Read Time
Categories
Share
Ten layers of cyber security for Indonesian banks, insurers and multifinance companies, each paired with the document an examiner asks for, the rule behind it, its owner and its deadline.

For an Indonesian bank, insurer or multifinance company, the useful types of cyber security are 10 layers of protection, and each one has a document an examiner will ask for: from an SMPI certificate valid for at most 3 years (BSSN Regulation 8/2020) to a 1-hour incident notice to Bank Indonesia (PBI 2/2024). SEOJK 29/SEOJK.03/2022 alone contains 80 cyber security controls, and its assessment worksheet asks for a "Referensi Dokumen" (document reference) against every one of them. The list below maps each layer to its rule, its owner on the buying committee, its deadline, and the question to put to a vendor.

Most "types of cyber security" lists name 3 to 8 categories (network, cloud, endpoint, application) and stop there, with no reference to OJK, BI or Indonesia's Personal Data Protection Law (UU PDP). This one is for compliance, internal audit (SKAI) and the CISO: the people who end up across the table from the examiner. Every article below is quoted from the official text we link to, and we re-checked the incident clocks and the January deadlines against it on 25 September 2026.

The map: 10 layers, their rules and the proof each one needs

#LayerPrimary ruleProof documentOwnerClock / cycle
1Governance / ISMSBSSN Reg. 8/2020 Art. 9(1), 28SNI ISO/IEC 27001 or SMPI certificate + Statement of ApplicabilityCISO3 years; renew 3 months before expiry
2Cyber risk management / maturityPOJK 11/POJK.03/2022 Art. 22Self-assessment of inherent risk and maturity (SEOJK 29, Annex II)Cyber security unit31 December position, filed in the LKTPTI by 21 January
3Vulnerability managementSEOJK 29 Ch. VII item 2; PBI 2/2024 Art. 30(c)Continuous scan logs, findings register with closure evidenceIT operations + cyber unitContinuous
4Application security / pentestPOJK 11 Art. 23–24; POJK 21/2023 Art. 13(3)–(4)Pentest report + retest evidence; independent third-party opinionCyber unit, never the build teamCompiled into the LKTPTI by 21 January
5Personal data protectionLaw 27/2022 Art. 34, 35, 46DPIA, record of processing, breach notification lettersCompliance / data protection officer3×24 hours from the failure
6Incident detection and responsePOJK 11 Art. 60; PBI 2/2024 Art. 40Initial notice and incident report (SEOJK 29 Annex IV format)Head of the cyber unit1 hour to 5 working days
7Scenario-based testingPOJK 11 Art. 25Test results report (SEOJK 29 Annex VI format)Cyber unitAt least yearly; report within 10 working days
8Resilience / DRPPOJK 11 Art. 18(3)DRP test report showing IT users took partHead of IT + business unitsAt least yearly
9Third parties / vendorsPOJK 11 Art. 30(3), 32(2)Contract with audit clause; vendor's IT audit resultsProcurement + ITReport within 3 working days if a vendor fails
10Data location / cloudPOJK 11 Art. 35Register of data centre and DRC locations; OJK approval if offshoreCTO + complianceBefore placement

The "Owner" column is our suggestion, not the regulator's. The SEOJK 29 worksheet has its own column for the responsible department, unit or position, so each bank fills in its own names, and those names are what the examiner reads.

Each layer in detail, with the vendor question

1. Governance and the ISMS

BSSN Regulation 8/2020 (16 November 2020), Article 9(1), requires strategic electronic systems to implement SNI ISO/IEC 27001. The Indonesian SMPI certificate lasts at most 3 years and must be renewed no later than 3 months before it expires (Article 28). How to test a vendor's certificate is covered in our ISO 27001 certification vendor check.

Ask the vendor for: the certificate number, the certification body, the scope, and a Statement of Applicability that names the system you'll actually use.

2. Cyber risk management and maturity

POJK 11/POJK.03/2022 (6 July 2022), Article 22(2), requires the maturity assessment annually, as at the end of December. The unit doing the assessing must be independent of IT management (Article 26(2)), so the Head of IT can't mark their own homework.

Ask the vendor for: the documents you could enter in the document-reference column for every control that touches their system.

3. Vulnerability management

SEOJK 29/SEOJK.03/2022 (27 December 2022), Chapter VII item 2, says this testing starts with vulnerability identification and is then followed by a penetration test. Scanning on its own meets only the continuous-detection control. The price and scope gap between the two is in vulnerability assessment vs penetration testing cost.

