Who will be Vietnam's cyber security protection force?

Resources
    Who will be Vietnam's cyber security protection force?
    Posted on: 22/04/2026

    The explosion of cyberspace in recent years has become a critical environment for state management, socio-economic development, national defense and security. However, along with the great benefits is the increasingly complex development of the cybersecurity situation. Acts of attack, illegal intrusion and data theft are on the rise, directly threatening national security and social order and safety.

     

    The cyber security protection force is the core force in the system of cyber security protection forces, organized uniformly from the central to the local level. 

     

    Practice shows that the current legal system only stops at stipulating general principles and orientations, while some important contents related to the cyber security protection force have not been specifically and synchronously regulated.

    On that basis, the Ministry of Public Security has submitted to the Government the Draft Decree on the Cyber Security Protection Force ("Draft") which is expected to be issued and take effect from July 1, 2026.

    Who is the Cybersecurity Protection Force?

    In Article 3.1 of the Draft, the cyber security protection force is determined to consist of three components: a full-time force, a standing force and a reserve force.

    The above regulation is essentially standardizing and fully clarifying the composition of the cyber security protection force in legal terms, thereby forming a unified organizational model to be applied in practice. If in the past, the awareness and organization of implementation were still scattered and not really clear between the core forces, forces regularly deployed at agencies, organizations, enterprises and forces mobilized when necessary, the Draft has more specifically delineated the position of each force in a unified whole.

    Firstly, the specialized security protection force

    The cyber security protection force is the core force in the system of cyber security protection forces, organized uniformly from the central to the local level. According to the Draft, this force includes specialized units deployed at the Ministry of Public Security (such as the Department of Cyber Security and High-tech Crime Prevention and Combat and corresponding units at the provincial police) and units under the Ministry of National Defense (including the Military Security Protection Department and the Cyber Warfare Command). With a key position, this force is prioritized in terms of resources, equipment and intensive training, thereby ensuring the role of leading, administering and effectively maintaining Vietnam's cyber security protection.

    Secondly, the standing security guard

    The Standing Cyber Security Protection Force in Vietnam is a force deployed in ministries, branches, localities, agencies, organizations and enterprises to directly protect information systems and databases under their management. This is a force that operates regularly and continuously with tasks such as cyber security monitoring, risk management, access control, incident detection and handling, and coordinates with authorities in rescue and reporting. Depending on the size and importance of the system, this force can be organized in the form of specialized units, full-time personnel, or hiring services from cybersecurity businesses. The formation of the standing force shows that Vietnam is building a cyber security protection mechanism in a proactive and on-site direction, associated with the responsibilities of each agency, organization and business in ensuring information and data security.

    Third, the security protection reserve force

     Cyber security protection reserve forces in Vietnam are organizations and individuals that are not part of the full-time or permanent forces but are mobilized to participate in cyber security protection when necessary in accordance with law.

    The construction of this force prioritizes businesses and organizations with capabilities in information and communication technology in cyberspace as well as officers, non-commissioned officers and conscripts in the Public Security and Army. The construction of the reserve force shows Vietnam's flexible approach to cyber security protection, taking advantage of social resources to provide timely and effective support when they arise practical requirements.    

    Requirements for individuals to join the cyber security protection force of the Draft

    Article 7 of the Draft has set general standards for individuals who want to join the cyber security protection force, including: (i) Having good political and moral qualities and a sense of discipline; (ii) There is no conflict of interest as prescribed by law and (iii) Having professional capacity suitable to the assigned job position, title or task.  Professional competence needs to be specifically determined through the competency framework, the system of diplomas, certificates as well as experience issued by the competent authority. At the same time, to limit risks arising from key positions (such as individuals having access to critical information systems,  sensitive data or participation in digital investigation activities), the regulatory agency must conduct reliability due diligence, control conflicts of interest and manage access rights according to the minimum principle. In addition, the efficiency and quality of the work performance of this force also need to be periodically evaluated as a mandatory requirement.

    Although the Draft has initially established a basic standard framework, from the perspective of legal practice and risk management, these regulations still need to be improved to ensure feasibility and adequacy.

