Blog

2026.07.29

OT Security for Manufacturing in Thailand: 2026 Guide

OT Security for Manufacturing in Thailand: 2026 Guide

For multinational and Japanese-affiliated manufacturers running plants in Thailand and the wider ASEAN region, the question of OT security for manufacturing in Thailand has moved from “sometime later” to this year’s budget cycle. In the first quarter of 2026 alone, 1,020 ransomware incidents were observed against industrial organisations, and 62% of them hit manufacturing. This guide is written for plant managers, IT managers and operations directors who need enough detail to make a decision: what separates operational technology from IT, how the IEC 62443 framework is actually used, what Thailand’s Cybersecurity Act and PDPA require, a phased roadmap that survives contact with a running factory, and indicative cost ranges.

Operational Technology vs IT: Why OT/IT Convergence Makes Factory Cybersecurity Different

What “OT” actually covers on a plant floor

Operational technology (OT) is the collective term for the technology that directly controls and monitors physical processes and equipment. In a factory, that means PLCs (programmable logic controllers), DCS (distributed control systems), SCADA supervisory systems, HMIs (operator panels), industrial robot controllers, CNC machine tools, inspection and vision systems, and the industrial networks that tie them together. Utility-side assets belong in the same category: substation and switchgear controls, compressors, chillers, boilers and wastewater treatment panels are all OT in the broad sense.

IT (information technology), by contrast, handles information. ERP, MES front-ends, mail and file servers, office PCs, cloud services — anything whose job is to process, store and transmit data.

Both are “computers and networks”, yet their purpose, design philosophy and operating conventions are entirely different. Factory cybersecurity is hard precisely because the moment you ignore that difference and import one side’s assumptions into the other, the plant floor breaks.

The priority order is inverted

In information security, the classic priority order is CIA: confidentiality, integrity, availability. Prevent data leakage first; a certain amount of downtime is acceptable if the data stays protected.

In OT, that order is essentially reversed: availability first, then integrity, then confidentiality. The reasoning is not ideological. If OT stops, product is not made, delivery dates slip, contracts are breached, and in the worst case equipment or people are harmed. If temperature control on a heat-treatment furnace misbehaves, that is not an information problem, it is a safety problem.

This inversion directly changes which countermeasures make sense. On the IT side, the standard reflex when suspicious traffic appears is to block it. Apply that reflex to OT and you may cut off legitimate process control traffic — in other words, you stop your own line on behalf of the attacker. OT demands a different sequence: observe first, assess the process impact, then act in a planned way.

Legacy equipment is a hard constraint, not an excuse

The second major difference is asset lifecycle. In IT, PCs are refreshed every four to five years and servers every five to seven. OT equipment runs for 15, 20, sometimes 30 years. Injection moulding machines commissioned in the 1990s are still running on main lines in plenty of plants across Thailand’s industrial estates.

The consequences are predictable and near-universal:

  • The operating system is long past end of support, but the OEM does not warrant any newer version, so it cannot be upgraded.
  • Patching requires stopping the equipment, which is only possible during one or two scheduled shutdowns a year.
  • Control software depends on a specific runtime version, making patching technically impossible without re-validation.
  • The maintenance contract voids the warranty if the customer modifies anything.
  • The internals of the machine are a black box, and nobody in the company knows what actually runs inside it.

OT security is therefore not a project to “eliminate vulnerabilities”. It is a design problem: how do you keep operating safely while carrying vulnerabilities you cannot eliminate? That reframing is the single biggest departure from IT security practice.

IT and OT side by side

DimensionITOT
Top priorityConfidentialityAvailability and safety
Asset lifetime4–7 years15–30 years
PatchingContinuous, largely automatedOnly during shutdowns, requires validation
Impact of downtimeDelayed workLost production, equipment damage, safety risk
Asset inventoryGenerally reliable via CMDB and EDROften outdated or non-existent
NetworkingPredominantly TCP/IPMixed industrial protocols
Change managementRelatively flexibleFrequently requires OEM approval
Accountable functionInformation systemsProduction, process engineering, maintenance

The last row matters more than the technical ones. IT and OT sit in different departments, with different reporting lines and different performance metrics. When an IT manager proposes “strengthening security”, the production engineering team is measured on uptime and OEE — and the two sets of incentives collide head-on. OT security programmes far more often stall for organisational reasons than for technical ones. Genuine OT/IT convergence is a governance exercise before it is a network design exercise.

The 2026 Threat Picture: ICS Ransomware by the Numbers

OT Security for Manufacturing in Thailand: 2026 Guide - figure 1

What was observed in Q1 2026

According to *Industrial Ransomware Analysis for the First Quarter of 2026* published by the industrial cybersecurity firm Dragos, 1,020 ransomware incidents hit industrial organisations in Q1 2026. Manufacturing accounted for 633 of them — 62% of the total, by far the largest share.

The sector breakdown within that total:

  • Manufacturing overall: 633 incidents (62%)
  • Construction-related: 152 incidents
  • Industrial equipment: 116 incidents
  • Food and beverage: 57 incidents
  • ICS ecosystem (engineering firms, system integrators, equipment vendors): 139 incidents
  • Transportation and logistics: 87 incidents

By region:

  • North America: 480 incidents
  • Europe: 252 incidents
  • Asia: 137 incidents, up from 113 in Q4 2025
  • South America: 59 incidents
  • Middle East: 54 incidents
  • Africa: 19 incidents
  • Australia and New Zealand: 19 incidents

By threat group, Qilin led with 198 incidents, followed by Akira with 100, The Gentleman with 83, LockBit 5.0 with 71 and PLAY with 53.

