Security Standard
• ISO 27001
It is the sign of your commitment to managing information safely and securely. Our consulting team specialises helping you implement and maintain your Information Security Management. A robust approach to manage the organisation's InfoSec is essential to build cyber resilience, and the team of experienced consultants can play a key role to establish the InfoSec foundation to the organisation. We could be your answer.
• CIS: Critical Security Controls
CIS Controls are a concisely recommended set of actions for cyber defense to implement and apply specific and actionable ways to stop today's most common, pervasive and dangerous attacks. CIS Controls are developed by a community of IT experts who apply their first-hand experience as cyber defenders to create these globally accepted security best practices. Your organizations can take CIS Controls to assess and improve the current security state. Our Incognito Lab Consulting Team could help you apply CIS Controls to your organisation in a prioritised approach.
Managed Security Services
In Thailand, many organisations are making significant investments in technology and outsourced services to transform their businesses. However, several projects were often ineffective because IT teams are consumed with the demands and complexities of ongoing operations along with unclear executive's decision. As IT leaders need to tackle this issue and focus their scarce resource the operations, performance, reliability and security. These are tough responsibility. You could leverage our security experts to select and manage your projects including:
- • Infrastructure improvement
- • Deploy security solutions
- • Improve IT operations
- • IT supports
With our vendor-neutral decision to choose experienced SI blended with our cyber security consultants, you can make a decision with us. Incognito Lab team are here to help.
Good security advice is grounded in how attackers actually work, not in a compliance checklist filled out from a distance. Because our consultants come from the same team that runs penetration tests and red team engagements, the roadmaps we build are shaped by what we have seen break in the field. We help organisations identify their security gaps, address the pain points, adopt the right practices, and drive real security transformation — turning a stack of findings into a prioritised plan that a team can actually deliver. We act as a vendor-neutral advisor alongside your internal teams, not a report generator that hands over a document and disappears.
Security Standards & Frameworks
We help organisations reach and maintain the standards their customers, regulators, and partners expect — from gap assessment through implementation to audit readiness. Certification itself is issued by an accredited certification body; our role is advisory and implementation support that gets you ready to pass. We hold ISO/IEC 27001 ourselves — certified across our own consulting, testing, and training services — so the guidance comes from a team that has sat on the other side of the audit.
Information security & governance
- ISO/IEC 27001 — the certifiable standard for an Information Security Management System (ISMS). We help you build, document, and maintain the ISMS that most other standards on this list extend.
IT service & business continuity
- ISO/IEC 20000-1 — the IT Service Management System (SMS) standard, aligned with ITIL practice. For teams that need service delivery to be formal, measurable, and auditable.
- ISO 22301 — the Business Continuity Management System (BCMS) standard. We help you run the business impact analysis and build the plans that keep operations running through a disruption — the kind of preparation the 2025 earthquake made concrete for many Thai businesses.
Privacy
- ISO/IEC 27701 — the Privacy Information Management System (PIMS), an extension of ISO 27001 (which must be in place first). Covers both controller and processor roles.
- ISO/IEC 27018 — a code of practice for protecting personal data (PII) when you act as a processor in a public cloud.
Cloud
- ISO/IEC 27017 — a code of practice for cloud-specific security controls. Adopted within your ISO 27001 ISMS rather than certified on its own.
- CSA STAR — the Cloud Security Alliance assurance program built on the Cloud Controls Matrix (CCM). Level 1 is a self-assessment; Level 2 is a third-party certification that leverages ISO 27001.
AI
- ISO/IEC 42001 — the first international AI Management System (AIMS) standard, published in 2023. For organisations that develop or use AI and need governance, risk, and lifecycle controls around it.
Control frameworks
- CIS Critical Security Controls — a prioritised, globally accepted set of defensive actions that stop the most common and damaging attacks first.
- NIST CSF — a risk-based framework for organising and maturing a security programme across identify, protect, detect, respond, and recover.
