Vietnam Social Security (BHXH) has issued an official dispatch on strengthening network information security during the 2026 National Day holiday, from August 29th to the end of September 2nd.
Review vulnerabilities, tighten access accounts
Vietnam Social Security requires units to review and fully update security patches for servers, workstations, network equipment, security equipment and software within their management scope. In which, vulnerabilities and weaknesses assessed as serious or high levels must be prioritized for handling.
Units must overcome the loopholes, weaknesses and unsafe configurations that have been warned by functional agencies or Vietnam Social Security; and at the same time turn off or restrict unnecessary services and connection ports.
Servers and workstations must also be checked to detect and handle malware. Handling needs to be prioritized for devices, accounts, IP addresses or domain names in the list of malware warnings, botnets and information security warnings provided by Vietnam Social Security.
Along with that, units are required to review SSO user accounts, VPN accounts and administrator accounts, ensuring that accounts are issued to the right subjects, functions, tasks and scope of authority.
Accounts that no longer need to be used, whose managers cannot be identified, or have inappropriate access rights must be locked, recovered, or adjusted.
Cases of suspected leakage of authentication information, illegal use of accounts, spam distribution or use of unauthorized tools to access the system and exploit data must be handled promptly.
Be wary of tricks to impersonate social insurance agencies
Throughout the holiday, units must arrange forces to be on duty, monitor and supervise information systems, network equipment, security equipment and information security solutions within their management scope.
Monitoring access logs, unusual warnings, warnings from malware prevention and control systems and centralized information security monitoring systems must be strengthened. Thereby, promptly detect, prevent and handle signs of cyberattacks, scanning, exploiting vulnerabilities, illegal access, dissemination or encryption of data by malware and other unusual behaviors.
In the process of handling incidents, units must prioritize maintaining the operation of essential systems, minimizing the impact on professional operations.
Vietnam Social Security also requests officials and employees to raise their vigilance against forms of online fraud, impersonation of social insurance agencies; emails, text messages or forms of contact requesting to provide accounts, passwords, authentication codes or internal information.
Officials and employees are not allowed to open links or attached files of unknown origin; do not provide or share passwords, authentication codes and security information to others.
At the same time, do not use public equipment or unlicensed equipment to access the information systems and professional systems of Vietnam Social Security.
Units must assign full personnel to be on duty to manage the system, information security and leadership focal points during the holidays; maintain communication, ensure coordination capacity, and handle incidents when they arise.
When an incident occurs that may affect the information system or professional operations, the unit must proactively implement preventive measures, isolate, and report and coordinate with the Information Technology and Digital Transformation Center for handling.
In particular, Vietnam Social Security requires units not to arbitrarily delete, change or lose logbooks, data and electronic traces related to incidents. Information must be transferred to the Standing Committee of the Vietnam Social Security Network Information Security Incident Response Team and the Vietnam Social Security Information System Operation Center (NOC) for coordination in verification and handling.