The Asian figure deserves attention. Moving from 113 to 137 quarter over quarter, it undermines the still-common assumption that ICS ransomware is a North American and European problem. The absolute number remains far below North America’s 480, but the direction of travel is unambiguous, and Asia is where the readers of this article run their plants.

How heavy a single incident is

For an operations director, incident counts matter less than the weight of a single event. Dragos reports that 25% of manufacturing ransomware incidents resulted in a full shutdown of the OT site, and 75% caused some form of operational disruption. One in four takes the whole plant down; three in four disturb production in some measurable way.

On the financial side, IBM’s *Cost of a Data Breach Report 2024* puts the average cost of a breach in manufacturing at roughly USD 5 million. That figure covers more than recovery: it includes lost business opportunity, customer handling and legal response.

Sophos research from 2025 found that 51% of manufacturers hit by ransomware paid the ransom. Payment guarantees nothing — recovery after payment is frequently partial — and it should not be treated as a strategy. But the fact that a majority pay tells you something important about the economics: for many plants, the cost of standing still exceeds the demand.

An important caveat: OT is rarely being broken directly

There is a persistent misreading in trade press and vendor material that is worth correcting precisely, because it changes where the money should go.

In its Q1 2026 report, Dragos states explicitly that no ransomware variant designed to directly manipulate industrial control protocols or process environments was identified in the quarter.

In other words, most of the production stoppages happening today are not cases of an attacker seizing a PLC and halting the line. They are cases where IT systems were encrypted, the information and instructions needed to produce stopped flowing, and the line therefore stopped. Getting this causal chain right is decisive when you set priorities.

In one sense this is good news. If you do not have to assume, as your primary scenario, a sophisticated adversary manipulating controllers directly, then the first thing to fix is the governance of the boundary between IT and OT — and that is entirely achievable with mature, widely available technology. Conversely, skipping that boundary work and spending the budget on advanced controller-level defences is a misallocation.

How Factories Actually Stop: The Overlooked Pathways

The mechanism by which IT damage halts a line

Plants depend on IT systems far more than most people assume. Laid out concretely, this is what happens:

  • No production plan, no work instructions. If the production management system or MES is down, the day’s schedule and the shop-floor instructions cannot be issued. The equipment may be perfectly healthy, but a line cannot run when nobody knows what to build and in what quantity.
  • Drawings and programs are unreachable. CAD data and NC programs typically live on file servers. Encrypt them and machining cannot begin.
  • Receiving and shipping stop. Without goods-receipt records and shipping documents, you can neither accept parts nor dispatch finished goods. The warehouse physically fills up, and at that point the line has to stop regardless.
  • Quality records cannot be captured. Continuing to manufacture without traceability records means you cannot later determine whether the output is shippable. In regulated industries, the correct decision the moment records stop is to stop production.
  • OT is disconnected as a precaution. When infection is confirmed on the IT side, teams often cut the plant network themselves to prevent spread. That is the right call — and it still means production stops.

That last item is the one most often underestimated. Even when the attacker has not reached OT, plants are shut down because the organisation cannot *prove* the attacker has not reached OT. Turn that around and you get one of the highest-leverage arguments for OT visibility: if you can demonstrate quickly that the control environment is clean, you can materially shorten the outage — even when the incident itself is entirely on the IT side.

In Japan there is a well-known case in which a supplier to a major automaker was infected with ransomware and the parent company’s entire domestic plant network stopped for more than a day. One supplier was infected. None of the automaker’s own production equipment was damaged. Every plant stopped anyway. That is the textbook illustration of IT damage stopping lines — and the same dependency structure exists in every ASEAN supply chain.

Where intrusions actually begin

Verizon’s 2026 Data Breach Investigations Report (DBIR) finds that 38% of manufacturing breaches begin with exploitation of a vulnerability and 61% originate from system intrusion, while social engineering accounts for 17%. Sophos’ 2025 research similarly attributes 32% of manufacturing ransomware to vulnerability exploitation as the initial access vector.

The implication is that security awareness training alone will not close the gap. Phishing defences remain necessary, but vulnerability management on externally exposed assets is where the larger share of risk sits. VPN concentrators, remote desktop gateways, managed file transfer appliances, and remote-maintenance gateways installed at the plant — these are exactly the assets most likely to be missing from a factory’s IT asset register, and they face the internet directly.

Vendor and third-party access: the least visible risk

The largest blind spot in most OT environments is the simple fact that equipment OEMs and maintenance vendors hold remote access.

Ponemon research from 2025 found that 42% of manufacturers experienced a breach via third-party or vendor access, and 54% do not verify a third party’s security before granting access. Verizon’s 2026 DBIR reports that a third party was involved in 61% of manufacturing breaches. Analysis by Cowbell puts the growth of supply chain attacks at 431% compared with 2021.

In practice, this is what it looks like on a plant floor in Thailand:

  • A router and dedicated line were installed for OEM maintenance when the equipment was commissioned ten years ago. It is still live. No contract or configuration record remains in the company.
  • A 4G/5G router was retrofitted to a machine and communicates externally without ever touching the corporate network. The IT department does not know it exists.
  • The vendor engineers share a single account, so there is no log of who connected and when.
  • The remote maintenance tool listens permanently instead of being opened only on request.

