Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation
Abstract
1. Introduction
2. Literature Review
2.1. Cyberattacks as Non-Traditional Security Threats and the Analytical Problem of Variation
2.2. Global Patterns, Cybercrime Hubs, and the Attribution Problem
2.3. Typologies of Cybercriminal Organisations and Interaction Patterns
2.4. Structural and Political–Economic Correlates of Cybercrime and Cyber Aggression
2.5. Thailand’s Cyber Posture, Military Roles, and Sectoral Vulnerabilities and ASEAN’s Role
2.6. Routine Activity Theory (RAT) and Clustering as an Applied Bridge to Policy Design
3. Materials and Methods
3.1. Data
3.2. Analytical Framework
3.3. Clustering Analysis
4. Results
4.1. Main Findings
4.2. Sensitivity Analysis
5. Discussion and Conclusions
5.1. Summary and Significance of Findings
5.2. Cluster-Level Interpretation Through Routine Activity Theory
5.3. Implications for Thailand’s Cyber Posture and the Role of the Military
5.4. Methodological Contribution: Clustering for Policy Design
5.5. Limitations
5.6. Concluding Remarks
Supplementary Materials
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Appendix A



| Variable | Type of Variable | Levels | Number of Sparse (Singleton) Categories | Sparse (Singleton) Categories | Number of Categories 2 or Less | Categories 2 or Less |
|---|---|---|---|---|---|---|
| Year | Supplementary | 11 | 1 | 2019 | 2 | 2017; 2019 |
| Actor | Descriptive | — | — | — | — | — |
| Actor Country | Active | 6 | 3 | Cambodia; Korea (the Democratic People’s Republic of); Russian Federation | 3 | Cambodia; Korea (the Democratic People’s Republic of); Russian Federation |
| Actor Type | Active | 4 | 0 | 0 | 0 | — |
| Organisation | Descriptive | — | — | — | — | — |
| Industry Name | Active | 16 | 3 | 0 | 7 | Administrative and Support and Waste Management and Remediation Services; Educational Services; Manufacturing; Professional, Scientific, and Technical Services; Real Estate and Rental and Leasing; Transportation and Warehousing; Wholesale Trade |
| Motive | Active | 4 | 0 | 0 | 0 | — |
| Event Type | Active | 4 | 0 | 0 | 1 | Undetermined |
| Event Sub-Type 1 | Active | 7 | 0 | 0 | 3 | Exploitation of End Hosts; Exploitation of Sensors; Message Manipulation |
| Event Sub-Type 2 | Active | 2 | 0 | 0 | 0 | — |


| Variable | Number of Unique Categories | Total Number of Observations | Percent Unique |
|---|---|---|---|
| Year | 11 | 78 | 14.10 |
| Actor | 29 | 78 | 37.18 |
| Actor Country | 6 | 78 | 7.69 |
| Actor Type | 4 | 78 | 5.13 |
| Organisation | 77 | 78 | 98.72 |
| Industry Name | 16 | 78 | 20.51 |
| Motive | 4 | 78 | 5.13 |
| Event Type | 4 | 78 | 5.13 |
| Event Sub-Type 1 | 7 | 78 | 8.97 |
| Event Sub-Type 2 | 2 | 78 | 2.56 |



| Cluster | Variable/Category | Cla/Mod | Mod/Cla | Global | p-Value | V-Test |
|---|---|---|---|---|---|---|
| 1 (Hacktivism) | motive_Protest | 100.0 | 90.9 | 25.6 | <0.001 | 8.3 |
| actor_type_Hacktivist | 100.0 | 86.4 | 24.4 | <0.001 | 7.9 | |
| year_2016 | 100.0 | 54.5 | 15.4 | <0.001 | 5.7 | |