Ask the vendor for: scan frequency, a closure SLA per severity level, and the findings register for the last 12 months.

4. Application security and penetration testing

The elucidation of POJK 11 Article 24(1) names the penetration test as an example of vulnerability-based testing. For a new digital service, POJK 21/2023 (19 December 2023), Article 13(4)(a), requires an opinion from an independent party outside the bank. For added features an internal party may do it, as long as they took no part in design or development. In plain terms, the team that built the channel doesn't get to test it. What the statement of work has to say is in the penetration testing scope of work for banks; the web basics are in our website security guide.

Ask the vendor for: the box type (white, grey or black) and the test environment (development or production). The LKTPTI format in PADK 1/2026 asks for both.

5. Personal data protection

Law 27/2022 on Personal Data Protection (17 October 2022), Article 46(1), gives 3×24 hours to notify data subjects and the supervisory agency in writing. The administrative fine tops out at 2% of annual revenue "against the variable of the violation" (Article 57(3)), not 2% of total revenue. What the notice must contain, and what triggers a DPIA, is in DPIA in Indonesia under Article 34.

Ask the vendor for: how many hours after finding a failure they'll tell you, written into the contract.

6. Incident detection and response

This layer carries the tightest clock on the list; the ladder is set out below. SEOJK 29 Chapter VIII requires an incident response team, and Annex IV gives the format for both the notice and the report.

Ask the vendor for: the name and 24-hour number of the person who'll call your cyber unit within minutes, not days.

7. Scenario-based testing

POJK 11 Article 25(1) requires scenario testing "at least 1 (one) time in 1 (one) year", and the report reaches OJK within 10 working days of the test finishing (Article 25(3)). SEOJK 29 Chapter VII item 4 defines when a test counts as finished: when its results report is complete. The elucidation of Article 25(1) gives table-top exercises and cyber range exercises as examples.

Ask the vendor for: a commitment to join your yearly table-top exercise with the people who actually run the system.

8. Resilience and disaster recovery

POJK 11 Article 18(3) requires a DRP test of every critical application and piece of infrastructure at least once a year, involving IT users. A test run only by the infrastructure team doesn't meet that sentence.

Ask the vendor for: the RTO and RPO proven in the last test, not the ones in the brochure.

9. Third parties and vendors

POJK 11 Article 30(3)(c) requires the vendor to commit to delivering periodic IT audit results from an independent auditor, and point (i) gives OJK access. If a vendor fails, the bank reports to OJK within 3 working days (Article 32(2)(a)).

Ask the vendor for: their latest independent IT audit report, and written consent for OJK to examine them.

10. Data location and cloud

POJK 11 Article 35(1) requires banks to place electronic systems in a data centre and disaster recovery centre within Indonesian territory. Offshore placement needs OJK approval (Article 35(2)). For a bank inside a regional group, that covers a group shared-services platform too, if it runs from Singapore or Kuala Lumpur.

Ask the vendor for: the cloud region for production data and for backups. Both, not just production.

The incident clock ladder: 1 hour to 5 working days

A single incident in the app of a bank that's also a payment service provider starts five clocks at once. The fastest one sets the real deadline: POJK 11 Article 60(4) requires the bank to notify OJK "at the same time" when another authority's deadline is shorter. So OJK's 24 hours collapses to 1 hour.

ClockObligationLegal basisCounted from
1 hourInitial notice to BIPBI 2/2024 Art. 40(b)(1); PADG 24/2024 Art. 45(2)(b)(1)Incident becomes known
24 hoursInitial notice to OJK (banks)POJK 11 Art. 60(1)(a)Incident becomes known
3×24 hoursWritten notice to data subjects and the agencyUU PDP Art. 46(1)The law doesn't say
3 calendar daysIncident report to BIPBI 2/2024 Art. 40(b)(2)Incident occurs
5 working daysIncident report to OJK (banks)POJK 11 Art. 60(1)(b)Incident becomes known
5 working daysReport to OJK (insurers, multifinance)POJK 4/POJK.05/2021 Art. 31(2)Critical event becomes known

Two details get missed. BI's 3-day report runs from when the incident occurred, not when it was found, and the PADG 24/2024 FAQ answers "Tidak ada" (none) when asked about a public-holiday exception. An intrusion discovered on day three is effectively already late. BI's clock applies to a bank in its role as a payment service provider (PBI 2/2024 Article 5), and the same FAQ puts the late-filing penalty at up to Rp5,000,000 per report. The agency named in UU PDP Article 46(1) is to be created by presidential regulation; we couldn't verify from a primary source whether that regulation has been issued.

