Cyber Security Incident Response and Data Breach Plan Exercise

14 July 2026
Corporate Communication and Alumni Relations Center (CCARC)

On July 14, 2026, Associate Professor Prasert Rerkkriangkrai, Vice President of Chiang Mai University, presided over the opening of the "Cybersecurity Incident Response and Data Breach Plan" workshop at the Ruenkhum Meeting Room, Khum Phucome Hotel. Attended by CMU administrators and staff, the workshop aligns with the university’s policy requiring all sectors to implement and practice their incident response plans. This mandate follows the CMU Announcement on Policy and Guidelines on Cybersecurity Protection B.E. 2567 (2024), with ITSC serving as the primary agency supporting the establishment of sectoral response teams. Under this policy, each sector must establish a dedicated task force or Computer Incident Response Team (CIRT) to promptly assess and contain incidents. The workshop utilized tabletop exercises and simulations, including data breaches, ransomware attacks, and account hijackings, to test readiness in executive decision-making, internal communication, and leadership coordination. Furthermore, to ensure compliance with the Personal Data Protection Act (PDPA), the responsible sector must take immediate action upon discovering a data breach. This includes notifying the Office of the Personal Data Protection Committee (PDPC) within 72 hours of becoming aware of the incident, as well as promptly informing the affected data subjects. Following any exercise or actual incident, a post-incident review must be conducted to identify the root cause, a comprehensive report made, and action taken to enhance protective measures for stronger future security.

Gallery