Digital Transformation
Digital Transformation
Challenges, Risks,
Thaioil Group foresees the potential of using digital technology in business activities to align with the Company’s 3Vs strategy. The focus is on developing digital projects as a Business Digital Platform across the value chain, which includes purchasing crude oil, production process, product sales, customer interactions, human capital development, procurement, governance, risk & compliance (GRC), and data collection to enhance competitiveness. In addition, the Company has developed agile projects to enrich new users’ experience by creating a digital ecosystem with safe and appropriate technologies to enhance flexibility and improve employee engagement.
Thaioil Group recognizes the value and importance of data, which is prevalent in the industry. The Company manages and governs the use of internal information and has developed a centralized data platform to collect and analyze data for operational enhancement. This will lead to the highest benefit for Thaioil Group’s business both present and in the future. Furthermore, the Company emphasizes the risks of cybersecurity and cyber-attacks that may arise on digital platforms. This ensures that the information is secured and well-protected, without adverse impacts on the business operations and confidence among all relevant stakeholders.
The Company places great importance on organizational structure and recruits personnel with digital capabilities, knowledge, and skills. In parallel, the Company also prioritizes the development of digital skills, ensuring all employees understand the working process related to digital projects. These factors pivotally drive the Digital Strategy according to the set targets and plans. As a result, Thaioil Group is able to conduct business efficiently and sustainably in the digital era.



Targets
Digital Maturity Index - Establish a digital foundation to enhance competitiveness and empower employees with vital skills and capabilities to effectively utilize technology.
Targets 2024
Literate(1)
(Level 2 out of 4 levels)
Long-term Targets
Performer (2)
(Level 3)
*Digital Maturity Index (DMI)
Cyber-attacks that affect business operations (Damage to Business)
Targets 2024
Case
0
Long-term Targets
Case
0
Internal Customer
Satisfaction
Targets 2024
Percentage
78
Long-term Targets
Percentage
78
Remarks
(1) “Literate” level indicates that the Company has established a Digital Master Plan and utilized digital technology for certain operational processes
(2) “Performer” level indicates that the Company’ functions leverage on digital capabilities effectively.
Management Approach
and Performance
Committees and Working Groups
Thaioil Group has established the Digital Steering Committee (DGSC) and the Cyber Emergency Response Team (CERT) to drive digital operations and enhance cybersecurity efficiently. The Company has appointed personnel with expertise to oversee cyber management throughout the management level and the operational level. Performance is regularly reported to the management executives while reporting the information security and cybersecurity risk management to the Risk Management Committee (Board level).


Committees and Working Groups
Thaioil Group Digital Steering Committee (DGSC)
Thaioil Group Digital Steering Committee (DGSC) was established in March 2022 to enhance the effectiveness and efficiency of our Digital Management.
The Committee Structure | ||
---|---|---|
1. Chief Executive Officer and President | (CEO) Chairman | |
2. Senior Executive Vice President – Hydrocarbon | (SEVP) Vice Chairman | |
3. Executive Vice President – Corporate Commercial | (EVPC) Committee | |
4. Executive Vice President – Operation Excellence | (EVPE) Committee | |
5. Executive Vice President – Finance and Accounting | (EVPF) Committee | |
6. Executive Vice President – Corporate Governance and Sustainability | (EVPG) Committee | |
7. Executive Vice President – Manufacturing | (EVPM) Committee | |
8. Executive Vice President – Power, New Business and Digitalization | (EVPN) Committee | |
9. Executive Vice President – Organization Effectiveness | (EVPO) Committee | |
10. Executive Vice President – Strategy | (EVPS) Committee | |
11. Vice President – Digitalization | (DGVP) serves as the Committee’s Secretary
|
Thaioil Group Digital Steering Committee Oversees
The DGSC oversees Thaioil Group’s technology development and incorporation of technological tools. The scope of works covers:
1. Digital Technology
2. Telecommunications
3. Operation and Refinery Control
4. Control Engineering of Measuring Tools
Roles and Responsibilities for the DGSC
1. Determine the directions, policies, and strategies for Thaioil Group digitalization management.
2. Supervise and manage digital operations in alignment with digital management policy and make decisions in the digital management strategy.
3. Drive policies, standards, and governance frameworks to increase operation’s efficiency and Thaioil’s competitiveness in the market.
4. Oversee risk management on digital and cyber security and act in compliance with domestic laws to gain and build trust from stakeholders.