Note: ISO/IEC 27017 and ISO/IEC 27018 are codes of practice implemented within an ISO 27001 ISMS, not certifications awarded on their own.
Regulatory compliance (Thailand)
Thai organisations answer to sector regulators as well as international standards, and most of those regulators mandate exactly the security testing and governance our team already performs. We map your obligations to a concrete plan — and where a regulator requires a penetration test, vulnerability assessment, or source code review, our own testing team does the work and produces evidence in the form your regulator and auditor expect. We advise and prepare you; we are not the regulator, and we are not your auditor.
- Bank of Thailand (BOT) — For financial institutions, the BOT's IT-risk and cyber-resilience requirements call for a secure development lifecycle: a vulnerability assessment before a system goes live and after any significant change, penetration testing of systems connected to external networks, and source code review for critical systems — including Internet Banking and Mobile Banking. We deliver those assessments and help you evidence them.
- SEC (ก.ล.ต.) — The Securities and Exchange Commission's IT governance notification requires an independent penetration test of critical systems connected to untrusted networks — at least once every three years for the highest-criticality systems and on a longer cycle for others — plus a vulnerability assessment of critical systems at least once a year. We perform the independent testing and prepare the report you file.
- OIC (คปภ.) — We help insurers meet the Office of Insurance Commission's IT security and governance expectations, aligning your controls and testing evidence to what the sector requires.
- SET — For listed companies, we align your security programme and testing cadence to the Stock Exchange of Thailand's IT governance expectations.
- NCSA & the Cybersecurity Act — For organisations designated as Critical Information Infrastructure (CII) under Thailand's Cybersecurity Act (B.E. 2562), we support the risk-assessment, testing, and incident-readiness obligations overseen by the National Cyber Security Agency.
- PDPA — Thailand's Personal Data Protection Act (B.E. 2562) is a governance obligation as much as a legal one. We align your privacy controls to it, and pair it with ISO/IEC 27701 when you want a certifiable privacy management system on top.
Exactly which of these bind you depends on your sector and how a regulator classifies your organisation. We confirm the ones that actually apply during scoping, so the roadmap targets real obligations rather than a generic checklist.
Managed Security Services
Leverage security experts to select and manage projects with a vendor-neutral approach:
- Infrastructure improvement
- Deploy security solutions
- Improve IT operations
- IT support
We operate along with your internal teams as a trusted advisor, benefiting from knowledge gained over many client engagements and trusted IS partners.
How we work
Every consulting engagement follows the same five-step process, so advice turns into action rather than sitting in a document.
- Scoping — We agree on what the engagement needs to achieve: a specific certification, a broad maturity uplift, or help with a particular pain point. The proposal states the objectives, the deliverables, and the timeline — no open-ended retainer that never resolves.
- Gap assessment — We measure your current state against the relevant framework — ISO 27001, the CIS Controls, or both — through document review, interviews, and hands-on inspection. The output is an honest picture of where you stand today, not a generic maturity score.
- Roadmap — We translate the gaps into a prioritised roadmap: what to fix first, what can wait, and what each step costs in effort. Priorities are weighted by real risk, drawing on what our testing team sees attackers exploit — so quick wins and structural changes are both accounted for.
- Execution support — We work alongside your internal teams to deliver the roadmap: refining policy, selecting and deploying solutions with a vendor-neutral eye, and improving IT operations. You get a trusted advisor in the room, not a document handed over at the door.
- Review & advisory cadence — We reassess progress against the roadmap on an agreed cadence, adjust priorities as your environment and threats change, and keep the programme moving. The engagement is a working relationship, not a one-off deliverable.
What you get
Consulting is delivered as a practical programme, not a shelf-ware binder:
- Gap assessment report — an honest, framework-mapped picture of where your security stands today, written so both leadership and practitioners can use it.
- Prioritised roadmap — a sequenced plan of what to fix and when, with each item weighted by real risk and scoped for effort, so your team knows exactly where to start.
