For an Indonesian bank, insurer or multifinance company, the useful types of cyber security are 10 layers of protection, and each one has a document an examiner will ask for: from an SMPI certificate valid for at most 3 years (BSSN Regulation 8/2020) to a 1-hour incident notice to Bank Indonesia (PBI 2/2024). SEOJK 29/SEOJK.03/2022 alone contains 80 cyber security controls, and its assessment worksheet asks for a "Referensi Dokumen" (document reference) against every one of them. The list below maps each layer to its rule, its owner on the buying committee, its deadline, and the question to put to a vendor.
Most "types of cyber security" lists name 3 to 8 categories (network, cloud, endpoint, application) and stop there, with no reference to OJK, BI or Indonesia's Personal Data Protection Law (UU PDP). This one is for compliance, internal audit (SKAI) and the CISO: the people who end up across the table from the examiner. Every article below is quoted from the official text we link to, and we re-checked the incident clocks and the January deadlines against it on 25 September 2026.
| # | Layer | Primary rule | Proof document | Owner | Clock / cycle |
|---|---|---|---|---|---|
| 1 | Governance / ISMS | BSSN Reg. 8/2020 Art. 9(1), 28 | SNI ISO/IEC 27001 or SMPI certificate + Statement of Applicability | CISO | 3 years; renew 3 months before expiry |
| 2 | Cyber risk management / maturity | POJK 11/POJK.03/2022 Art. 22 | Self-assessment of inherent risk and maturity (SEOJK 29, Annex II) | Cyber security unit | 31 December position, filed in the LKTPTI by 21 January |
| 3 | Vulnerability management | SEOJK 29 Ch. VII item 2; PBI 2/2024 Art. 30(c) | Continuous scan logs, findings register with closure evidence | IT operations + cyber unit | Continuous |
| 4 | Application security / pentest | POJK 11 Art. 23–24; POJK 21/2023 Art. 13(3)–(4) | Pentest report + retest evidence; independent third-party opinion | Cyber unit, never the build team | Compiled into the LKTPTI by 21 January |
| 5 | Personal data protection | Law 27/2022 Art. 34, 35, 46 | DPIA, record of processing, breach notification letters | Compliance / data protection officer | 3×24 hours from the failure |
| 6 | Incident detection and response | POJK 11 Art. 60; PBI 2/2024 Art. 40 | Initial notice and incident report (SEOJK 29 Annex IV format) | Head of the cyber unit | 1 hour to 5 working days |
| 7 | Scenario-based testing | POJK 11 Art. 25 | Test results report (SEOJK 29 Annex VI format) | Cyber unit | At least yearly; report within 10 working days |
| 8 | Resilience / DRP | POJK 11 Art. 18(3) | DRP test report showing IT users took part | Head of IT + business units | At least yearly |
| 9 | Third parties / vendors | POJK 11 Art. 30(3), 32(2) | Contract with audit clause; vendor's IT audit results | Procurement + IT | Report within 3 working days if a vendor fails |
| 10 | Data location / cloud | POJK 11 Art. 35 | Register of data centre and DRC locations; OJK approval if offshore | CTO + compliance | Before placement |
The "Owner" column is our suggestion, not the regulator's. The SEOJK 29 worksheet has its own column for the responsible department, unit or position, so each bank fills in its own names, and those names are what the examiner reads.
BSSN Regulation 8/2020 (16 November 2020), Article 9(1), requires strategic electronic systems to implement SNI ISO/IEC 27001. The Indonesian SMPI certificate lasts at most 3 years and must be renewed no later than 3 months before it expires (Article 28). How to test a vendor's certificate is covered in our ISO 27001 certification vendor check.
Ask the vendor for: the certificate number, the certification body, the scope, and a Statement of Applicability that names the system you'll actually use.
POJK 11/POJK.03/2022 (6 July 2022), Article 22(2), requires the maturity assessment annually, as at the end of December. The unit doing the assessing must be independent of IT management (Article 26(2)), so the Head of IT can't mark their own homework.
Ask the vendor for: the documents you could enter in the document-reference column for every control that touches their system.
SEOJK 29/SEOJK.03/2022 (27 December 2022), Chapter VII item 2, says this testing starts with vulnerability identification and is then followed by a penetration test. Scanning on its own meets only the continuous-detection control. The price and scope gap between the two is in vulnerability assessment vs penetration testing cost.
Ask the vendor for: scan frequency, a closure SLA per severity level, and the findings register for the last 12 months.