5. Participate in developing the master plan and budget allocation relating to digital technology matters.
6. Provide advice and suggestions on digital technology to relevant operations.
7. Analyze, review, and monitor the progress of digital practices and report to the Board of Directors as appropriate.
Thaioil Group Digital Steering Committee holds a meeting to consider matters related to their roles and responsibilities every quarter or as necessary. Also, the Committee reports on the progress to the Board of Directors at least once a year or as appropriate.
Thaioil Group Digital Steering Committee holds a meeting to consider matters related to their roles and responsibilities every quarter or as necessary. Also, the Committee reports the progress to the Board of Directors at least once a year or as appropriate.
Cyber Emergency Response Team (CERT)
Cyber Emergency Response Team (CERT) was established in March 2022 to oversee and respond to digital emergencies. The purpose is to promptly recover from emergencies and return to normal system operations while maintaining Thaioil Group’s business continuity and minimizing any negative impacts or losses.
CERT Structure
1. Executive Vice President – Power, New Business and Digitalization as CERT Commander
2. Manager – Legal as Lawyer Team
3. Vice President – Corporate Strategic Risk as Risk, BCM and Insurance Team
4. Manager – Business Continuity Management as Risk, BCM and Insurance Team
5. Manager – Corporate Insurance Management as Risk, BCM and Insurance Team
6. Manager – Security as Physical Security Team
7. Manager – Employee Relation as Information Center Team
8. Manager – Public Affairs Coordination-Brand Management as Information Center Team
9. Manager – Refinery Relation Coordinator – Refinery Public Relation as Information Center Team
10. Manager – Investor Relations as Information Center Team
11. Manager – Domestic Commercial Operations – Petroleum & Petrochemicals as Information Center Team
12. Vice President – Digitalization as Response Management Team
13. Vice President – Engineering as Response Management Team
14. Vice President – Technology as Response Management Team
15. PTT Digital Computer Security Incident Response Team (CSIRT) (Response Team)
Roles and Responsibilities of the CERT Team
The Executive Vice President of Power, New Business, and Digitalization (EVPN) is positioned as the Chief Information Security Officer (CISO) or CERT Commander to oversee the Company’s cybersecurity in accordance with ISO27001 Information security management systems. The roles and responsibilities of CERT are:
1. Formulate management strategies to respond to emergency situations.
2. Develop the emergency management plan and assign the key responsibility for each activity to ensure that all those involved in the plan understand their roles and responsibilities.
3. Monitor and assess the situation to provide recommendations in responding to an emergency situation and returning to normal operations.
4. Report and communicate the emergency situations to relevant parties, including the executives and refineries, while providing information on the incident, action plans, current status, and the impact on the Company’s production or business operations.

Digital Policy
Thaioil Group has announced the digital-related policies as follows:
- The TOP Group Digital Policy is established to govern business operations, provide business direction, adopt the digital technology, and communicate within Thai Oil Public Company Limited and its subsidiaries. The policy aligns with international best practices, the Company’s Enterprise Architecture, and the Data Governance Framework.
- The Cyber Security Policy is established to ensure that the information systems of Thai Oil Public Company Limited and its subsidiaries have prevention and effective cyber risk management.
- Social Networking Policy is established to govern and provide direction on data dissemination, access to social media and electronic services, and opinion expression.
- The Personal Data Protection Policy (PDPA) is established to provide criteria, mechanisms, and measures to manage personal data appropriately. The policy also highlights the right of privacy and personal data protection when conducting transactions with the Company.
- Generative AI Policy is established to define the direction for governance, usage, and development of Gen AI within Thai Oil Public Company Limited and its subsidiaries to ensure alignment with relevant international standards and clarify the effective use of Gen AI. The policy also enhances business competitiveness, promotes innovation, and remains within the boundaries of law and ethical standards of society.
Digital Master Plan 2022 - 2030
The Digital Master Plan has been developed to support business operations with short-, medium-, and long-term frameworks in different aspects, including:
Advanced Business Platform - Strengthen Business Competitiveness
Integrate digital technology throughout the Company’s value chain to support the business strategy, and link to the core work processes through the Value Chain Digital Platform (VCDP) project.
Big Data & Artificial Intelligence (AI) - Developing a Data-Driven and AI-Based Decision-Making Organization
Cyber Resilience - Cybersecurity Readiness
Develop a cybersecurity system based on the Zero Trust principle and establish measures and practices to prepare for potential cyber threats regularly.
