The National Cyber Security Agency (NCSA) is preparing the country to deal with emerging attacks involving smart devices, particularly CCTV systems and virtual power plants (VPPs) in the energy sector, while deeming data sovereignty a priority. “We see the risks for digital surveillance by monitoring specific data points, such as what time and where a vehicle was moving in and out, which could determine precisely a target’s location and routine,” AVM Amorn Chomchoey, the NCSA secretary-general, told the Bangkok Post. The agency plans to introduce Internet of Things (IoT) security guidelines in September covering consumer smart home devices to help consumers choose safer devices. The guidelines recommend several crucial security features, such as no-default passwords — devices must not come up with default passwords; users are required to set their own. In addition, the products must support firmware updates to patch future security issues. Devices must have a notification system to alert users when a security vulnerability is detected. This initiative involves collaboration with the Thai Intelligent CCTV Association, AVM Amorn said. There are discussions about making these security requirements mandatory, he said. Regulatory agencies may adopt and enforce these rules, specifically to control the importation of devices and ensure that non-standard, vulnerable products are not brought into the market. However, if the guideline becomes mandatory, there is concern about whether the new standards will be compatible with older measures and if the effect will drastically increase the prices of products, AVM Amorn said. By the end of this month, the NCSA expects to discuss security with power utilities, manufacturers and service providers of VPPs. According to Electricity Generating Authority of Thailand, a VPP is a cutting-edge energy management platform that aggregates multiple small, scattered power sources into a single, large-scale power network without constructing a physical facility. The integration