| industry_Public Administration | 66.7 | 81.8 | 34.6 | <0.001 | 5.3 | |
| event_subtype_1_External Denial of Service | 100.0 | 40.9 | 11.5 | <0.001 | 4.7 | |
| event_type_Disruptive | 80.0 | 36.4 | 12.8 | <0.001 | 3.5 | |
| industry_Finance and Insurance | 0.0 | 0.0 | 11.5 | 0.042 | −2.0 | |
| year_2024 | 6.7 | 4.5 | 19.2 | 0.037 | −2.1 | |
| event_subtype_1_Data Attack | 0.0 | 0.0 | 16.7 | 0.009 | −2.6 | |
| year_2022 | 0.0 | 0.0 | 16.7 | 0.009 | −2.6 | |
| motive_Financial | 0.0 | 0.0 | 56.4 | <0.001 | −6.6 | |
| actor_type_Criminal | 0.0 | 0.0 | 61.5 | <0.001 | −7.3 | |
| 2 (Financial Crime) | actor_type_Criminal | 100.0 | 94.1 | 61.5 | <0.001 | 8.6 |
| motive_Financial | 100.0 | 86.3 | 56.4 | <0.001 | 7.8 | |
| actor_country_Undetermined | 73.1 | 96.1 | 85.9 | 0.001 | 3.3 | |
| event_subtype_1_Data Attack | 100.0 | 25.5 | 16.7 | 0.002 | 3.1 | |
| industry_Finance and Insurance | 100.0 | 17.6 | 11.5 | 0.017 | 2.4 | |
| year_2022 | 92.3 | 23.5 | 16.7 | 0.024 | 2.3 | |
| year_2023 | 100.0 | 13.7 | 9.0 | 0.044 | 2.0 | |
| motive_Political-Espionage | 16.7 | 2.0 | 7.7 | 0.018 | −2.4 | |
| actor_type_Nation-State | 16.7 | 2.0 | 7.7 | 0.018 | −2.4 | |
| actor_country_Thailand | 0.0 | 0.0 | 5.1 | 0.012 | −2.5 | |
| actor_country_China | 0.0 | 0.0 | 5.1 | 0.012 | −2.5 | |
| event_type_Disruptive | 20.0 | 3.9 | 12.8 | 0.003 | −3.0 | |
| event_subtype_1_External Denial of Service | 0.0 | 0.0 | 11.5 | <0.001 | −4.2 | |
| year_2016 | 0.0 | 0.0 | 15.4 | <0.001 | −5.1 | |
| industry_Public Administration | 22.2 | 11.8 | 34.6 | <0.001 | −5.8 | |
| actor_type_Hacktivist | 0.0 | 0.0 | 24.4 | <0.001 | −7.0 | |
| motive_Protest | 0.0 | 0.0 | 25.6 | <0.001 | −7.2 | |
| 3 (Political Espionage) | motive_Political-Espionage | 83.3 | 100.0 | 7.7 | <0.001 | 5.1 |
| actor_type_Nation-State | 83.3 | 100.0 | 7.7 | <0.001 | 5.1 | |
| actor_country_China | 100.0 | 80.0 | 5.1 | <0.001 | 4.6 | |
| event_subtype_1_Exploitation of End Hosts | 100.0 | 40.0 | 2.6 | 0.003 | 2.9 | |
| motive_Financial | 0.0 | 0.0 | 56.4 | 0.013 | −2.5 | |
| actor_type_Criminal | 0.0 | 0.0 | 61.5 | 0.007 | −2.7 | |
| actor_country_Undetermined | 0.0 | 0.0 | 85.9 | <0.001 | −4.2 |

| k | Cluster | Mean Jaccard | Times Dissolved | Times Recovered | Stability | Dissolution Rate | Recovery Rate |
|---|---|---|---|---|---|---|---|
| 2 | Cluster 1 | 0.690377 | 581 | 21,098 | Pattern present, but membership uncertain | 0.00581 | 0.21098 |
| Cluster 2 | 0.407398 | 77,195 | 3127 | Unstable | 0.77195 | 0.03127 | |
| 3 | Cluster 1 | 0.758887 | 1277 | 54,046 | Stable | 0.01277 | 0.54046 |
| Cluster 2 | 0.440936 | 65,156 | 2884 | Unstable | 0.65156 | 0.02884 | |
| Cluster 3 | 0.323794 | 76,004 | 23,363 | Unstable | 0.76004 | 0.23363 |
References
- Raksereepitak, Y.; Tantayakul, S. Thai Army and Cybersecurity Policy for Non-Traditional Threats (Thai) [บทบาท ของ กองทัพ กับ นโยบาย รักษา ความ มั่นคง ปลอดภัย ไซเบอร์ เพื่อ ป้องกัน ภัย คุกคาม รูป แบบ ใหม่]. วารสาร รามคำแหง ฉบับ รัฐประศาสนศาสตร์ [Ramkhamhaeng J. Public Adm.] 2025, 5, 461–481. [Google Scholar]
