Bangkok · Chief Information Security Officer
Fractional CISO in Bangkok
The second most-established fractional role after CFO, and for the same reason: the need is compliance-triggered and finite. An enterprise customer conditions a contract on ISO 27001, a regulator names a required officer, an insurer asks for MFA and offline backup attestations before renewal — and a company of eighty people discovers it needs security judgment it cannot justify hiring full-time.
Severance runs to 400 days of uncapped wages while employer social cost is capped at THB 10,500 a year. A bad executive hire is cheap to carry and ruinous to exit.
What they deliver
- Security programme and a costed 12–18 month roadmap
- ISO 27001 or SOC 2 readiness, through to managing the external auditor
- Incident response plan mapped to each regulator’s notification clock, and the tabletop exercises to test it
- Enterprise customer security questionnaires — often the highest-return work on the whole mandate
- Third-party and vendor risk: tiering, diligence, contract security schedules
- Board and regulator reporting, and managing the MSSP or a small internal team
Signals you need one
- A customer has made ISO 27001 or a security questionnaire a condition of the contract
- You have had a breach, a ransomware scare, or a near-miss nobody formally closed out
- Cyber insurance renewal came back loaded, or declined
- A buyer or investor has commissioned technical due diligence
- Security has been the CTO’s side job and headcount is now past fifty
- You have security engineers but nobody senior enough to set the direction
Saudi Arabia and South Korea both require the named security officer to be an internal, full-time appointment — Saudi under NCA Essential Cybersecurity Controls 1-2-2, which requires cybersecurity roles to be filled by full-time Saudi nationals, and Korea under the Network Act, where the CISO is designated and reported to the Ministry of Science and ICT, with larger companies barred from letting that person hold unrelated duties. In both, a fractional CISO can advise the designated officer but cannot be them. Hong Kong is the opposite case: its critical infrastructure regime expressly allows the security management unit and its supervisor to sit outside Hong Kong, which makes it the most fractional-friendly regime in the region.
The Bangkok numbers
The full Bangkok picture — tax, regulation and market context →
What governs this in Thailand
Foreign Business Act B.E. 2542
A company more than 49% foreign-held is a "foreigner". List 3 item 21 captures consulting, so a foreign-owned advisory entity billing a Thai client from inside Thailand needs a Foreign Business Licence. Nominee shareholding is criminal — up to three years and THB 1m.
BOI promotion
Exempts from FBA licensing and eases work permits, but since 1 October 2025 imposes minimum salaries: THB 150,000/month for executives, THB 75,000 for managers, plus a 70% Thai-staff rule for larger manufacturers.
International Business Centre (IBC)
Corporate tax of 8%, 5% or 3% depending on local spend, THB 10m paid-up capital and ten skilled employees. Expatriate employees get a flat 15% personal income tax instead of the 35% top rate.
Mandatory statutory audit
Every Thai limited company must file audited financial statements regardless of size or dormancy. Directors are personally liable for fines, and three consecutive years of non-filing triggers strike-off. Even five-person firms already buy external finance expertise.