The government is set to implement a multi-factor authentication (MFA) login method for all government services, an approach that will be tabled for cabinet approval today in order to combat a massive data leak that has compromised over 200 million login credentials nationwide, including vulnerabilities in 30,000 state systems.
According to Digital Economy and Society (DES) Minister Chaichanok Chidchob, the centrepiece of the proposal is the mandatory adoption of MFA for all government services.
MFA refers to a security method that requires two or more proofs of identity before allowing users to access an account, making it much harder for hackers to break in.
Mr Chaichanok held a meeting yesterday with related parties, including the National Cyber Security Agency (NCSA), Personal Data Protection Agency and Cyber Crime Investigation Bureau, to bolster state measures on cyber defence and protect the public's data.
As an urgent short-term measure, he said the government will also enforce a forced reset of passwords across all state agencies.
This directive, which can be implemented immediately, is designed to neutralise the usefulness of previously leaked credentials.
"We are buying time to conduct a total system cleansing," the minister said, noting that over 300 departments have 15 days to audit their digital assets.
The goal is to identify "zombie" systems -- old or abandoned platforms that remain active behind the scenes and serve as easy entry points for hackers, he added.
To ensure the measures are not ignored, the government plans to link cybersecurity compliance directly to key performance indicators and budget allocations for the upcoming fiscal year.
"If there are no tangible consequences, agencies may not act with the necessary urgency," Mr Chaichanok added.
He said the NCSA will strictly monitor implementation and enforce penalties for negligence.
While acknowledging that a 100% guarantee against leaks is impossible, Mr Chaichanok said the government is shifting towards a highest-security infrastructure model.
This includes transitioning to a standardised cloud-based authentication system used in high-security industries to protect personal data.
Amorn Chomchoey, secretary-general of the NCSA, said it is a good time to turn the crisis into an opportunity by seriously implementing the MFA method across all state units.
The proposed measures would be issued as a cabinet resolution to provide a clear legal and procedural framework for all state entities to follow, he added.