- Manantan, M.B. Cyber ASEAN: Advancing Cyber Resiliency and Capacity in Southeast Asia. In The Palgrave Handbook on Cyber Diplomacy; Christou, G., Vosse, W., Burton, J., Koops, J.A., Eds.; Springer Nature: Cham, Switzerland, 2025; pp. 905–925. ISBN 978-3-031-93384-4. [Google Scholar]
- Ramadhan, I. ASEAN-China Cybersecurity Cooperation: Challenges and Opportunities. J. Soc. Political Sci. 2023, 6, 1–10. [Google Scholar] [CrossRef] [Scilit]
- Taeratanachai, C.; Wiriyakitjar, R. Cybersecurity Analysis in Thailand: Trends, Challenges, and Policy Insights from Case Studies of SMEs, Mobile Banking, and Port Infrastructure. Natl. Def. Stud. Inst. J. 2025, 16, 43–61. [Google Scholar]
- Tay, K.L. ASEAN Cyber-Security Cooperation: Towards a Regional Emergency-Response Framework; The International Institute for Strategic Studies: London, UK, 2023. Available online: https://www.iiss.org/research-paper/2023/06/asean-cyber-security-cooperation-towards-a-regional-emergency-response-framework/ (accessed on 18 March 2026).
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef] [Scilit]
- European Union. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on Measures for a High Common Level of Cybersecurity across the Union, Amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and Repealing Directive (EU) 2016/1148 (NIS 2 Directive). 2022. Available online: https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html (accessed on 7 June 2026).
- Rea-Guaman, A.M.; San Feliu, T.; Calvo-Manzano, J.A.; Sánchez-García, I.D. Systematic Review: Cybersecurity Risk Taxonomy. In Proceedings of the International Conference on Software Process Improvement; Springer: Berlin/Heidelberg, Germany, 2017; pp. 137–146. [Google Scholar]
- Rabitti, G.; Khorrami Chokami, A.; Coyle, P.; Cohen, R.D. A Taxonomy of Cyber Risk Taxonomies. Risk Anal. 2025, 45, 376–386. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Choo, K.-K.R. Organised Crime Groups in Cyberspace: A Typology. Trends Organ. Crime 2008, 11, 270–295. [Google Scholar] [CrossRef] [Scilit]
- Leukfeldt, E.R.; Kleemans, E.R.; Stol, W.P. A Typology of Cybercriminal Networks: From Low-Tech All-Rounders to High-Tech Specialists. Crime Law Soc. Chang. 2017, 67, 21–37. [Google Scholar] [CrossRef] [Scilit]
- Cohen, L.E.; Felson, M. Social Change and Crime Rate Trends: A Routine Activity Approach. Am. Sociol. Rev. 1979, 44, 588. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Harry, C.; Gallagher, N.W. Categorizing Cyber Effects. In The Elgar Companion to Digital Transformation, Artificial Intelligence and Innovation in the Economy, Society and Democracy; Carayannis, E., Grigoroudis, E., Campbell, D., Katsikas, S., Eds.; Edward Elgar Publishing: Cheltenham, UK, 2023; pp. 7–31. ISBN 978-1-83910-936-2. [Google Scholar]
- Harry, C.; Gallagher, N. Classifying Cyber Events. J. Inf. Warf. 2018, 17, 17–31. [Google Scholar]
- Harry, C.; Gallagher, N. Cyber Events Database (Version Date 2026-02-18). Available online: https://cissm.umd.edu/cyber-events-database (accessed on 25 February 2026).
