# Siam Thanat Hack (STH) > Siam Thanat Hack Co., Ltd. (บริษัท สยามถนัดแฮก จำกัด) is a Bangkok-based offensive cybersecurity company providing expert-led, AI-augmented penetration testing (Pentest), VA scanning, and Red Team services for Web, Mobile, API, and Network systems. Certified to ISO/IEC 27001:2022 and ISO 9001:2015. Incorporated 11 December 2018. Tax ID: 0105561208922. Contact: pentest@sth.sh For the comprehensive full technical reference, see [llms-full.txt](https://sth.sh/llms-full.txt). ## Main pages - [Thai homepage](https://sth.sh/th/): บริการการทดสอบเจาะระบบ (Pentest) โดยทีม White Hat สัญชาติไทย - [English homepage](https://sth.sh/en/): Penetration testing and cybersecurity services in Thailand - [Compliance & Regulations Hub](https://sth.sh/th/compliance/): สรุปข้อกำหนดหน่วยงานกำกับดูแลไทยและมาตรฐานสากล - [Careers Hub](https://sth.sh/th/careers/): ร่วมงานกับ STH ในสายงาน Offensive Security - [Security Blog & Research](https://sth.sh/th/blog/): ศูนย์รวมบทวิเคราะห์เชิงเทคนิค สรุปมาตรฐาน และงานวิจัยช่องโหว่ ## AI Security & Governance Frameworks - [ISO/IEC 42001:2023 AI Management](https://sth.sh/th/compliance/iso-42001-ai-management/): How penetration testing and AI Red Teaming prove AIMS readiness and Annex A technical controls - [MITRE ATLAS Matrix](https://sth.sh/th/compliance/mitre-atlas/): Adversarial Threat Landscape for AI Systems v2026.07 covering prompt injection, agentic execution, and model extraction - [NIST AI RMF 1.0 & GenAI Profile](https://sth.sh/th/compliance/nist-ai-rmf/): National AI Risk Management Framework (NIST AI 600-1) and offensive red-team verification - [Google Secure AI Framework (SAIF)](https://sth.sh/th/compliance/google-saif/): 6 core AI security elements and threat-informed testing - [NCSA AI Security Guidelines](https://sth.sh/th/compliance/ncsa-ai-security-guidelines/): Thai National Cybersecurity Agency secure AI lifecycle, governance, risk, and evidence - [OWASP Top 10 for LLM Applications:2026](https://sth.sh/en/compliance/owasp-top-10/llm/): Ten current LLM application risk categories - [OWASP Top 10 for Agentic Applications:2026](https://sth.sh/en/compliance/owasp-top-10/agent/): Ten current agentic AI risk categories covering autonomous decision-making, tool execution, identity boundaries, and multi-agent systems ## Thai Regulatory Mandates & National Standards - [Bank of Thailand (BOT)](https://sth.sh/th/compliance/bank-of-thailand/): BOT penetration testing guideline, iPentest (1252/2562), VA requirements (สนช. 1/2564), Mobile Banking security (ประกาศ ธปท. ที่ 4/2568), and e-Money - [Thai SEC](https://sth.sh/th/compliance/sec/): Securities and digital asset business penetration testing requirements - [Office of Insurance Commission (OIC)](https://sth.sh/th/compliance/oic/): Thai insurance regulator IT risk management criteria and penetration testing - [NDID Member Criteria](https://sth.sh/th/compliance/ndid/): Penetration testing requirements for National Digital ID members - [Personal Data Protection Act (PDPA)](https://sth.sh/th/compliance/pdpa/): Thailand Personal Data Protection Act B.E. 2562 (2019) and technical security testing - [Cybersecurity Act](https://sth.sh/th/compliance/cybersecurity-act/): Thailand Cybersecurity Act B.E. 2562 (2019) for Critical Information Infrastructure (CII) - [NCSA Cloud Security Standard B.E. 2567](https://sth.sh/th/compliance/ncsa-cloud-security-standard/): Government, regulator, and CII cloud security standard, including vulnerability-management and supplier-agreement clauses 5.2.6.8 and 5.2.9.2 - [NCSA Website Security Standard B.E. 2568](https://sth.sh/th/compliance/ncsa-website-standard/): Thai national website security standard B.E. 2568 (2025) - [NCSA Zero Trust Guidelines](https://sth.sh/th/compliance/ncsa-zero-trust-guidelines/): Thailand NCSA Zero Trust Architecture 5 pillars, migration roadmap, and control points - [NCSA Post-Quantum Readiness](https://sth.sh/th/compliance/ncsa-post-quantum-readiness/): Guidelines for PQC crypto asset inventory, harvest-now-decrypt-later risk, and hybrid PQC transition - [BOT ATM Malware Guideline](https://sth.sh/th/compliance/bot-atm-malware-guideline/): Bank of Thailand ATM and kiosk security requirements, application whitelisting, and hardware pentest ## International Security Standards & Frameworks - [PCI DSS v4.0.1](https://sth.sh/th/compliance/pci-dss/): Payment Card Industry Data Security Standard Requirement 11.4 penetration testing - [ISO/IEC 27001:2022](https://sth.sh/th/compliance/iso-27001/): How penetration testing supports an ISMS and Annex A.8.8 management of technical vulnerabilities - [MPA Content Security v5.3.1](https://sth.sh/th/compliance/mpa-content-security/): Motion Picture Association best practices and TPN 4-tier shield verification - [OWASP Top 10 Hub](https://sth.sh/th/compliance/owasp-top-10/): Current OWASP standards for Web, Mobile, API, LLM, and Agentic applications - [OWASP Top 10:2025 Web](https://sth.sh/en/compliance/owasp-top-10/web/): Ten current web application risk categories with testing and remediation focus - [OWASP Mobile Top 10:2024](https://sth.sh/en/compliance/owasp-top-10/mobile/): Ten current mobile application risk categories - [OWASP API Security Top 10:2023](https://sth.sh/en/compliance/owasp-top-10/api/): Ten current API risk categories - [MITRE ATT&CK v19.2](https://sth.sh/th/compliance/mitre-attack/): Enterprise Matrix threat techniques used in penetration testing ## Careers at STH - [Penetration Tester](https://sth.sh/th/careers/penetration-tester/): Junior / Mid-level Offensive Security Tester - [Senior Penetration Tester](https://sth.sh/th/careers/senior-penetration-tester/): Senior Offensive Security Specialist - [IT Security Manager](https://sth.sh/th/careers/it-security-manager/): IT Security Manager / Offensive Team Lead ## Security Blog & Research Articles - [Google SAIF: Six Core Principles for Securing AI Systems](https://sth.sh/en/compliance/google-saif/): A breakdown of Google's Secure AI Framework and practical steps to defend models, training data, and agent integrations. - [Does ISO/IEC 27001:2022 Require Penetration Testing?](https://sth.sh/en/compliance/iso-27001/): Analyzing Control A.8.8 (Management of technical vulnerabilities), threat-informed prioritization with CISA KEV and EPSS, and operationalizing pentest evidence across ISMS core clauses. - [What ISO/IEC 42001:2023 Means and How AI Pentesting Proves AIMS Readiness](https://sth.sh/en/compliance/iso-42001-ai-management/): An in-depth breakdown of ISO/IEC 42001:2023 for AI management systems and how offensive testing provides verifiable evidence for executive oversight and audits. - [Understanding MITRE ATLAS for AI Red Teaming and Threat Modeling](https://sth.sh/en/compliance/mitre-atlas/): Explore the 16 tactics of the MITRE ATLAS matrix to plan systematic adversary simulations across Generative AI, RAG pipelines, and agentic workflows. - [NCSA Government Cloud Security Standard and Testing Guidance](https://sth.sh/en/compliance/ncsa-cloud-security-standard/): National cloud security guidelines in Thailand and technical testing methodologies for public and private cloud environments. - [NCSA Post-Quantum Cryptography Readiness Guidelines 2025: Technical Implementation](https://sth.sh/en/compliance/ncsa-post-quantum-readiness/): In-depth guide to Thailand NCSA Post-Quantum Readiness guidelines, Shor and Grover risk models, Mosca theorem evaluation, dual-pillar inventories, and hybrid PQC architecture. - [Zero Trust: from policy decisions to enforcement](https://sth.sh/en/compliance/ncsa-zero-trust-guidelines/): Follow the roles of the PE, PA, and PEP, and see how a policy decision controls the path to a resource. - [NIST AI RMF Explained: Risk Management and Technical Assurance](https://sth.sh/en/compliance/nist-ai-rmf/): How the NIST AI Risk Management Framework connects organizational governance with empirical AI security testing. - [Thai SEC Security Testing Requirements for Securities and Digital Assets](https://sth.sh/en/compliance/sec/): Comprehensive guide to Thai SEC cybersecurity regulations, vulnerability assessments, penetration testing, digital asset custody, and smart contract audits. - [MPA Content Security v5.3.1 and Penetration Testing for Media Production](https://sth.sh/en/compliance/mpa-content-security/): An overview of MPA Content Security Best Practices v5.3.1, the TPN four-tier shield framework, and mandatory penetration testing under Control TS-4.1 for production vendors. English versions of every guide are available by replacing /th/ with /en/ in the URL.