- Policy & documentation support — practical help building the policies, standards, and evidence an ISMS or a control framework requires — tailored to your organisation, not copied from a template.
- Advisory cadence — regular check-ins to track progress, adjust priorities, and keep momentum, so the programme does not stall after the report is delivered.
- Vendor-neutral guidance — recommendations on solutions and improvements made in your interest, drawing on many client engagements and trusted IS partners, with no product to sell you.
Team credentials
Advice is delivered by our in-house team holding industry certifications including OSCP, OSCE, CREST CRT, CREST CPSA, and GIAC GREM — credentials earned through rigorous, hands-on examination. The same team presents its research at international venues and has served 180+ clients across finance, enterprise, and critical sectors. That offensive background is what keeps our consulting grounded: we recommend controls because we have seen what happens when they are missing, not because a framework lists them. See the full list of certifications the team holds.
Standards & compliance
Our consulting work is built around globally recognised standards — ISO/IEC 27001 for information security, ISO/IEC 20000-1 for IT service management, ISO 22301 for business continuity, ISO/IEC 27701, 27017, and 27018 for privacy and cloud, ISO/IEC 42001 for AI governance, and control frameworks like the CIS Critical Security Controls and NIST CSF. We map your current state and your roadmap to the standards that matter to you, so progress is measurable and auditable, and so you can demonstrate to auditors and partners exactly where you stand. Certification is issued by an accredited body; we get you audit-ready. If your programme needs evidence in a specific format, tell us during scoping — aligning the deliverables costs nothing at that stage.
Consulting works best paired with hands-on validation. A penetration test confirms that the controls on your roadmap actually hold, and a red team engagement tests whether your people and process respond the way the plan assumes they will.
Last reviewed: 11 Jul 2026
Book a scoping callFrequently asked questions
How is your consulting different from a typical advisory firm?
Our consultants come from the same team that runs penetration tests and red team engagements, so the roadmaps we build are shaped by what we have seen break in the field — not a compliance checklist filled out from a distance. We act as a vendor-neutral advisor alongside your internal teams, not a report generator that hands over a document and disappears.
Which standards and frameworks do you help us achieve?
ISO/IEC 27001 (ISMS), ISO/IEC 20000-1 (IT service management), ISO 22301 (business continuity), the ISO 27701/27017/27018 privacy and cloud family, ISO/IEC 42001 (AI management), and control frameworks like the CIS Critical Security Controls and NIST CSF. We hold ISO/IEC 27001 ourselves. Certification is issued by an accredited body; our role is advisory and implementation support that gets you audit-ready.
Can you help us meet Thai regulatory requirements such as BOT, SEC, and PDPA?
Yes. We map your obligations under regulators such as the Bank of Thailand, SEC, OIC, SET, and the Cybersecurity Act, plus PDPA, to a concrete plan — and where a regulator requires a penetration test, vulnerability assessment, or source code review, our own testing team does the work and produces evidence in the form your regulator and auditor expect. We advise and prepare you; we are not the regulator, and we are not your auditor.
Do you sell security products?
No. Our guidance is vendor-neutral — recommendations on solutions and improvements made in your interest, drawing on many client engagements and trusted IS partners, with no product to sell you. Through Managed Security Services we can also help you select and manage projects on that same vendor-neutral basis.
What does a consulting engagement actually deliver?
A practical programme, not shelf-ware: a framework-mapped gap assessment, a prioritised roadmap weighted by real risk, policy and documentation support, and a regular advisory cadence so the programme does not stall after the report. Every engagement follows the same five steps — scoping, gap assessment, roadmap, execution support, and a review cadence.
OPERATE ALONG WITH YOUR INTERNAL TEAMS AS A TRUSTED ADVISOR
Benefit from knowledge gained over many client engagements, trusted IS partners, and our technical experts, we are certain that we, together, could overcome obstacles and achieve what your team and your management need.
Need more info? Let us know how we can help.