- Gandhi, R.; Sharma, A.; Mahoney, W.; Sousan, W.; Zhu, Q.; Laplante, P. Dimensions of Cyber-Attacks: Cultural, Social, Economic, and Political. IEEE Technol. Soc. Mag. 2011, 30, 28–38. [Google Scholar] [CrossRef] [Scilit]
- González-Manzano, L.; De Fuentes, J.M.; Ramos, C.; Sánchez, Á.; Quispe, F. Identifying Key Relationships Between Nation-State Cyberattacks and Geopolitical and Economic Factors: A Model. Secur. Commun. Netw. 2022, 2022, 1–11. [Google Scholar] [CrossRef] [Scilit]
- Alcaide, J.I.; Llave, R.G. Critical Infrastructures Cybersecurity and the Maritime Sector. Transp. Res. Procedia 2020, 45, 547–554. [Google Scholar] [CrossRef] [Scilit]
- Farahbod, K.; Shayo, C.; Varzandeh, J. Cybersecurity Indices and Cybercrime Annual Loss and Economic Impacts. J. Bus. Behav. Sci. 2020, 32, 63–71. [Google Scholar]
- Grant Thornton. The Economic Cost of Cybercrime; Grant Thornton: Dublin, Ireland, 2021. [Google Scholar]
- Bruce, M.; Lusthaus, J.; Kashyap, R.; Phair, N.; Varese, F. Mapping the Global Geography of Cybercrime with the World Cybercrime Index. PLoS ONE 2024, 19, e0297312. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Dixon Analyzing Cyberattacks in the Maritime Domain Using Hierarchical Clustering and Descriptive Statistics. J. Territ. Marit. Stud. 2025, 12, 7–33. [CrossRef] [Scilit]
- Finlay, L.; Payne, C. The Attribution Problem and Cyber Armed Attacks. AJIL Unbound 2019, 113, 202–206. [Google Scholar] [CrossRef] [Scilit]
- Richey, M. Cyber Offence Dominance, Regional Dynamics, and Middle Power–Led International Cooperation. In Cybersecurity Policy in the EU and South Korea from Consultation to Action: Theoretical and Comparative Perspectives; Boulet, G., Reiterer, M., Pardo, R.P., Eds.; New Security Challenges; Springer International Publishing: Cham, Switzerland, 2022; ISBN 978-3-031-08383-9. [Google Scholar]
- Rid, T.; Buchanan, B. Attributing Cyber Attacks. J. Strateg. Stud. 2015, 38, 4–37. [Google Scholar] [CrossRef] [Scilit]
- Chen, S.; Hao, M.; Ding, F.; Jiang, D.; Dong, J.; Zhang, S.; Guo, Q.; Gao, C. Exploring the Global Geography of Cybercrime and Its Driving Forces. Humanit. Soc. Sci. Commun. 2023, 10, 71. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Kshetri, N. Diffusion and Effects of Cyber-Crime in Developing Economies. Third World Q. 2010, 31, 1057–1079. [Google Scholar] [CrossRef] [Scilit]
- Kumar, S.; Carley, K.M. Approaches to Understanding the Motivations Behind Cyber Attacks. In Proceedings of the 2016 IEEE Conference on Intelligence and Security Informatics (ISI); IEEE: Tucson, AZ, USA, 2016; pp. 307–309. [Google Scholar]
- Srivastava, S.K.; Das, S.; Udo, G.J.; Bagchi, K. Determinants of Cybercrime Originating within a Nation: A Cross-Country Study. J. Glob. Inf. Technol. Manag. 2020, 23, 112–137. [Google Scholar] [CrossRef] [Scilit]
- Hunter, L.Y.; Albert, C.D.; Garrett, E. Factors That Motivate State-Sponsored Cyberattacks. Cyber Def. Rev. 2021, 6, 111–128. [Google Scholar]
- Office of the National Security Council Thailand. National Security Policy and Plan B.E. 2566–2570 (2023–2027) 2022. Available online: https://www.nsc.go.th/wp-content/uploads/2023/09/ExecutiveSummaryEN.pdf (accessed on 24 February 2026).