The annual evidence calendar for 2026–2027

Most of the annual evidence lands in the last ten days of January. We checked each date against Indonesia's 2027 joint decree on public holidays and collective leave:

  • 31 December 2026: the position date for the maturity assessment (POJK 11 Article 22(2)).
  • Thursday 21 January 2027: the annual IT report (LKTPTI) to OJK, carrying the compiled pentest results (PADK OJK 1/2026, issued 23 January 2026, Annex II A.3.c). Counting 15 working days under POJK 11 Article 59 would land on Monday 25 January 2027. PADK uses a fixed, earlier date. Use 21 January.
  • Friday 29 January 2027: the cyber security maturity report to BI, with supporting evidence attached, including the cyber audit report and the penetration test report (PADG 24/2024 Article 53). The nominal deadline is 31 January, a Sunday, so it moves back to the previous BI working day (Article 53(5)).
  • At least once during the year: scenario testing (POJK 11 Article 25), DRP testing (Article 18(3)), internal IT audit (Article 54), the cyber audit and the security awareness programme (PADG 24/2024 Articles 12(1) and 13(4)).
  • Every 3 years: external review of the internal IT audit function (POJK 11 Article 55(2)) and the SMPI certificate cycle.

The Q4 launch trap. This is our inference from the rules above, not a quoted article. A digital channel that goes live between October and December needs its final pentest report before mid-January to make the 21 January LKTPTI and the 29 January BI filing. If it's the bank's first digital service, the independent outside opinion under POJK 21/2023 has to exist before the licence.

SEOJK 29's 80 controls: what a certificate can't answer

We counted the controls in SEOJK 29's two control matrices, ID by ID, on 25 September 2026:

MatrixControlsBy domain
Annex I.b, risk management implementation56Governance 7 · framework 20 · process, people and systems 20 · internal control 9
Annex I.c, cyber resilience process24Identify 3 · protect 10 · detect 5 · respond and recover 6
Total80Each with a document-reference column in Annex II.b and II.c

That column is defined as the document that can serve as the reference for assessing whether the control is in place. An ISO 27001 certificate proves a management system exists and has been audited. It doesn't prove that the 5 detection controls and 6 response controls in Annex I.c were running last month. For those 11, the examiner will ask for logs, incident tickets and test reports.

Banks are not insurers or multifinance

The named pentest and scenario-testing duties sit in POJK 11, which covers banks. Insurers and multifinance companies fall under POJK 4/2021 (9 March 2021), which doesn't mention pentests and leaves DRP test frequency to the company's own written policy (Article 16(5)). Their incident report is due in 5 working days. UU PDP applies to everyone equally. At an insurer or multifinance company, what gets examined is the internal policy and the vendor contracts, so that's where the numbers above need to be written down.

What this means for the buying committee

  • Compliance and internal audit (SKAI): have the vendor fill in the 10-layer table above before contract, with document names rather than the word "available".
  • CISO: make sure the vendor contract sets a notification clock shorter than BI's 1 hour, not 24 hours.
  • Head of Digital: pull the pentest forward if launch falls in Q4.
  • Director: budget scenario testing, DRP testing and the cyber audit as a fixed yearly cost, not a project line.

Our view: if you only get to negotiate one clause before signing, make it the incident notification clock. A certificate can be requested later and an audit can be scheduled. A 24-hour clock already written into the contract can't be shortened once the incident has happened, and BI only gives you one hour.

Of the WEBARQ projects with published case studies, two touch the layers above. For CGS International, investor onboarding runs through a web form with OCR, plus video call and self-verification, connected to banks, CGS-CIMB, KSEI and Dukcapil, Indonesia's civil registry. For BCA Group, the CMS behind three divisional sites uses draft, preview, merge and multi-layer approval, which is maker-checker applied to content on a regulated channel. Both describe what the case studies say, not a claim of compliance with any particular rule. If you're preparing a digital channel and want this evidence list built in from the design stage, see our website development service.

Back to List