Announcement of RATCH Group Public Company Limited
No. 5/2025
Re: Information Technology Security, Cybersecurity, and Artificial Intelligence Policy

RATCH Group Public Company Limited (the “Company”) recognizes the importance of information technology, network systems, and artificial intelligence as tools to enhance the efficiency and effectiveness of its operations toward organizational excellence. The Company is committed to driving its business in the digital era to create innovation and value for stakeholders, as well as sustainable organizational growth, while upholding secure, ethical, well-governed, and responsible protection of data, systems, and the use of Artificial Intelligence (AI).

The Company has therefore established this Information Technology Security, Cybersecurity, and Artificial Intelligence Policy in alignment with applicable laws and international standards to ensure that the use and management of such technologies are secure, safe, transparent, and reliable. This Policy repeals the Announcement of RATCH Group Public Company Limited No. 2/2019 Re: Network and Computer System Usage Policy dated 17 April 2019; and the Announcement of RATCH Group Public Company Limited No. 2/2021 Re: Information Technology Security Policy dated 15 January 2021.

Objectives of the Policy
  1. To establish a framework for managing information technology, cybersecurity, and the use of Artificial Intelligence (AI) to safeguard the confidentiality, integrity, and availability of the Company’s data and information.
  2. To prevent and respond to all forms of cyber threats, reduce risks and impacts on the Company’s information assets, and ensure business continuity in alignment with the Company’s strategies and objectives.
  3. To govern the management of information technology, cybersecurity, and AI usage in compliance with the Computer-Related Crime Act B.E. 2550 (2007) and its amendments, the Cybersecurity Act B.E. 2562 (2019), the Personal Data Protection Act B.E. 2562 (2019), and other relevant laws.
  4. To align information technology, cybersecurity, and use of AI technology management practices with international standards such as NIST Cybersecurity Framework, OECD AI Principles, and other related international practices.
  5. To ensure that such operations comply with the Company’s regulations, policies, announcements, and orders, and that information technology, cyber, and AI technology usage are appropriately utilized to support business operations and risk management in accordance with good corporate governance principles.
Scope of the Policy
  1. This Policy applies to the Company’s Board of Directors, executives, employees, entities under the Company’s management control, and persons within the supply chain who are involved with the Company’s assets and systems. It covers all information technology systems, organizational data and digital assets, and devices connected to the Company’s network, without limitation as to location or time of use.
  2. The Company promotes and supports awareness of information technology security, cybersecurity, and responsible AI technology usage among the aforementioned groups. Any prior announcements, rules, orders, or practices that conflict with this Policy shall be superseded by this Policy.
Definitions
  1. “Company/Organization” means RATCH Group Public Company Limited.
  2. “Policy” means the principles relating to information technology security, cybersecurity, and Artificial Intelligence (AI) established by the Company, approved by the Chief Executive Officer, and formally announced for enforcement.
  3. “Guidelines” means operational practices relating to information technology security, cybersecurity, and AI technology usage established and announced by the Company for strict compliance.
  4. “Entities under the Company’s management control” means entities over which the Company has control or authority, whether through holding more than 50% of shares with voting rights or controlling the majority of voting rights at shareholders’ meetings, including authority over management decisions and operations, and where information technology and/or network and computer systems, and/or AI systems are jointly utilized.
  5. “Supply Chain” means the network of relationships among the Company, its business partners, contractors, and relevant parties involved in the management of information technology security, cybersecurity, and AI of the Company and its controlled entities.
  6. “Information” means data, news, records, histories, textual content, computer programs, computer data, images, sounds, symbols, and other marks, whether stored in a format directly understandable by individuals or through computers or other means.
  7. “Information System” means a system that collects, stores, processes, and distributes data to generate useful information for decision-making and operations of individuals or the organization. It comprises several key components including hardware, software, data, people, processes, and networks. Its main function is to transform raw data into meaningful information to support management and achieve organizational objectives.
  8. “Information Technology” means technology used in business operations, including data/information, operating systems, application systems, database systems, hardware, and communication network systems.
  9. “Information Technology Security” means the protection of information systems and data to ensure confidentiality, integrity, and availability at all times, preventing unauthorized access, alteration, or destruction of data through administrative, technical, and physical measures to respond to threats.
  10. “Cyber” means data and communications arising from services or applications of computer networks, internet system, telecommunications networks, including normal services of satellites, and other similar interconnected systems.