- Mongkolnchaiarunya, J. The Trouble with Thailand’s New Cyber Approach. The Diplomat. 2016. Available online: https://thediplomat.com/2016/08/the-trouble-with-thailands-new-cyber-approach/ (accessed on 24 February 2026).
- Limna, P.; Kraiwanit, T.; Siripipattanakul, S. The Relationship between Cyber Security Knowledge, Awareness and Behavioural Choice Protection among Mobile Banking Users in Thailand. Int. J. Comput. Sci. Res. 2023, 7, 1133–1151. [Google Scholar] [CrossRef] [Scilit]
- Sriyai, S. Analysis of Cyber Attacks in Southeast Asia: Strategic Dynamics, Policy Gaps, and Recommendations. ISEAS Perspective. 2025. Available online: https://www.iseas.edu.sg/wp-content/uploads/2025/11/ISEAS_Perspective_2025_104.pdf (accessed on 18 March 2026).
- Pimple, K.D. Routine Activity Theory and Research Ethics: A Criminological Approach; Colorado State University Libraries: Fort Collins, CO, USA, 2016. [Google Scholar]
- Leukfeldt, E.R.; Yar, M. Applying Routine Activity Theory to Cybercrime: A Theoretical and Empirical Analysis. Deviant Behav. 2016, 37, 263–280. [Google Scholar] [CrossRef] [Scilit]
- Yar, M. The Novelty of ‘Cybercrime’: An Assessment in Light of Routine Activity Theory. Eur. J. Criminol. 2005, 2, 407–427. [Google Scholar] [CrossRef] [Scilit]
- Vakhitova, Z.I. Cyber-Routine Activity Theory. In Oxford Research Encyclopedia of Criminology and Criminal Justice; Pontell, H.N., Ed.; Oxford University Press: New York, NY, USA, 2025; ISBN 978-0-19-785140-1. [Google Scholar]
- Bossler, A.M.; Holt, T.J. On-Line Activities, Guardianship, and Malware Infection: An Examination of Routine Activities Theory. Int. J. Cyber Criminol. 2009, 3, 400–420. [Google Scholar]
- Boutemeur, J.; Lella, I.; Bakatsis, I.; Chatzichristos, G.; Foley, K.; Leskinen, J.; Otcenasek, J.; Ziolek, D. ENISA Threat Landscape 2025; European Union Agency for Cybersecurity (ENISA): Attiki, Greece, 2025; Available online: https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf (accessed on 2 March 2026).
- European Union Agency for Cybersecurity. ENISA Threat Landscape 2024: July 2023 to June 2024; Lella, I., Theocharidou, M., Magonara, E., Malatras, A., Naydenov, R.S., Ciobanu, C., Chatzichristos, G., Eds.; European Union Agency for Cybersecurity (ENISA): Luxembourg, 2024. [Google Scholar]
- Filho, D.B.F.; Rocha, E.C.D.; Júnior, J.A.D.S.; Paranhos, R.; Silva, M.B.D.; Duarte, B.S.F. Cluster Analysis for Political Scientists. Appl. Math. 2014, 05, 2408–2415. [Google Scholar] [CrossRef]
- Wolfson, M.; Madjd-Sadjadi, Z.; James, P. Identifying National Types: A Cluster Analysis of Politics, Economics, and Conflict. J. Peace Res. 2004, 41, 607–623. [Google Scholar] [CrossRef] [Scilit]
- Jang, J.; Hitchcock, D.B. Model-Based Cluster Analysis of Democracies. J. Data Sci. 2021, 10, 297–319. [Google Scholar] [CrossRef] [Scilit]
- Arbolino, R.; Carlucci, F.; Cirà, A.; Ioppolo, G.; Yigitcanlar, T. Efficiency of the EU Regulation on Greenhouse Gas Emissions in Italy: The Hierarchical Cluster Analysis Approach. Ecol. Indic. 2017, 81, 115–123. [Google Scholar] [CrossRef] [Scilit]
- Majcherek, D.; Hegerty, S.W.; Kowalski, A.M.; Lewandowska, M.S.; Dikova, D. Opportunities for Healthcare Digitalization in Europe: Comparative Analysis of Inequalities in Access to Medical Services. Health Policy 2024, 139, 104950. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Esnault, C.; Rollot, M.; Guilmin, P.; Zucker, J.-D. Qluster: An Easy-to-Implement Generic Workflow for Robust Clustering of Health Data. Front. Artif. Intell. 2023, 5, 1055294. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Berles, P.; Wölfer, J.; Alfieri, F.; Botton-Divet, L.; Guéry, J.-P.; Nyakatura, J.A. Linking Morphology, Performance, and Habitat Utilization: Adaptation Across Biologically Relevant ‘Levels’ in Tamarins. BMC Ecol. Evol. 2024, 24, 22. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Husson, F.; Josse, J.; Pages, J. Principal Component Methods-Hierarchical Clustering-Partitional Clustering: Why Would We Need to Choose for Visualizing Data. Tech. Rep.-Agrocampus. 2010. Available online: http://factominer.free.fr/more/HCPC_husson_josse.pdf (accessed on 2 March 2026).