None of these were created maliciously. Every one of them exists to restore equipment faster. That is exactly why the plant resists removing them, and why a blanket prohibition simply produces a new workaround. Controlling vendor access is as much a contracting and process problem as a technical one.

The detection and response vacuum

Dragos reports that 88% of OT networks have gaps in detection and response capability. In most plants, nobody and nothing is continuously watching what happens on the OT side. Anomalies are noticed after the line stops, or when an operator remarks that a screen looks wrong.

EDR and SIEM on the IT side, nothing on the OT side: that asymmetry is what turns incidents into prolonged outages. Since no control set prevents intrusion outright, the practical contest is over how quickly you notice and how narrowly you can contain.

Thailand and ASEAN: Cybersecurity Act, NCSA, the CII List and PDPA

For a plant in Thailand, the regulatory centre of gravity is local, not offshore. The following is the part of the compliance landscape that a plant or IT manager in the Kingdom should be able to explain from memory.

The Cybersecurity Act and the NCSA

Thailand has a Cybersecurity Act, under which the National Cyber Security Agency (NCSA) was established. The Act imposes incident reporting obligations and adherence to defined standards on organisations designated as Critical Information Infrastructure (CII).

The reflex response from a manufacturing site — “we are a factory, we are not CII” — is premature, and it is becoming less defensible with each revision of the framework. CII designation follows the function an organisation performs in the national economy, not its industry label.

The September 2025 CII list revision

In September 2025, the National Cyber Security Committee (NCSC) issued a new notification revising the list of CII organisations. It replaces the 2023 classification and expands the scope to reflect the growing technical interdependence between sectors.

For a manufacturer, the practical question is whether any part of the business touches energy, utilities, logistics or public services deeply enough to fall within the expanded scope. Useful questions to put to legal counsel when assessing applicability include:

  • Does the site generate, distribute or feed back electricity or utilities that other parties depend on?
  • Does the site operate logistics or transport functions that other operators rely on?
  • Does the site supply goods or services that public services depend on directly?
  • Have any of these dependencies changed since the 2023 classification was issued?

Applicability should be confirmed through a formal determination with legal counsel rather than settled by internal assumption. Designation carries concrete obligations — incident reporting to the NCSA within defined timeframes, adherence to prescribed standards, and cooperation with the authority during incidents — and the cost of discovering the obligation during an incident is considerably higher than the cost of checking now.

Separately, the 2025 Website Security Standards require SSL/TLS and multi-factor authentication. Externally facing web systems and portals operated by a plant — supplier portals, delivery booking systems, recruitment pages hosted on plant infrastructure — can fall within scope of that requirement.

PDPA: the second, parallel obligation

Alongside the CII regime, Thailand’s Personal Data Protection Act (PDPA, B.E. 2562 / 2019) applies in parallel. When a ransomware incident occurs, the operational problem of stopped production is joined by a data protection problem: if employee, contractor or business partner personal data is affected, a PDPA notification obligation arises.

The practical point is that breach notification and risk management procedures must satisfy both the Personal Data Protection Committee (PDPC) and the NCSA. If your incident response plan does not specify in advance *who* reports *what* to *which* authority and *by when*, the response will fracture under time pressure — and it will do so at exactly the moment when the plant is also fielding calls from the Japanese or European head office, the group communications team and key customers.

A single-page reporting matrix is one of the cheapest and highest-value artefacts you can produce. It should list, at minimum: the trigger condition, the recipient (NCSA, PDPC, head office, insurer, key customers), the deadline, the named owner, the named deputy, and the channel. Draft it before you need it, and rehearse it once a year.

Thailand as a threat environment

Regulation is only half the picture. According to SOCRadar’s *Thailand Threat Landscape Report 2026*, Thailand entered the world’s ten most targeted countries for the first time in early 2026. The same report attributes 42.9% of ransomware incidents observed in Thailand to The Gentleman (Gentlemen) family.

That name should look familiar. The Gentleman also appears in the Dragos Q1 2026 data as one of the leading groups attacking industrial organisations, with 83 incidents. The overlap — the group most active in Thailand is also a group actively targeting industry — is not something a manufacturer with Thai operations can reasonably discount.

The intuition that “head office in Japan or Europe might be a target, but the attackers will not bother with our Thai site” does not survive contact with the data. The more realistic model is the opposite: overseas sites carry thinner security investment and smaller IT headcount than headquarters, which makes them an attractive entry point into the group as a whole. In a group network with flat trust relationships, an overseas plant is not a peripheral asset — it is a door.

Reading the regional picture

Across factory cybersecurity Southeast Asia more broadly, the pattern that matters for a regional manufacturing footprint is uneven regulatory maturity combined with tightly coupled supply chains. A group operating in Thailand, Vietnam, Indonesia and Malaysia faces different national frameworks and different reporting timelines at each site, while the production dependencies between those sites are continuous. Two consequences follow:

  1. Group-level OT security standards should be written to the most demanding site requirement and applied uniformly, with local addenda for national reporting obligations. Maintaining four different technical baselines is unsustainable.
  2. Business continuity analysis has to be done across borders. If a Thai plant supplies sub-assemblies to a Vietnamese plant, an incident at either one propagates, and neither site’s local regulator cares about the other’s schedule.

