BMSP Strengthens Cybersecurity Awareness for EXIM BANK Employees

The Export Import Bank of Thailand (EXIM BANK) held a Cybersecurity Awareness Training session at its headquarters on October 1, 2026, inviting BMSP, a cybersecurity specialist, to share practical knowledge and insights with its personnel.

The session was led by Kris Nawani, Co-Founder and Director of BMSP, with the aim of strengthening cybersecurity awareness across the organization. The training focused on cyber threats that employees may encounter in both their professional and personal lives, along with practical ways to identify, prevent, and respond to potential risks before they affect organizational data or systems.

Today, cyberattacks are no longer limited to directly targeting technology and infrastructure. Attackers increasingly exploit human behavior, trust, and user mistakes as entry points into organizations. At the same time, advances in Artificial Intelligence (AI) are making scams and impersonation attacks more sophisticated and convincing.

Building strong cybersecurity awareness among employees is therefore an essential part of reducing cyber risk at its source.

Recognizing More Sophisticated Phishing and Social Engineering Attacks

One of the key topics covered during the training was Phishing and Social Engineering, which remain common techniques used by attackers to trick individuals into disclosing sensitive information, clicking malicious links, downloading harmful files, or carrying out unauthorized actions.

Participants learned how to identify suspicious emails and recognize scams delivered through various channels, including SMS Phishing, QR Code Scams, and Executive Impersonation, where attackers pose as senior executives to request money transfers or confidential information.

The rapid development of Generative AI has also introduced new forms of Social Engineering, including AI generated Deepfake Voice and Deepfake Video. These technologies can realistically imitate a person’s voice or appearance and may be used to impersonate executives or other trusted individuals during voice calls or video conferences.

Such attacks may attempt to convince finance or accounting teams to transfer funds or disclose sensitive information.

When receiving requests involving financial transactions, confidential information, or unusual urgency, users should always verify the identity of the requester and confirm the request through a trusted communication channel before taking action.

Malware and Ransomware Can Begin with a Single Action

The training also covered risks associated with Malware and Ransomware, ranging from malicious files and computer viruses to attack methods that users may not immediately recognize as cybersecurity threats.

One example is a USB Drop Attack, also known as USB Baiting, where attackers deliberately leave USB devices in public areas or workplace environments in the hope that someone will connect them to a computer.

Another risk discussed was Juice Jacking, which involves connecting mobile devices to public USB charging points that may be unsafe or compromised.

These examples demonstrate that malware does not necessarily originate from websites or email attachments alone. Everyday actions involving external devices, downloads, or unfamiliar connections may also expose users and organizations to cyber threats.

Using Personal Devices for Work Securely

As modern working environments allow employees to access organizational data and systems from different locations and devices, endpoint security has become an increasingly important part of cybersecurity.

One of the key recommendations discussed during the session was that personal devices used for work, such as notebooks, tablets, or smartphones, should remain under the control of the individual user and should not be routinely shared with other family members.

If another person uses the same device to visit unsafe websites, click unknown links, or install games or software from untrusted sources, the device may become exposed to malware or other cyber threats.

When the same device can also connect to corporate email, organizational data, or internal systems, a security issue originating from personal use may create additional risk for the organization.

AI Security Awareness and Responsible AI Use

As AI becomes increasingly integrated into everyday work, using AI tools securely and responsibly is becoming an important part of modern Cybersecurity Awareness.

The training discussed appropriate use of tools such as Microsoft Copilot, as well as the importance of avoiding the submission of confidential, internal, or sensitive organizational information into public AI services without authorization.

Participants were also introduced to emerging AI related security risks, including Prompt Injection, which may be used to manipulate or alter the behavior of an AI system, and Data Leakage, where sensitive organizational information may be unintentionally exposed.

The objective is not to avoid AI, but to understand what types of information can be used with AI, which AI tools are approved by the organization, and how AI generated outputs should be reviewed before being used in business processes.

Safe Internet Use and Account Security

Another important part of building secure digital behavior is protecting the accounts and credentials used across online services and platforms.

The training emphasized that users should avoid reusing the same username and password across multiple platforms. If credentials from one account are compromised or exposed in a data breach, attackers may attempt to reuse those credentials to gain access to other accounts.

Users should also be cautious when storing passwords in web browsers or on devices, particularly when those devices may be accessible to other people. If the device or account used to store credentials is compromised, multiple accounts could be exposed at the same time.

Safe Internet and Social Media practices were also discussed in both workplace and personal contexts. Users should carefully consider what information they publish online, verify the credibility of information before sharing it, remain cautious of Fake News, and avoid downloading free software or files from untrusted sources that may contain malware.

Information that appears insignificant when viewed individually can sometimes be collected and combined with information from other sources. Attackers may use this information to conduct Social Engineering or develop highly targeted attacks against individuals or organizations.

Practicing responsible Internet, Social Media, and account usage therefore provides an important foundation for reducing opportunities for attackers to exploit user information and behavior as a pathway into the organization.

Learning Through Workshops and Practical Scenarios

In addition to knowledge sharing sessions, the training included practical workshops designed to help participants apply cybersecurity concepts to realistic scenarios.

Participants practiced analyzing emails to determine whether they were legitimate or potentially part of a Phishing attack while identifying warning signs and suspicious elements that users should look for.

The session also included examples of attack techniques and scenarios that can occur in real situations, helping participants understand how cyber incidents may begin and how user decisions at different stages can help prevent an attack or reduce its potential impact.

Every employee who uses organizational email, devices, systems, or data plays a role in cybersecurity.

Building the right knowledge, awareness, and digital habits among employees therefore strengthens the organization’soverall security posture and helps reduce risks related to human behavior.

BMSP would like to thank the Export Import Bank of Thailand (EXIM BANK) for the opportunity to share and exchange knowledge on Cybersecurity Awareness with its personnel.

For organizations looking to strengthen Cybersecurity Awareness among employees or seeking comprehensive Cybersecurity and IT Managed Services, BMSP provides comprehensive consulting, solutions, and services designed to support the specific requirements and operating environments of each organization.

Contact BMSP to discuss Cybersecurity Awareness, Cybersecurity Solutions, and IT Managed Services for your organization.

Contact BMSP

Contact BMSP to discuss practical cybersecurity solutions for your organization.

Share

Related Content

Get in touch with us. We’re here to assist you.

08. Home Bottom (EN)

Learn how we helped 100 top brands gain success