# Siam Thanat Hack (STH) > Siam Thanat Hack Co., Ltd. (บริษัท สยามถนัดแฮก จำกัด) is a Bangkok-based offensive > security company providing expert-led, AI-augmented penetration testing (Pentest), > VA scanning, and Red Team services for Web, Mobile, API, and Network systems. > Certified to ISO/IEC 27001:2022 and ISO 9001:2015. Incorporated 11 December 2018. > Contact: pentest@sth.sh ## Main pages - [Thai homepage](https://sth.sh/th/): บริการการทดสอบเจาะระบบ (Pentest) โดยทีม White Hat สัญชาติไทย - [English homepage](https://sth.sh/en/): Penetration testing and cybersecurity services in Thailand ## Regulations & standards guides (Thai regulators and international standards) - [Overview of all requirements](https://sth.sh/th/compliance/): มาตรฐานและข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing - [Bank of Thailand](https://sth.sh/th/compliance/bank-of-thailand/): BOT penetration testing guideline, iPentest, VA requirements, Mobile Banking security, and e-Money - [Thai SEC](https://sth.sh/th/compliance/sec/): Securities and digital asset business penetration testing requirements - [PCI DSS](https://sth.sh/th/compliance/pci-dss/): PCI DSS v4.0 penetration testing requirements - [NDID](https://sth.sh/th/compliance/ndid/): Penetration testing requirements for NDID members - [OIC](https://sth.sh/th/compliance/oic/): Thai insurance regulator IT requirements - [PDPA](https://sth.sh/th/compliance/pdpa/): Thailand Personal Data Protection Act and security testing - [Cybersecurity Act](https://sth.sh/th/compliance/cybersecurity-act/): Thailand Cybersecurity Act B.E. 2562 (2019) - [NCSA Website Security Standard](https://sth.sh/th/compliance/ncsa-website-standard/): Thai national website security standard B.E. 2568 (2025) - [NCSA AI Security Guidelines](https://sth.sh/th/compliance/ncsa-ai-security-guidelines/): Thai guidance for secure AI lifecycle, governance, risk, and evidence - [NCSA Cloud Security Standard B.E. 2567](https://sth.sh/th/compliance/ncsa-cloud-security-standard/): Thailand National Cloud Security Framework scope, shared responsibilities, controls, and reporting - [NCSA Zero Trust Guidelines](https://sth.sh/th/compliance/ncsa-zero-trust-guidelines/): Thailand NCSA Zero Trust Architecture 5 pillars, migration roadmap, and control points - [NCSA Post-Quantum Readiness](https://sth.sh/th/compliance/ncsa-post-quantum-readiness/): Guidelines for PQC crypto asset inventory, harvest-now-decrypt-later risk, and hybrid PQC transition - [BOT ATM Malware Guideline](https://sth.sh/th/compliance/bot-atm-malware-guideline/): Bank of Thailand ATM and kiosk security requirements, application whitelisting, and hardware pentest - [ISO/IEC 27001:2022](https://sth.sh/th/compliance/iso-27001/): How penetration testing supports an ISMS - [OWASP Top 10 hub](https://sth.sh/th/compliance/owasp-top-10/): current OWASP guides for Web, Mobile, API, LLM, and Agentic applications - [OWASP Top 10:2025 Web](https://sth.sh/en/compliance/owasp-top-10/web/): ten current web application risk categories with testing and remediation focus - [OWASP Mobile Top 10:2024](https://sth.sh/en/compliance/owasp-top-10/mobile/): ten current mobile application risk categories - [OWASP API Security Top 10:2023](https://sth.sh/en/compliance/owasp-top-10/api/): ten current API risk categories - [OWASP Top 10 for LLM Applications:2025](https://sth.sh/en/compliance/owasp-top-10/llm/): ten current LLM application risk categories - [OWASP Top 10 for Agentic Applications:2026](https://sth.sh/en/compliance/owasp-top-10/agent/): ten current agentic AI risk categories covering autonomous decision-making, tool execution, identity boundaries, and multi-agent systems - [MITRE ATT&CK](https://sth.sh/th/compliance/mitre-attack/): How ATT&CK techniques are used in testing English versions of every guide are available by replacing /th/ with /en/ in the URL. ## Articles - [STH blog (สยามถนัดแฮก)](https://blog.sth.sh/): Thai-language security research, tutorials, and industry commentary