IEC 62443 Fundamentals: Zones, Conduits, Security Levels and Defence in Depth

OT Security for Manufacturing in Thailand: 2026 Guide - figure 2

Why IEC 62443 is the reference framework

IEC 62443 (ISA/IEC 62443) is the international series of standards covering security for industrial automation and control systems (IACS). Where ISO/IEC 27001 defines the organisational machinery for protecting information, IEC 62443 defines technical and process requirements for protecting control systems — and it does so separately for three roles: the asset owner (the factory), the system integrator, and the product supplier.

As of 2026, the scope explicitly includes IIoT devices and cloud analytics that interoperate with field devices. The modern architecture in which plant data is pushed to the cloud and analysed with AI sits inside the standard’s remit, not outside it.

What matters commercially is that IEC 62443 has become a shared vocabulary rather than a purely technical document. The OT security market is estimated at USD 25 billion in 2026, and IEC 62443 is increasingly referenced in procurement contracts, regulatory requirements and cyber insurance application forms. Independently of whether you pursue certification, the ability to describe your own posture in the standard’s terms is becoming a condition of doing business — particularly for tier-one suppliers to automotive and electronics OEMs.

Zones and conduits: the core construct

The central concept in IEC 62443 is risk-based network segmentation using zones and conduits.

  • Zones are groupings of assets that share common protection requirements. Typical examples: “Building A moulding line control system”, “shared MES server group”, “safety instrumented system”. The grouping criterion is the required level of protection and the associated risk — not physical location.
  • Conduits are governed communication paths between zones. A conduit is not a cable or a circuit; it is a logically defined channel specifying which zone may talk to which other zone, using which protocols, initiated by whom, for what purpose.

Two principles make the design work. First, every conduit carries explicit controls: firewalling, authentication, encryption where appropriate, and logging. Second, no inter-zone communication is permitted outside a defined conduit.

The second principle is the genuinely difficult one. Most plants contain paths that appear on no drawing: two lines that are somehow directly connected, a maintenance laptop with interfaces on both networks, a temporary cable installed during a commissioning crunch three years ago and never removed. Designing zones and conduits is, in large part, the work of finding and closing those back doors.

Security levels SL1 to SL4

IEC 62443 expresses the required standard of protection as security levels 1 through 4. The important design feature is that the levels correspond to attacker motivation and resources, not to a generic notion of “how secure”.

LevelThreat assumedTypical application
SL1Unintentional misuse, accidental eventsGeneral office-adjacent areas
SL2Intentional attack using simple means, limited resourcesTypical production line control systems
SL3Attacker with sophisticated means, specialist knowledge and substantial resourcesCore lines, critical proprietary processes
SL4Well-resourced, highly motivated attacker such as a state-sponsored actorCritical infrastructure, exceptionally critical assets

Setting every zone to SL4 is neither realistic nor consistent with the intent of the standard. The objective is to assess risk per zone and assign the level each zone actually needs. Assigning a high level to a safety instrumented system and a low one to an office-adjacent auxiliary system is not a compromise — that graduated judgement is the practice of IEC 62443.

The most useful output for management is the gap between the current level (SL-Achieved) and the target level (SL-Target). It converts the conversation from “we are worried about security, please approve budget” into “if we set SL2 as the target for the core line, the gap consists of these five items, and closing them costs this much.” That translation is the practical reason to adopt the standard, whether or not you ever seek certification.

Defence in depth

Defence in depth means using the layered architecture created by zones and conduits so that a compromise in one place does not propagate through the whole plant.

Instead of a single strong wall, you stack layers: the perimeter firewall, network segmentation, device-level access control, account management, monitoring and detection, and finally backup and recovery procedures. When any one layer is defeated, the next one buys time.

“Buying time” is the honest description of the goal. No combination of controls can guarantee that intrusion is prevented. What you can influence is the interval between intrusion and material damage, and whether you notice inside that interval. Given that most production stoppages originate as spillover from the IT side, placing one reliable layer at the IT/OT boundary is among the most cost-effective investments available to a manufacturing site.

Japanese Group Standards: A Brief Note

For plants that report into a Japanese parent, two domestic reference documents are worth knowing by name, because they frequently form the basis of group audits even though they carry no legal force in Thailand.

Japan’s Ministry of Economy, Trade and Industry (METI) publishes the *Guidelines for Cyber-Physical Security Measures in Factory Systems*, established in 2022 and currently at Version 1.1. Its founding premise is stated plainly: any factory can be attacked. That is a useful sentence to have in hand when a site argues that it is too small or too unremarkable to be a target — attackers largely scan for exposed, vulnerable surfaces rather than selecting targets by name. In April 2024, METI added a supplementary volume, *Key Points for Advancing Smart Manufacturing*, which addresses how to build security into IoT adoption and data utilisation rather than bolting it on afterwards.

Separately, Japan’s Information-technology Promotion Agency (IPA) publishes an annual *10 Major Security Threats*. In the 2026 edition, ransomware ranks first among threats to organisations for the fourth consecutive year, with supply chain attacks second. The pairing is the point: even a plant with excellent internal security stops when a supplier, a logistics provider or an equipment maintainer stops.

For an ASEAN site, the practical consequence is that head office may assess you against the METI framework while the NCSA assesses you against Thai law. Mapping the two onto a single control set — most conveniently using IEC 62443 as the common structure — avoids maintaining parallel compliance programmes.

