0 case | |
Intellectual Capital
| All IT infrastructure with cyber threats obtained ISO27001 certification, including 1. The Data Center, SAP, and LIMS systems, under the control and management of the Digital Function. 2. Advanced Process Control Network, under the control and management of the Technology Process Control Function, which supports service activities and work processes within the Thaioil Group. 3. Instrument Network, under the control and management of the Instrument Engineering Functions. 4. Telecommunication and ELICS systems, under the control and management of the Electrical Engineering functions. | 100% |
Cybersecurity Awareness training for new employees | 100% for new employees | |
Phishing Email Exercise for employees | 4 times per year | |
Employee pass rate for Phishing Email Exercise | 96% | |
Social and Relationship Capital
| Internal Customer Satisfaction | 87% |