- Watanabe, S. Strategic Analysis of Capacity Building for the Cyber Security of the United States in Asia. J. Asia Pac. Stud. 2020, 4, 100–111. [Google Scholar] [CrossRef] [Scilit]
- Tarrow, S.G. Power in Movement: Social Movements and Contentious Politics, 3rd ed.; Cambridge University Press: Cambridge, UK, 2011; ISBN 978-0-521-19890-5. [Google Scholar]
- Jaydn; Skidmore, M.; Medail, C. The Role of Social Media and Disruptive Technologies in Post-Coup Democracy Activism. In After the Coup: Myanmar’s Political and Humanitarian Crises; Ware, A., Skidmore, M., Eds.; ANU Press: Canberra, Australia, 2023; pp. 47–70. ISBN 978-1-76046-613-8. [Google Scholar]
- Brown, J.M.; Fazal, T.M. #SorryNotSorry: Why States Neither Confirm nor Deny Responsibility for Cyber Operations. Eur. J. Int. Secur. 2021, 6, 401–417. [Google Scholar] [CrossRef] [Scilit]
- Baram, G.; Sommer, U. Covert or Not Covert: National Strategies During Cyber Conflict. In Proceedings of the 2019 11th International Conference on Cyber Conflict (CyCon); IEEE: Tallinn, Estonia, 2019; pp. 1–16. [Google Scholar]
- Cirincione, G.H.; Verma, D. Federated Machine Learning for Multi-Domain Operations at the Tactical Edge. In Proceedings of the Artificial Intelligence and Machine Learning for Multi-Domain Operations Applications; Pham, T., Ed.; SPIE: Baltimore, MD, USA, 2019; p. 73. [Google Scholar]
- Lee, Y.; Park, T.; Lee, Y.; Gong, J.; Kang, J. Exploring Potential Prompt Injection Attacks in Federated Military LLMs and Their Mitigation. In Proceedings of the 2025 IEEE International Conference on Big Data (BigData), Macau, China, 8–11 December 2025. [Google Scholar]
- Sharma, S.; Guleria, K. A Federated Learning Mechanism for Preserving Security of Sensitive Data. In Proceedings of the 2023 4th International Conference on Data Analytics for Business and Industry (ICDABI); IEEE: Manama, Bahrain, 2023; pp. 1–5. [Google Scholar]
- Tanveer, F.; Iradat, F.; Iqbal, W.; Alsagri, H.S.; Alhakbani, H.A.A.; Ahmad, A.; Khan, F.A. Balancing Privacy and Performance in Healthcare: A Federated Learning Framework for Sensitive Data. Digit. Health 2025, 11, 20552076251381769. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Husson, F.; Josse, J. Multivariate Data Analysis: Special Focus on Clustering and Multiway Methods. Presented at useR, Gaithersburg, MD, USA, 21–23 July 2010; Available online: https://www.r-project.org/conferences/useR-2010/tutorials/Husson+Josse.pdf (accessed on 2 March 2026).