  11. “Cybersecurity” means measures or actions established to prevent, respond to, and reduce risks from all forms of cyber threats, both internal and external, which may impact the Company’s operations, national security, economic security, military security, or public order.
  12. “Cyber Threat” means any unlawful act or action carried out using computers, computer systems, or malicious programs intended to cause damage or abnormality to computer systems, computer data, or related information. It refers to a danger that adversely affects the operation of a computer, computer system, or other related data.
  13. “Artificial Intelligence (AI)” means technology developed to enable computer systems, robots, machines, or electronic devices to exhibit human-like characteristics or behaviors as defined by human objectives, such as learning, perception and response to the environment, reasoning, and problem-solving.
Key Policy Guidelines
  1. The Company shall manage information technology security, cybersecurity, and AI usage in compliance with applicable laws, governmental regulations, the Company’s related policies, and internationally recognized standards such as ISO/IEC 27001, NIST Cybersecurity Framework, and OECD AI Principles.
  2. The Company shall establish guidelines on information technology security, cybersecurity, and the use of AI technology for relevant parties to adhere to in their operations. These guidelines aim to prevent threats and reduce risks from intruders in the use of the Company’s information technology, cyber, and AI technology.
  3. The Company shall establish guidelines on information technology security, cybersecurity, and AI technology usage to support business operations, business development, and comprehensive and appropriate risk management, as follows:
    1. Establish a systematic management structure for information technology security, cybersecurity, and the use of AI technology, clearly defining the roles, responsibilities, and duties of all relevant parties at every level to ensure effective governance of information technology, cyber systems, and the use of Artificial Intelligence (AI).
    2. Establish processes for risk identification, risk assessment, and the determination of acceptable risk levels, including the management of risks related to information technology, cybersecurity, and AI usage. This includes conducting surveys and maintaining an inventory of information technology assets, as well as assessing risks that may affect the security of systems and data, in order to develop appropriate prevention plans aligned with the level of risk and to address potential cyber threats that may arise in the future.
    3. Emphasize the implementation of control measures to prevent unauthorized access to or use of data, as well as to prevent data loss or destruction, by adopting appropriate technologies such as access control systems, endpoint protection systems, and data encryption. In addition, provide continuous training to employees to enhance awareness of information technology, cyber, and the use of Artificial Intelligence (AI).
    4. Establish systems and processes to monitor and detect abnormal events, and to manage information technology security breaches or potential cyber threats that may occur within the information technology systems in real time. This includes using tools capable of analyzing cyber threats and providing early warnings, enabling timely response and risk management to minimize potential impacts on the organization. Additionally, continuously improve processes to ensure effectiveness, enabling the organization to contain incidents, implement corrective actions, mitigate impacts, provide remediation, and promptly recover business operations and information assets.
    5. Establish guidelines and response plans for cyber threats and the use of Artificial Intelligence (AI) technology that cover cyber threat levels and AI usage, reporting procedures, review processes, impact containment, and system recovery. In addition, appoint a Cybersecurity Incident Response Team (CIRT) to ensure that corrective actions and situation control are carried out systematically, minimizing potential damage to the greatest extent possible.
    6. Establish a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) for information technology systems to ensure that the organization can resume operations quickly and continuously following a cyber threat. The recovery plans shall be regularly reviewed and updated, incorporating lessons learned from past incidents to systematically improve management practices.
  4. The Company shall establish criteria for the use of AI technology in alignment with ethical principles, applicable laws, and appropriate and verifiable guidelines, that are in line with the OECD AI Principles.
  5. The Company shall establish a process to regularly promote awareness of information technology security, cybersecurity, and the responsible use of AI technology among the Board of Directors, executives, employees, entities under the Company’s management control, as well as relevant parties throughout the supply chain.
Governance and Policy Review
  1. The Information Technology and Cybersecurity Risk Management Working Committee has duties as prescribed in RATCH Group Public Company Limited’s Order No. C.13/2025, to ensure governance and oversight in compliance with this Policy.
  2. A review of this Policy and related guidelines shall be conducted at least once a year to ensure that the principles of this Policy remain aligned with the Company’s context and business operations at that time, or whenever there are changes in relevant laws, technologies, or threats.
Penalties