A Practical Roadmap: Phase 0 Through Phase 3

With the context established, the question becomes where to start. The governing principle is not to start everything at once. When budget and people are limited, sequence determines success.

Phase 0: Establish ownership and scope (1–2 months)

Settle these before any technical work begins, or the programme will stall later — reliably.

  • Name an owner. Decide who is accountable for OT security. Neither IT alone nor production alone succeeds. A small steering group combining both, ideally with an executive sponsor, is the realistic structure.
  • Define the scope. A programme that targets every plant and every line from day one never finishes. Choose one site, or one line, as a pilot. The selection criterion is a line where downtime is expensive *and* where the stakeholders will cooperate.
  • Estimate the cost of downtime. How many baht does one day of stoppage cost? Without this number, every subsequent investment decision becomes a matter of opinion. A rough figure is sufficient.
  • Review the existing incident response procedure. In most cases an IT procedure exists and an OT procedure does not. Even deciding only one question — who has the authority to disconnect the plant network — measurably changes the first hour of an incident.

Phase 1: Asset visibility (2–4 months)

You cannot protect what you do not know exists. The sole objective of Phase 1 is to establish what is connected to the OT network.

  • Bring the network diagram up to date. The existing drawing is almost certainly divergent from reality.
  • Build an inventory of controllers, HMIs, industrial PCs and network equipment.
  • Record OS and firmware versions and support status for each device.
  • Enumerate every external communication path, including wired, wireless and cellular.
  • Take stock of vendor remote access and tie each connection to a contract.

One rule is absolute here: do not run active scans against equipment in production. The network scanning that is routine in IT can crash or misbehave older controllers. In OT environments, the correct starting point is passive visibility that observes traffic without injecting any.

Asset visibility also pays for itself outside security. A cleaned-up equipment register and clearly identified data acquisition points can be reused directly as the foundation for a production management system for a Thai factory or an IoT equipment monitoring deployment. Where a standalone security budget is hard to secure, positioning visibility as a productivity investment is a common and legitimate approach.

Phase 2: Segmentation and boundary control (3–9 months)

Once visibility exists, segment along IEC 62443 zone and conduit lines.

  • Define the IT/OT boundary first. This is the highest priority. As established above, most stoppages propagate from the IT side. Place a firewall at the boundary and explicitly define which traffic may cross.
  • Add an intermediate DMZ where needed. Systems accessed from both sides — MES, historians, reporting databases — belong between the two, not inside the control network. The objective is to eliminate any configuration in which an IT endpoint communicates directly with control equipment.
  • Segment by line or area. Contain a compromise on one line so it does not reach the whole plant. This does not have to be done everywhere at once; work down from the most critical lines.
  • Control vendor access. Replace permanent connectivity with request-based, time-limited access. Combine named individual accounts, multi-factor authentication, activity logging and session recording according to risk. This has to proceed alongside a contract review, not ahead of it.
  • Re-examine backups. Verify that PLC programs, HMI screen data, equipment configuration parameters and recipe data are actually backed up. Server backups on the IT side are often fine while the control system configuration exists only on one engineer’s laptop. Offline or immutable storage is strongly preferable.

Phase 3: Monitoring, operations and exercises (ongoing)

Once segmentation is in place, the work becomes continuous.

  • Deploy OT-aware monitoring. Use tooling that understands industrial protocols and can flag unusual traffic or the appearance of new devices. Recall that 88% of OT networks have detection and response gaps — for most plants this is the largest single blind spot.
  • Decide who receives the alerts. Detection without a recipient is not detection. Decide whether monitoring is in-house or delivered by an external SOC, and whether coverage is 24/7 or business hours.
  • Run incident response exercises. Tabletop is sufficient. Put the actual responders in a room for one to two hours with a scenario — “infection is confirmed on the IT side at 21:00 on a Friday; what do we do with the plant?” — and the gaps surface quickly.
  • Embed security into change management. Build a checkpoint into the process for installing new equipment, modifying existing equipment, and onboarding new vendors. Without it, the architecture you carefully documented reverts within a few years.
  • Review continuously, not annually. An annual stock-take cannot keep pace with change. Automate detection of asset and configuration change wherever possible.

What It Costs: Indicative Budget Ranges

OT Security for Manufacturing in Thailand: 2026 Guide - figure 3

The figures below are Japanese domestic market rates, as compiled in the AEVUS 2026 cost guide, and they are expressed in Japanese yen. USD equivalents are shown only as a rough orientation, converted at approximately JPY 155 to the dollar; no precise exchange rate is claimed and the figures should not be used for quotation purposes.

Delivered in Thailand or elsewhere in ASEAN, these amounts may come in lower because of labour cost differences. Conversely, if the engagement involves dispatching specialists from Japan, or requires deliverables written in Japanese for head office, the cost moves back toward the Japanese level. Treat everything here as a starting point for scoping, not as a quotation.