- Husson, F. Package ‘FactoMineR’: Multivariate Exploratory Data Analysis and Data Mining 2026, Version 2.13; CRAN: Vienna, Austria, 2026. Available online: https://cran.r-project.org/web/packages/FactoMineR/FactoMineR.pdf (accessed on 3 June 2026).
- Husson, F.; Le, S.; Pagès, J. Exploratory Multivariate Analysis by Example Using R, 2nd ed.; Chapman & Hall/CRC Computer Science and Data Analysis Series; CRC Press/Taylor & Francis Group: Boca Raton, FL, USA; London, UK; New York, NY, USA, 2017; ISBN 978-1-138-19634-6. [Google Scholar]






| Variable | Definition |
|---|---|
| Year | year event occurred |
| Actor | organisation or individual responsible for the event |
| Actor Country | actor’s location |
| Actor Type | nature of the actor responsible for the event |
| Organisation | target organisation whose networks were illicitly breached |
| Industry Name | sector/industry of the target organisation |
| Motive | intended results sought by the actor committing the event |
| Event Type | primary end effects of the event |
| Event Sub-Type 1 & Event Sub-Type 2 | detailed classification of the nature of an event based on the part of the target organisation’s IT infrastructure that was most seriously impacted, regardless of the tactics or techniques used to achieve the final result |
| Variable | Chi-Square | df | p-Value | Adjusted Cramer’s V | Min Expected | Expected Cells Below 5 |
|---|---|---|---|---|---|---|
| Actor Country | 74.83 | 10 | <0.001 | 0.65 | 0.06 | 16 |
| Actor Type | 135.64 | 6 | <0.001 | 0.92 | 0.32 | 8 |
| Event Type | 17.97 | 6 | 0.009 | 0.28 | 0.13 | 8 |
| Event Subtype 1 | 69.37 | 12 | <0.001 | 0.61 | 0.13 | 17 |
| Motive | 134.11 | 6 | <0.001 | 0.92 | 0.38 | 7 |
| Year | 57.90 | 20 | <0.001 | 0.50 | 0.06 | 29 |
| Industry | 48.53 | 30 | 0.036 | 0.35 | 0.06 | 45 |
| Event Subtype 2 | 1.16 | 2 | 0.684 | <0.001 | 0.45 | 4 |
| Cluster | Variable/Category | Cla/Mod | Mod/Cla | Global | p-Value | v-Test |
|---|---|---|---|---|---|---|
| 1 (Financial Crime) | actor_type_Criminal | 100.0 | 94.1 | 61.5 | <0.001 | 8.6 |
| motive_Financial | 100.0 | 86.3 | 56.4 | <0.001 | 7.8 | |
| actor_country_Undetermined | 73.1 | 96.1 | 85.9 | 0.001 | 3.3 | |
| event_subtype_1_Data Attack | 100.0 | 25.5 | 16.7 | 0.002 | 3.1 | |
| industry_Finance and Insurance | 100.0 | 17.6 | 11.5 | 0.017 | 2.4 | |
| year_2022 | 92.3 | 23.5 | 16.7 | 0.024 | 2.3 | |
| year_2023 | 100.0 | 13.7 | 9.0 | 0.044 | 2.0 | |
| motive_Political-Espionage | 16.7 | 2.0 | 7.7 | 0.018 | −2.4 | |
| actor_type_Nation-State | 16.7 | 2.0 | 7.7 | 0.018 | −2.4 | |
| actor_country_Thailand | 0.0 | 0.0 | 5.1 | 0.012 | −2.5 | |
| actor_country_China | 0.0 | 0.0 | 5.1 | 0.012 | −2.5 | |
| event_type_Disruptive | 20.0 | 3.9 | 12.8 | 0.003 | −3.0 | |
| event_subtype_1_External Denial of Service | 0.0 | 0.0 | 11.5 | <0.001 | −4.2 | |