Any person who violates, fails to comply with, or breaches this Policy shall be subject to disciplinary action under the Company’s work regulations. If such action constitutes a legal offense, legal penalties may also apply.

For the acknowledgement and compliance of all.

Announcement Date: 17 October 2025

Chief Executive Officer

Other Policy
The Corporate Governance Policy
The Company’s Group sets practice guideline at the international standard to promote transparent and effective management and operations that lead to reinforcement of trust among shareholders, investors and all stakeholders; and to pursue the principles of Good Corporate Governance of listed companies.
Learn More
Supplier Code of Conduct
RATCH Group Public Company Limited (Company) realizes the importance of balancing environmental, social, and governance (ESG) considerations in our business practices.
Learn More
Human Rights Policy
RATCH Group Public Company Limited is aware that respect for human rights is an essential for business operations.
Learn More
Stakeholder Engagement Policy
The Company’s Board of Directors clearly specifies the policy and guideline on stakeholder groups. The Company’s Code of Conduct was reviewed and improved as the framework for directors, executives and employees in treating each stakeholder group including shareholders, employees, customers, creditors, partners, competitors, the government and communities around the Company’s premises,
Learn More
Risk Management Policy
RATCH Group Public Company Limited establish an international standard risk management system which will uphold the customer satisfaction and preferable returns to shareholders and all stakeholders based on good corporate governance.
Learn More
Shareholders Policy
In pursuance to the principles of Good Corporate Governance recommended by the Stock Exchange of Thailand to listed companies to comply with or to adapt to best fit the situation of each company, the Board of Directors stipulated the Company’s shareholders policy
Learn More
Employee Policy
The Company recognizes the employees as its valuable assets and key factor in driving its operations towards targeted success and that it attempts to manage, develop and retain its employees to create outputs for sustainable and progressive growth to the Company.
Learn More
Environmental And Social Policy
RATCH Group Public Company Limited has been committed to sustainable business development, to achieve continuous, solid and long-term growth. The Company is confident that the commitments to higher environmental, social and governance standards will not only keep risks manageable but also add the values of our operations that are geared towards positive impacts on society and minimized impacts on the environment.
Learn More
Safety, Occupational Health and Working Environment Policy
RATCH Group Public Company Limited (“the Company”) has determined the vision to become a leading value-oriented energy and infrastructure company in Asia Pacific. We realized that safety, occupational health and good working environment are vital for our employees, partners, suppliers, and visitors.
Learn More
Energy Conservation Policy
At present, the domestic demand on energy, including electricity consumption gradually increases due to rising population and industrial and economic expansion that cuts down the energy reserve.
Learn More
Office Building’s Environmental Management Policy
The Company appointed the Office Building’s Environmental Management Committee to efficiently and effectively operate office building’s environmental management according to the controlled building act, environmental, safety, occupational health and working environment laws, other relevant laws and regulations as well as the Company's Social and Environmental Policy of the Company,
Learn More
The 5 S Policy
In order to promote discipline, safety and good health to create pleasant working environment and good corporate image through participation of employees at all levels and with continuous practices that have been developed into corporate culture, the Company, therefore, provides the 5S activities based on the following objectives and goals:
Learn More
Anti-Fraud Corruption Policy
To ensure that the operations of RATCH Group Public Company Limited (“the Company”) are in accordance with international practice while being fair and transparent, to uphold corporate social responsibilities for all stakeholders to align with good corporate governance and business conduct, and to align with the Company’s declaration with Thailand’s Private Sector Collective Action Coalition against Corruption (CAC)
Learn More
Tax Policy
RATCH Group Public Company Limited sets forth the corporate tax policy, to ensure that the Company Group's operations comply with international standards, adhere to transparent and fair business practices, as well as uphold responsibility towards society and all stakeholders in accordance with good corporate governance and business ethics.
Learn More
Corporate Sustainability Policy
The company commits to operating business in principle of good corporate governance aiming for corporate sustainability which will bring shared value on economic, social and environment to its business value chain.
Learn More
Business Continuity Management Policy
To guide practices of Business Continuity Management of RATCH Group Public Company Limited in managing risks and any kind of crises in order to continue ongoing business operation, protect stakeholders’ interest, and maintain reputation, credibility and sustainability, the Company addressed the Business Continuity Management Policy
Learn More
Information Technology Security, Cybersecurity, and Artificial Intelligence Policy
RATCH Group Public Company Limited hereby announced the Information Technology (IT) Security Policy, to ensure the IT system as well as the network and computer system of the Company, subsidiaries and affiliated companies sharing these systems is secure and continually supportive to the Company's operations; compliant with the Computer Crime Act and other relevant laws; and efficient in preventing harms and damage on the Company.
Learn More
Prevention of Misuse of Inside Information Policy
RATCH Group Public Company Limited realizes the importance of preventive measures against misuse and abuse of inside information by directors, executives, job operators and related parties, directly or indirectly for their own or others’ benefits. Whether returns are obtained or not, such act violates the Securities and Exchange Act, puts pressure on the Company’s interests, causes conflict of interest and is harmful to the Company’s credibility.
Learn More
RGCO Announcement on Environment, Occupational Health and Safety
Ratchaburi Electricity Generating Co., Ltd. operates the electricity generation business with 3,645 Megawatt in capacity, to address national power demand. The generation is fueled primarily by natural gas, with bunker oil and diesel oil as secondary fuels.
Learn More
Personal Data Protection Policy
RATCH Group Public Company Limited and its subsidiaries (“Company”) realize the potential measures of the protection of personal data. Pursuant to this personal data protection policy, it hereby explains on how the Company treats the process of data collection, preservation, use and disclosure of personal data, and related individual’s rights.
Learn More
Cookies Policy
This website is serviced by RATCH Group Public Company Limited (the “Company”). The Company’s website operates Cookies and other alike technologies that enables to access your internet-connected browser and devices e.g., computer, smartphone or tablet in order to remember your pattern and preferences during web visiting session.
Learn More
Giving/ Receiving of Gifts and Souvenirs
On the upcoming New Year's occasion, the company would like to announce the no gift practice to all employees adherence to the international standards of good governance and transparency in business operation and to align with the company’s Anti-Fraud Corruption Policy
Learn More
Charitable Donations and Sponsorships Order
In compliance with RATCH Group Public Company Limited Regulations on Anti-Fraud and Corruption (B.E.2562) and by the authorization granted under Section 2 (13.4) of RATCH Group Public Company Limited Regulations on Accounting, Finance and Budgeting B.E. 2562 as well as Section 1 (5) of RATCH Group Public Company Limited Regulations on Anti-Fraud and Corruption (B.E.2562), the Chief Executive Officer hereby issues the following order
Learn More