    It is necessary to clarify the standard of "No conflict of interest"

    Specified in Article 7.1. (b) The draft is currently quite qualitative. In the practice of cybersecurity, an expert can both work at a state agency and participate in professional consulting for businesses. In order to avoid problems in recruiting and attracting talents, the Draft needs to add a clear definition of what is a "conflict of interest" right in the explanation of the term, or refer specifically to other specific regulations. In case it is not possible to specify in detail, the authority should be assigned to the management agency to promulgate a specific set of evaluation criteria to ensure transparency and consistency in the application process.

    Tightening internal risk control

    The provisions in Article 7.3 of the Draft currently stop at the requirement of "reliability appraisal" with a rather general content, not fully reflecting the level of risk in practice. For personnel who hold admin access to sensitive data, the risk of information leakage from within is particularly great. Therefore, it is necessary to supplement mandatory regulations on the mechanism of "periodic personnel security appraisal" to ensure that supervision is carried out continuously, instead of only focusing on the entry stage.

    In addition, the Draft also needs to establish stricter legal constraints related to information confidentiality obligations after personnel leave their jobs or transfer jobs to create a closed protection mechanism.

     

    Prime Minister Pham Minh Chinh visits and works at the Department of Cyber ​​Security and Prevention of High-Tech Crimes. Source: Ministry of Public Security

     

    Roles and responsibilities of the cyber security protection force

    The draft has established a relatively clear framework for the organization and assignment of tasks among cybersecurity protection forces.

    For specialized forces

    This is the core force of cyber security protection, uniformly organized from the central to the local level, performing the function of policy advice, state management, organizing the implementation of cyber security protection measures, coordinating, inspecting, guiding, training, rehearsing, etc  respond to incidents and perform other tasks as prescribed by law (Article 4).

    For standing forces

     Standing forces are forces arranged at ministries, branches, localities, agencies, organizations and enterprises to directly protect cyber security for information systems and databases under their management; supervise, manage risks, control access, report incidents, coordinate rescue and ensure regular and continuous operations (Article 5).

    For reservists

    Reserve forces are organizations and individuals that do not belong to the two forces mentioned above but are mobilized to participate in cyber security protection in accordance with law, especially in cases where it is necessary to increase resources, expertise, technology or support in handling complex situations. (Article 6).

    The role of cyber security protection forces does not only stop at performing independent tasks, but is also expanded through a close coordination mechanism between forces. This coordination needs to ensure timeliness and effectiveness, and at the same time comply with the functions and authority of each subject. In addition, information sharing activities must be strictly controlled in terms of purposes and users; in particular, it is forbidden to cause unlawful disruption to the normal operation of agencies, organizations and enterprises.

    Challenges and opportunities for cybersecurity protection forces

    Currently, the cyber security protection force performs tasks of a specific nature, with high requirements on expertise, techniques, security, large working intensity, high pressure and responsibility. Meanwhile, the current salary, allowance and bonus regime does not fully reflect this specific characteristic, affecting work motivation and the ability to retain human resources. Faced with this situation, the Draft has proposed to develop a mechanism for policies on salaries, allowances and bonuses for cyber security protection forces (Article 14) and policies on salaries, remuneration and income for those who are attracted and employed and those who sign contracts to perform important tasks.  strategies on cyber security protection (Article 18).

    These policies, although they may increase state budget spending; comparisons and differences between forces and units may arise if the criteria for determining the subjects and the level of benefits are not clear, but contribute to improving work motivation, retaining a team with high professional qualifications, limiting the situation of moving to areas with better income levels.

    This is a policy that comes from the very specific requirements of cyber security protection. The current digital technology labor market has very strong competition for high-quality human resources, especially human resources with in-depth capabilities in cybersecurity, digital investigation, cyber attack prevention, incident response, data protection and critical system operation. If salary, allowances and bonuses are still applied as a general mechanism, it is very difficult for the public sector to compete to attract, retain and develop this strategic workforce. Therefore, higher remuneration is not a widespread incentive, but only a necessary fee to maintain the national cyber security defense capacity.

    In summary, the formulation and promulgation of the Decree regulating the cyber security protection force is necessary in order to fully and promptly institutionalize the Party's guidelines and guidelines on protecting national security, cyber security, developing high-quality human resources and promoting innovation in the field of science and technology.  technology, national digital transformation. In addition, this will contribute to strengthening and perfecting the legal basis, thoroughly solving current inadequacies and gaps, thereby improving the feasibility in the process of organizing the implementation of the Law on Cyber Security 2025 which will take effect from July 1, 2026.