CategoryItemJapan domestic rate (JPY)Rough USD equivalent
Risk assessmentDocument review¥500,000 – ¥1,500,000~USD 3,000 – 10,000
Risk assessmentPassive network visibility¥1,500,000 – ¥3,000,000~USD 10,000 – 19,000
Risk assessmentActive on-site assessment¥2,000,000 – ¥5,000,000~USD 13,000 – 32,000
Risk assessmentRed team exercise¥3,000,000 – ¥8,000,000~USD 19,000 – 52,000
Risk assessmentOverall range¥500,000 – ¥5,000,000~USD 3,000 – 32,000
ConsultingPer project¥1,000,000 – ¥5,000,000~USD 6,500 – 32,000
ConsultingAdvisory retainer¥500,000 – ¥1,500,000 / month~USD 3,000 – 10,000 / month
ConsultingEmbedded support¥1,000,000 – ¥2,000,000 / month~USD 6,500 – 13,000 / month
IEC 62443 certificationCSMS (organisational)¥3,000,000 – ¥7,000,000~USD 19,000 – 45,000
IEC 62443 certificationSystem design requirements¥4,000,000 – ¥8,000,000~USD 26,000 – 52,000
IEC 62443 certificationDevelopment process¥5,000,000 – ¥10,000,000~USD 32,000 – 65,000
IEC 62443 certificationAnnual surveillance audit¥1,000,000 – ¥3,000,000 / year~USD 6,500 – 19,000 / year
IEC 62443 certificationFirst-year total¥3,000,000 – ¥15,000,000+~USD 19,000 – 97,000+
Phased budgetSmall manufacturer, year 1¥1,600,000 – ¥3,800,000~USD 10,000 – 25,000
Phased budgetSmall manufacturer, year 2 onward¥5,300,000 – ¥10,600,000 / year~USD 34,000 – 68,000 / year
Phased budgetMid-size, year 1¥19,200,000 – ¥45,400,000~USD 124,000 – 293,000
Phased budgetLarge enterprise, year 1¥100,000,000 – ¥300,000,000+~USD 645,000 – 1,940,000+

Reading the assessment figures

Assessment work must not affect production equipment that is running, and avoiding that requires specialist knowledge. That constraint is a large part of why OT assessment prices sit above conventional IT penetration testing. If a quotation comes in materially below these ranges, verify specifically that the provider has delivered assessments in live OT environments — not merely in IT environments belonging to manufacturers.

Reading the consulting figures

Typical deliverables at these price points are security policy documentation, segmentation design, and an incident response plan. For a first engagement at a single site, a per-project arrangement is usually more appropriate than a retainer; retainers become worthwhile once there is an internal owner who needs regular guidance.

Reading the certification figures

Certification is something to pursue when there is an explicit customer requirement or regulatory driver. Approaching it in the reverse order — “we want better security, so let us get certified” — often produces disproportionate cost relative to the risk actually reduced on the plant floor. Using the standard as a design yardstick costs nothing in certification fees; make the certification decision when it becomes a commercial requirement.

Reading the phased budget

The small-manufacturer year-one range of ¥1.6–3.8 million (roughly USD 10,000–25,000) is lower than most executives expect. At that level, scope is confined to the fundamentals: assessment, network segmentation and training. The step up to ¥5.3–10.6 million per year from year two reflects the addition of SOC monitoring, which is a continuing service with a human cost attached.

The cleanest way to frame the investment decision is to compare these numbers with the cost of one day of downtime calculated in Phase 0. Set that against the two figures established earlier — 25% of manufacturing ransomware incidents result in a full OT site shutdown, and the average manufacturing breach costs approximately USD 5 million — and each plant can reach its own conclusion about whether a first-year investment in this range is proportionate.

Common Failure Patterns in OT Security Projects

The following failures recur across projects. Every one of them is avoidable simply by knowing about it in advance.

Importing IT practice wholesale into OT

The most common failure by a wide margin. IT leads the initiative, installs the same endpoint protection used on office PCs onto control PCs, enrols them in the same patch distribution system, and pushes the same asset management agent. The results are predictable: OEM warranties void, real-time performance degraded to the point that control becomes erratic, and equipment that will not boot after a patch cycle.

In OT, every change sits under the constraint of OEM operational warranty. The first question is not whether a change is technically possible, but whether it is contractually permitted.

Active scanning of running equipment

Equally typical. Someone runs a scanning tool to enumerate network assets, an older PLC cannot handle the traffic, and it stops. What was intended as an assessment becomes a self-inflicted incident.

Start OT visibility with passive traffic observation. Where active verification is genuinely required, align it with a planned shutdown or validate it on a test bench first, then execute it in a limited scope with OEM approval.

Stopping at an annual stock-take

A consultant is engaged once, and a handsome report and network diagram are produced. A year later, new equipment has arrived, vendors have been added, temporary connections have been made, and the diagram no longer matches reality.

Asset management has to be a process, not an event. Continuous automated discovery is ideal; where that is not feasible, a simple business rule — that any equipment installation or modification requires notification to the information systems function — makes a substantial difference on its own. Whether the rule is followed depends almost entirely on how little effort the notification takes, so keep the form minimal.

Leaving vendor maintenance lines untouched

The conversation that ends with “what is that router?” / “it has always been there”. As long as external connections nobody manages remain in place, hardening the interior yields limited benefit.

The sequence is: enumerate, reconcile against contracts, remove what is unnecessary, and bring what is necessary back under control. Because unilateral disconnection is usually impossible without damaging the vendor relationship, frame the change as “making it safe without reducing maintenance quality”. Timing the discussion to coincide with contract renewal is effective.

Pursuing perfection and shipping nothing

A plan is drafted covering every plant in the group, deliberation continues for two years, and nothing is implemented in the meantime.

OT security has no 100% state. One line segmented, or one firewall installed at the IT/OT boundary, is a definite improvement. Running one pilot, learning from it, and replicating it across sites is in practice the faster route.

