Directive 57-CT/TW: tightening data security in the state sector

In early 2026, the Secretariat issued Directive 57-CT/TW on strengthening cybersecurity, information security and data security across the political system. It is a top-level political signal on something already urgent: protecting the state sector's data.
Why this directive matters
- It makes data security a political task, not just IT's technical job.
- It comes as a chain of incidents on state systems shows real risk (see the CIC incident).
- It resonates with the 2025 Cybersecurity Law and PDPL — legal frame and directive tightening together.
What state agencies must do
- Classify and protect information systems by level (under the 2025 Cybersecurity Law).
- Manage access, least privilege and tight monitoring — identity is a top target.
- Keep sensitive data in controllable infrastructure; limit exposure.
Tetra
Manta Security centralizes device management, permissions and access monitoring; Tetra eOffice keeps documents in your systems. See also enterprise cyber defense. For advice, book a consultation.
Related articles

Securing Dokploy: adding a WAF and IPS on the server itself
A default Dokploy install runs fine but is not safe: Traefik is not a WAF, Docker bypasses UFW, DNS-only domains leak the origin IP. Three gaps and how to close them on your own host.
Read ↗
Vietnam's 2025 Cybersecurity Law: 5-level system classification and what to do
From 1 July 2026, Cybersecurity Law 116/2025 merges two prior laws, codifies "data security" and classifies systems into 5 levels. The new obligations and what to do.
Read ↗
Hansoll hit by ransomware: how manufacturing and FDI firms defend
The ransomware case targeting Hansoll Textile shows manufacturing and FDI firms are also targets. Practical defense lessons for manufacturers.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.