Digital Workplace - Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization
Upgrade infrastructure systems ,such as improving the Wi-Fi system for better performance, enhancing the capabilities of laptops, and upgrading the meeting room systems for increased convenience, to facilitate seamless and flexible hybrid work from anywhere.
People - Employee Digital Skills Development
Establish a framework for enhancing digital literacy and skills through various initiatives, including conducting digital skills training for employees and inviting external experts to provide insights on emerging technologies.
Advanced Business Platform - Strengthen Business Competitiveness
Enhance business processes with digital technology in the form of Business Digital Platform to integrate the working process.
Big Data & Artificial Intelligence (AI) - Developing a Data-Driven and AI-Based Decision-Making Organization
Promote and facilitate the adoption of developed AI / Generative AI for wider use (Adoption at Scale)
Cyber Resilience -Cybersecurity Readiness
Examine and adopt new innovative technologies to improve cybersecurity, both in defense and incident response (Automated Defend & Response).
Digital Workplace - Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization
Develop an IT service system as a centralized “One-Stop Service Platform” and providing services with standardized ITSM (IT Service Management).
People - Employee Digital Skills Development
Establish digital proficiency as the foundation and basic qualification for employees at all levels.
Advanced Business Platform - Strengthen Business Competitiveness
Achieve business excellence (Intelligence Business) by adopting digital technology as an automated tool to support every working process.
Big Data & Artificial Intelligence (AI) - Developing a Data-Driven and AI-Based Decision-Making Organization
Seek new business opportunities of the Big Data from organization-managed information.
Cyber Resilience -Cybersecurity Readiness
Consistently develop cybersecurity system to become the leader on cybersecurity in the oil and gas industry.
Digital Workplace - Establishing an Efficient IT Infrastructure and Fostering a Productive Work Environment Within the Organization
Boost productivity and enhance employee well-being by providing and advancing IT and digital infrastructure.
People - Employee Digital Skills Development
Educate employees to continuously pursue digital skills and strive towards “Digital Natives”.
Digital Management Approach
In 2024, Thaioil Group successfully implemented core focus areas as the part of the Company’s digital strategy as follows:

Digital Transformation
Thaioil Group prioritizes the integration of digital technology to enhance business competitiveness. The Company has established a strategic plan and executed various projects related to digital technology. Moreover, the Company monitores the project performance and reviews the plan on a regular basis. This aims to ensure that the adaptation of digital technology is aligned with the business targets during the changing situation. The following are key projects:
Advanced Business Platform
- Comnxt Project : Develop a commercial platform that enhances the Company’s competitive ability by managing customer and partner data, marketing information, and tracking purchase/sale status. This will also enable the Company to identify new potential customers, increase sales opportunities, make informed decisions, and operate efficiently. Additionally, it will create value for the Company while enabling risk management through tools that control data access and track data usage, ensuring the organization’s operations are secure and compliant with regulations.
- Project to Improve the Recording of operational data in the E-Shift Report (Phase II) : Enhance the E-Shift Report project by converting the log sheet into a digital format that can retrieve data from the system for display. This will help reduce the time spent on shift reports and minimize operational errors.
- Sourcing Workspace Project : Develop a strategic procurement management system by gathering data on partners, current and historical market prices, and past and present product demand to systematically analyze the data, leading to strategic procurement management. This enables more agile procurement operations, supports continuous profit growth for the Company, and accommodates the increased procurement volume in the future.
Big Data & AI – Developing a Data-Driven and AI-Based Decision-Making Organization
In 2024, Thai Oil Public Company Limited established a new department named the ‘Digitalization – Data and AI Section’ to drive the use of data within the Company, implement Artificial Intelligence (AI) technology more concretely, and promote use cases within the Company to increase their widespread adoption. The following are key projects:
Projects | Details | Achievement Indicators | Relevant ESG |
Electronic Nose Project | Electronic Nose (E-Nose) Application is the use of AI to monitor, detecting, and notifying the unpleasant odors that arise from the production process and other activities and may affect the employees, contractors, or surrounding communities. The system is active 24 hours a day, allowing the Company to identify the sources of unpleasant odors and manage them appropriately. | Reduce community complaints regarding odor pollution. | Community Relation Occupational Health and Safety |
IK-Q Inspection Project | IK-Q Inspection (Intelligence – Knowledge – Query) is the use of Generative AI developed to assist in searching for international engineering standards, best practices, as well as internal Company databases related to inspection tasks. This can also analyze data and provide preliminary recommendations for engineers. | Reduce work time. | Human Capital Development |
Predictive Maintenance Analytics Project | Expand the scope of the Predictive Maintenance Analytics project to cover more machinery in the production unit. The process will predict the likelihood of damage to the machines and provide preventive measures in advance to reduce the likelihood of chemical spills. This will also help avoid unplanned shutdowns and maintenance, while reducing the risks associated with such damages. | Reduce the likelihood of chemical spills and equipment damage due to lack of prior protection. | Risk Management |

Cybersecurity Management
- Enforcing Multifactor Authentication (MFA) for VPN and email access.