Excluding the plant floor from the decision

IT and executives decide, then hand the outcome down to operations. This approach reliably generates resistance, because the plant floor is measured on uptime and delivery, and security measures arrive framed as an obstacle to both.

What works is connecting each control to a benefit the plant floor recognises. Segmentation speeds up fault isolation. Asset visibility improves maintenance planning accuracy. Controlled remote access creates a record of who did what, which protects the operators as much as it constrains them. Explain the programme in the language of operations rather than the language of security.

Backups that exist but cannot be restored

The pattern where confirming that backups exist is mistaken for confirming that recovery is possible. In reality the restoration procedure is undocumented, the person who knew it has left, a restore test has never been performed, or the backup itself sits on the network and is encrypted alongside everything else.

At minimum, perform an actual restore test once a year. Control system programs and parameters are the highest-risk area, because it is common for exactly one person to know how to put them back.

Reconciling Smart Manufacturing and IIoT with OT Security

DX and security are not in conflict

A frequent objection runs: tighten security and IoT and digital transformation will grind to a halt. In practice the opposite is closer to the truth.

The most common obstacle in Thai manufacturing DX projects is not a security requirement. It is that nobody knows how the equipment is configured, nobody knows where to extract data from, and ad-hoc connections have multiplied to the point of incoherence. Phase 1 asset visibility and Phase 2 segmentation are precisely the work of resolving that disorder.

Any IoT equipment monitoring deployment requires deciding which device, over which protocol, along which path, will supply the data. That is very nearly the same exercise as designing zones and conduits under IEC 62443. An architecture organised for security becomes, without further work, the foundation for data utilisation.

The same applies to factory automation in Thailand. The further automation and equipment integration progress, the more devices join the network and the more external communication occurs. Expanding without a plan multiplies the cost of retrofitting segmentation later. Expanding along an existing zone design adds very little incremental cost.

The reasoning behind METI’s April 2024 supplementary volume, *Key Points for Advancing Smart Manufacturing*, is exactly this: treat smart manufacturing and security as one design activity rather than two projects.

Principles for introducing new technology

Increasingly, plant data is being connected to external services and cloud platforms — for example in AI agent deployments in manufacturing. The fact that IEC 62443’s scope as of 2026 explicitly includes IIoT and cloud analytics reflects the same trend.

Four principles keep this manageable:

  • Make data flow outbound by default. Design for extraction from OT. Any path that returns control commands from an external system into OT should be justified rigorously and placed under independent controls.
  • Always interpose an intermediate layer. Avoid architectures in which cloud or IT systems communicate directly with control equipment. Place a data collection gateway or DMZ in between.
  • Assign the zone at design time. Decide which zone a new device or service belongs to when it is introduced. Deferred decisions do not get made.
  • Design accounts and logging alongside function. Determine who can access what, and what is recorded, at the same time as the functional requirements. Retrofitting after go-live is difficult and expensive.

Build these four into the requirements from the start and you can hold the pace of DX while containing risk. Projects that defer them typically get flagged during a post-implementation audit or a group head office review, and end up being rebuilt.

Frequently Asked Questions

What is OT security in manufacturing, and how does it differ from IT security?

OT (operational technology) security is the practice of protecting production equipment and control systems — PLCs, SCADA, HMIs, industrial robots, instrumentation and the networks connecting them — from cyberattack and unauthorised manipulation.

Where IT security places the highest priority on protecting information, OT security places it on continuity of operations and safety. In addition, equipment lifetimes of 15 to 30 years mean that patching and rebooting cannot be performed at will, so IT methods cannot be transplanted unchanged. That constraint is what makes OT/IT convergence a design discipline rather than a tooling decision.

Does OT security for manufacturing in Thailand fall under the Cybersecurity Act?

It requires a formal applicability check rather than an assumption. Thailand has a Cybersecurity Act under which the NCSA imposes incident reporting and standards compliance obligations on Critical Information Infrastructure (CII) operators. In September 2025 the National Cyber Security Committee issued a new notification revising the CII organisation list, replacing the 2023 classification and expanding the scope. If your operations touch energy, utilities, logistics or public services, re-check whether you now fall within scope.

Separately from the CII regime, the PDPA (Personal Data Protection Act B.E. 2562 / 2019) applies in parallel. If a breach occurs, notification and risk management procedures must be consistent with both PDPC and NCSA requirements, so the recipients and deadlines should be set out in advance within the incident response plan.

If our IT department already has security controls, do we still need OT security measures?

Yes, although IT controls are correctly understood as the foundation. Dragos’ Q1 2026 report states that no ransomware variant designed to directly manipulate industrial control protocols or process environments was identified, and most production stoppages occur as spillover from damage to IT systems. IT controls therefore do protect the plant.

However, hardening only the IT side leaves paths the IT department does not know about: OEM maintenance lines, retrofitted cellular routers, engineering laptops with dual connectivity. And without visibility on the OT side, you cannot demonstrate that the control environment is uncontaminated during an incident, which forces a precautionary production shutdown. Boundary control at the IT/OT interface and OT-side visibility are both required in addition to IT controls.

How much does IEC 62443 certification cost, and is it necessary?

