STH Security Blog and Insights
Security Blog and Research
Technical analyses, regulatory summaries, and offensive security methodologies to help engineering teams, CISOs, and auditors build resilient systems.
-
Penetration Testing Requirements under Bank of Thailand Regulations
Summary of BOT circulars and guidelines on threat-led penetration testing (iPentest), mobile banking security, and e-money systems.
-
Thailand Cybersecurity Act 2019 and Critical Information Infrastructure
Duties of CII operators under Thailand's Cybersecurity Act and recommended penetration testing practices.
-
Google SAIF: Six Core Principles for Securing AI Systems
A breakdown of Google's Secure AI Framework and practical steps to defend models, training data, and agent integrations.
-
Does ISO/IEC 27001:2022 Require Penetration Testing?
Analyzing Control A.8.8 (Management of technical vulnerabilities) and how independent penetration tests validate ISMS effectiveness.
-
What ISO/IEC 42001:2023 Means and How AI Pentesting Proves AIMS Readiness
An in-depth breakdown of ISO/IEC 42001:2023 for AI management systems and how offensive testing provides verifiable evidence for executive oversight and audits.
-
Understanding MITRE ATLAS for AI Red Teaming and Threat Modeling
Explore the 16 tactics of the MITRE ATLAS matrix to plan systematic adversary simulations across Generative AI, RAG pipelines, and agentic workflows.
-
Enterprise ATT&CK v19.2: Adversary Tactics and Offensive Security Testing
Navigating the 14 tactics of Enterprise ATT&CK v19.2 to design objective-driven offensive tests and evaluate detection coverage.
-
NCSA Government Cloud Security Standard and Testing Guidance
National cloud security guidelines in Thailand and technical testing methodologies for public and private cloud environments.
-
NCSA Website Security Standard 2025 and Testing Requirements
Overview of the National Cyber Security Agency's standard for government and critical infrastructure websites in Thailand.
-
NIST AI RMF Explained: Risk Management and Technical Assurance
How the NIST AI Risk Management Framework connects organizational governance with empirical AI security testing.
-
OWASP Top 10 for Agentic Applications:2026 and Agent Security
Analyzing security risks in autonomous AI agents, tool invocation, memory poisoning, and Model Context Protocol integrations.
-
OWASP API Security Top 10:2023 and Practical Mitigation
Key vulnerabilities in modern API architectures including BOLA, broken authentication, and excessive data exposure.
-
OWASP Top 10 for LLM Applications:2026 Security Guide
Comprehensive guide to securing LLM applications against prompt injection, model theft, sensitive data exposure, and supply-chain vulnerabilities.
-
OWASP Mobile Top 10:2024 for iOS and Android Security
Essential mobile application security guidelines covering credential storage, network communications, and client-side code hardening.
-
OWASP Top 10:2025 for Web Applications and Pentesting Guidelines
Detailed review of the 2025 web security risks, including broken access control, cryptographic failures, and injection attacks with mitigating controls.
-
PCI DSS v4.0.1 Penetration Testing and Network Segmentation Guidance
Explaining Requirement 11.4 penetration testing mandates, segmentation verification, and vulnerability management under PCI DSS v4.0.1.
-
Does Thailand's PDPA Require Penetration Testing?
Navigating personal data protection security measures under the PDPA and demonstrating appropriate technical controls through offensive testing.
-
Thai SEC Security Testing Requirements for Securities and Digital Assets
Regulatory testing requirements and IT risk management circulars from the Securities and Exchange Commission of Thailand.