- Installing Endpoint Detection and Response (EDR) anti-virus software on all devices.
- Launching conditional access controls to verify system access and protect the Company’s critical information.
- Implementing the mobile device management for Bring Your Own Device (BYOD) in a secured manner.
- Conducting quarterly employee phishing awareness tests to educate and modify behavior regarding cyber threats to raise awareness of the importance of cybersecurity and foster a consistent mindset of caution against cyber threats.
- Developing the Cyber Emergency Response Procedure consistent with the Company’s overall Emergency Response Plan. This plan is rehearsed at least twice a year, covering information Technology, operational technology, business continuity plan, and communication measures for internal and external stakeholders in an event of cyber emergency.
- Upgrading digital systems and applications affected by obsolescent technology (Application Obsolescence) ensures they are modern and current. This helps prevent cyber risks and threats arising from vulnerabilities in obsolete systems and applications, providing users with confidence in safe and secure usage.
- Mitigating cyber risks for computer systems that operate through the Internet (Attack Surface), including regularly searching for and managing the risks associated with the Attack Surface.
- Increasing cybersecurity services to prevent simultaneous large-scale attacks, ensuring uninterrupted system operations, known as Distributed Denial of Service (DDoS).
Cyber Emergency Response
- Monitor and respond to cyber events and cybersecurity threats, supplementing the external service provider (MDR) through the Security Operating Center (SOC), with continuously monitor and manage cyber risks for 24 hours a day.
- Assess vulnerabilities continuously and ensure that deficiencies are resolved, with the addition of conducting Penetration Tests on an annual basis by external experts.
- Prepare for cyber incidents related to ransomware (Ransomware Assessment) by reviewing processes and the response playbook to ensure they are up-to-date and regularly practiced at least twice a year. Performance outcomes are consistently reported to executives, along with data security and cybersecurity risk management updates provided to the Risk Management Committee.
- Engage external consultants to assess security gaps in accordance with the NIST 2.0 framework and develop an improvement plan to ensure readiness in governance, detection and prevention systems, as well as sustainable processes for addressing cyber threats.

Digital Knowledge and Cybersecurity Awareness Promotion for Employees
- Provide information and knowledge through E-newsletters and public relations to build awareness of the digital systems that integrate new technologies developed for use within the Company. This aims to motivate employees to recognize the benefits of technology and its precautions.
- Conduct awareness training, including employees, executives, and system administrators, to provide knowledge on emerging cybersecurity threats and ensure each group understands the necessary information accurately and appropriately.
- Raise awareness of phishing email threats to new employees through the New Staff Orientation Program and conduct unannounced phishing email tests for employees approximately every three months, and subsequently report the test results to the executives. Employees who do not pass the tests are required to attend additional training on the prevention of phishing email threats.
- Develop online training courses to enhance awareness and provide basic practices related to the Personal Data Protection Act (PDPA). This is a mandatory course, which all employees are required to complete the course and pass the test.
In 2024
Performance
- Zero cases of cyberattacks affecting the business operation
- Zero cases of breaches of information security
- 100% of all IT infrastructure with cyber threats obtained ISO27001 certification, including:
- The Data Center, SAP, and LIMS systems, under the control and management of the Digital Function.
- Advanced Process Control Network, under the control and management of the Technology Process Control Function, which supports service activities and work processes within the Thaioil Group.
- Instrument Network, under the control and management of the Instrument Engineering Functions.
- Telecommunication and ELICS systems, under the control and management of the Electrical Engineering functions.
- 100% cybersecurity awareness training for new employees
- 4 times per year of phishing email exercise for employee
- 84% of internal customer (user) satisfaction