At Japanese domestic rates, first-year cost is indicatively ¥3 million to over ¥15 million (roughly USD 19,000 to over 97,000 at approximately JPY 155 per USD). The components are CSMS at the organisational level (¥3–7 million), system design requirements (¥4–8 million), development process (¥5–10 million), and annual surveillance audits (¥1–3 million per year). Delivery in a market with different labour costs, such as Thailand, may come in lower.

For most plants, though, certification is not the first requirement. Using the IEC 62443 concepts — zones and conduits, and target security levels — as a design yardstick incurs no certification cost at all. Pursue certification when a customer requirement or regulatory obligation makes it explicit.

Where should we start with ICS ransomware protection at a factory?

Take these three steps in order:

  1. Estimate the cost of downtime. Establish what one day of stopped production costs. It becomes the reference point for every subsequent investment decision.
  2. Establish what is connected to the OT network. In particular, enumerate every external communication path — vendor maintenance lines, cellular routers, wireless links. Do not run active scans against equipment in production.
  3. Separate IT from OT. Place controls at the boundary so that damage on the IT side does not propagate. At the same time, back up control system programs and parameters, and run a restore test.

Advanced detection tooling can wait until these three are complete.

We have a lot of old equipment and cannot patch it. What are the options?

Designing on the assumption that patching is impossible is the basic posture of OT security, not a failure state.

Concretely, isolate unpatchable devices into a dedicated zone and tightly restrict the conduits into that zone. This is known as compensating control: instead of removing the vulnerability, you remove reachability to it. In parallel, ensure reliable backups of the device’s configuration and programs so that recovery can be completed quickly if necessary.

Where an equipment replacement plan already exists, the most effective step is to write security requirements into the procurement specification at that point. Specifying requirements at purchase is dramatically cheaper than retrofitting them onto installed equipment.

Can factory cybersecurity in Southeast Asia coexist with DX and IoT equipment monitoring?

Yes, and the two are complementary in sequence. Deploying IoT equipment monitoring requires deciding which devices supply data over which protocols — very nearly the same work as designing IEC 62443 zones and conduits. The asset register and network architecture produced for security purposes serve directly as the foundation for data utilisation. METI’s April 2024 supplementary volume points in the same direction, recommending that security be built in at the design stage of smart manufacturing.

The caution is about order. Adding IoT devices without a plan and re-segmenting afterwards multiplies cost. Fix the zone design before you expand.

Is an OT security programme realistic for a small or mid-sized plant?

Yes. At Japanese domestic rates, first-year budget for a small manufacturer is indicatively ¥1.6–3.8 million (roughly USD 10,000–25,000) covering assessment, network segmentation and training, rising to ¥5.3–10.6 million per year from year two once SOC monitoring is added. Delivery in Thailand may come in lower because of labour cost differences.

Smaller scale also carries genuine advantages. Fewer devices means asset discovery finishes sooner, and a flatter decision hierarchy means consensus with the plant floor is reached faster. As METI’s guidelines state, any factory can be attacked — being small is not a reason to be spared. Start with a pilot on a single line.

How should a regional group handle OT/IT convergence across multiple ASEAN sites?

Write one group technical baseline to the most demanding site requirement and apply it uniformly, then attach local addenda covering national reporting obligations — NCSA and PDPC in Thailand, and their equivalents elsewhere. Maintaining separate technical standards per country becomes unmanageable quickly. Business continuity analysis should also be performed across borders, because production dependencies between sites do not respect the boundaries of any single regulator.

Key Takeaways

  • OT and IT differ in purpose and in constraints. OT prioritises availability and safety, equipment lifetimes are long, and patching is not freely available. Transplanting IT practice unchanged breaks the plant floor.
  • The threat is quantified, not hypothetical. 1,020 ransomware incidents against industrial organisations in Q1 2026, 633 of them (62%) in manufacturing. Asia rose from 113 incidents in the previous quarter to 137.
  • But OT is not usually being broken directly. No variant designed to manipulate industrial control protocols was identified in the quarter; stoppages occur as spillover from IT-side damage. Governance of the IT/OT boundary is therefore the highest-return control.
  • Vendor and third-party access is the biggest blind spot. 42% of manufacturers have experienced a breach via third-party access, and 54% do not verify third-party security before granting it.
  • IEC 62443 works as a design yardstick. Zones and conduits for segmentation, SL1–SL4 for graduated targets, defence in depth for containment. Decide on certification when a commercial requirement appears.
  • Thai regulation is the operative regime for a Thai plant. The Cybersecurity Act and the NCSA, the CII list revised in September 2025, the 2025 Website Security Standards, and PDPA obligations running in parallel. Japanese group standards — METI’s guidelines Version 1.1 and its 2024 supplement, IPA’s 2026 threat ranking with ransomware first for the fourth year — sit on top as internal control expectations.
  • Sequence determines the outcome. Ownership and scope, asset visibility, segmentation, then monitoring and operations — starting with a single-line pilot.
  • None of this conflicts with DX. Asset visibility and network cleanup are the foundation for IoT equipment monitoring and smart manufacturing.

No set of controls can guarantee that a cyberattack is fully prevented. The achievable objective is a plant where an intrusion is contained within one zone, noticed quickly, and recovered from reliably — and that state is built incrementally rather than in one procurement cycle.

TOMAS TECH CO., LTD. is a Bangkok-based IT integrator serving manufacturers in Thailand and ASEAN, providing the PEGASUS production management system and energy management systems. If you would like to discuss mapping your current plant network or designing IoT equipment monitoring, we are happy to talk.

References