| year_2016 | 0.0 | 0.0 | 15.4 | <0.001 | −5.1 | |
| industry_Public Administration | 22.2 | 11.8 | 34.6 | <0.001 | −5.8 | |
| actor_type_Hacktivist | 0.0 | 0.0 | 24.4 | <0.001 | −7.0 | |
| motive_Protest | 0.0 | 0.0 | 25.6 | <0.001 | −7.2 | |
| 2 (Hacktivism) | motive_Protest | 100.0 | 90.9 | 25.6 | <0.001 | 8.3 |
| actor_type_Hacktivist | 100.0 | 86.4 | 24.4 | <0.001 | 7.9 | |
| year_2016 | 100.0 | 54.5 | 15.4 | <0.001 | 5.7 | |
| industry_Public Administration | 66.7 | 81.8 | 34.6 | <0.001 | 5.3 | |
| event_subtype_1_External Denial of Service | 100.0 | 40.9 | 11.5 | <0.001 | 4.7 | |
| event_type_Disruptive | 80.0 | 36.4 | 12.8 | <0.001 | 3.5 | |
| industry_Finance and Insurance | 0.0 | 0.0 | 11.5 | 0.042 | −2.0 | |
| year_2024 | 6.7 | 4.5 | 19.2 | 0.037 | −2.1 | |
| event_subtype_1_Data Attack | 0.0 | 0.0 | 16.7 | 0.009 | −2.6 | |
| year_2022 | 0.0 | 0.0 | 16.7 | 0.009 | −2.6 | |
| motive_Financial | 0.0 | 0.0 | 56.4 | <0.001 | −6.6 | |
| actor_type_Criminal | 0.0 | 0.0 | 61.5 | <0.001 | −7.3 | |
| 3 (Political Espionage) | motive_Political-Espionage | 83.3 | 100.0 | 7.7 | <0.001 | 5.1 |
| actor_type_Nation-State | 83.3 | 100.0 | 7.7 | <0.001 | 5.1 | |
| actor_country_China | 100.0 | 80.0 | 5.1 | <0.001 | 4.6 | |
| event_subtype_1_Exploitation of End Hosts | 100.0 | 40.0 | 2.6 | 0.003 | 2.9 | |
| motive_Financial | 0.0 | 0.0 | 56.4 | 0.013 | −2.5 | |
| actor_type_Criminal | 0.0 | 0.0 | 61.5 | 0.007 | −2.7 | |
| actor_country_Undetermined | 0.0 | 0.0 | 85.9 | <0.001 | −4.2 |
| k | Cluster | Mean Jaccard | Times Dissolved | Times Recovered | Stability | Dissolution Rate | Recovery Rate |
|---|---|---|---|---|---|---|---|
| 2 | Cluster 1 | 0.888 | 50 | 88,899 | Highly stable | 0.0005 | 0.889 |
| Cluster 2 | 0.311 | 75,237 | 17,750 | Unstable | 0.75237 | 0.178 | |
| 3 | Cluster 1 | 0.773 | 749 | 65,122 | Stable | 0.00749 | 0.651 |
| Cluster 2 | 0.529 | 52,435 | 39,661 | Unstable | 0.52435 | 0.397 | |
| Cluster 3 | 0.323 | 78,823 | 7395 | Unstable | 0.78823 | 0.074 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Dixon, J.; Ruangsuwan, C.; Sereewatthanawut, I. Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation. J. Cybersecur. Priv. 2026, 6, 124. https://doi.org/10.3390/jcp6040124
Dixon J, Ruangsuwan C, Sereewatthanawut I. Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation. Journal of Cybersecurity and Privacy. 2026; 6(4):124. https://doi.org/10.3390/jcp6040124
Chicago/Turabian StyleDixon, Jevon, Charupol Ruangsuwan, and Issara Sereewatthanawut. 2026. "Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation" Journal of Cybersecurity and Privacy 6, no. 4: 124. https://doi.org/10.3390/jcp6040124
APA StyleDixon, J., Ruangsuwan, C., & Sereewatthanawut, I. (2026). Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation. Journal of Cybersecurity and Privacy, 6(4), 124. https://doi.org/10.3390/jcp6040124