The elucidation of POJK 11 Article 24(1) names the penetration test as an example of vulnerability-based testing. For a new digital service, POJK 21/2023 (19 December 2023), Article 13(4)(a), requires an opinion from an independent party outside the bank. For added features an internal party may do it, as long as they took no part in design or development. In plain terms, the team that built the channel doesn't get to test it. What the statement of work has to say is in the penetration testing scope of work for banks; the web basics are in our website security guide.
Ask the vendor for: the box type (white, grey or black) and the test environment (development or production). The LKTPTI format in PADK 1/2026 asks for both.
Law 27/2022 on Personal Data Protection (17 October 2022), Article 46(1), gives 3×24 hours to notify data subjects and the supervisory agency in writing. The administrative fine tops out at 2% of annual revenue "against the variable of the violation" (Article 57(3)), not 2% of total revenue. What the notice must contain, and what triggers a DPIA, is in DPIA in Indonesia under Article 34.
Ask the vendor for: how many hours after finding a failure they'll tell you, written into the contract.
This layer carries the tightest clock on the list; the ladder is set out below. SEOJK 29 Chapter VIII requires an incident response team, and Annex IV gives the format for both the notice and the report.
Ask the vendor for: the name and 24-hour number of the person who'll call your cyber unit within minutes, not days.
POJK 11 Article 25(1) requires scenario testing "at least 1 (one) time in 1 (one) year", and the report reaches OJK within 10 working days of the test finishing (Article 25(3)). SEOJK 29 Chapter VII item 4 defines when a test counts as finished: when its results report is complete. The elucidation of Article 25(1) gives table-top exercises and cyber range exercises as examples.
Ask the vendor for: a commitment to join your yearly table-top exercise with the people who actually run the system.
POJK 11 Article 18(3) requires a DRP test of every critical application and piece of infrastructure at least once a year, involving IT users. A test run only by the infrastructure team doesn't meet that sentence.
Ask the vendor for: the RTO and RPO proven in the last test, not the ones in the brochure.
POJK 11 Article 30(3)(c) requires the vendor to commit to delivering periodic IT audit results from an independent auditor, and point (i) gives OJK access. If a vendor fails, the bank reports to OJK within 3 working days (Article 32(2)(a)).
Ask the vendor for: their latest independent IT audit report, and written consent for OJK to examine them.
POJK 11 Article 35(1) requires banks to place electronic systems in a data centre and disaster recovery centre within Indonesian territory. Offshore placement needs OJK approval (Article 35(2)). For a bank inside a regional group, that covers a group shared-services platform too, if it runs from Singapore or Kuala Lumpur.
Ask the vendor for: the cloud region for production data and for backups. Both, not just production.
A single incident in the app of a bank that's also a payment service provider starts five clocks at once. The fastest one sets the real deadline: POJK 11 Article 60(4) requires the bank to notify OJK "at the same time" when another authority's deadline is shorter. So OJK's 24 hours collapses to 1 hour.
| Clock | Obligation | Legal basis | Counted from |
|---|---|---|---|
| 1 hour | Initial notice to BI | PBI 2/2024 Art. 40(b)(1); PADG 24/2024 Art. 45(2)(b)(1) | Incident becomes known |
| 24 hours | Initial notice to OJK (banks) | POJK 11 Art. 60(1)(a) | Incident becomes known |
| 3×24 hours | Written notice to data subjects and the agency | UU PDP Art. 46(1) | The law doesn't say |
| 3 calendar days | Incident report to BI | PBI 2/2024 Art. 40(b)(2) | Incident occurs |
| 5 working days | Incident report to OJK (banks) | POJK 11 Art. 60(1)(b) | Incident becomes known |
| 5 working days | Report to OJK (insurers, multifinance) | POJK 4/POJK.05/2021 Art. 31(2) | Critical event becomes known |
Two details get missed. BI's 3-day report runs from when the incident occurred, not when it was found, and the PADG 24/2024 FAQ answers "Tidak ada" (none) when asked about a public-holiday exception. An intrusion discovered on day three is effectively already late. BI's clock applies to a bank in its role as a payment service provider (PBI 2/2024 Article 5), and the same FAQ puts the late-filing penalty at up to Rp5,000,000 per report. The agency named in UU PDP Article 46(1) is to be created by presidential regulation; we couldn't verify from a primary source whether that regulation has been issued.
Most of the annual evidence lands in the last ten days of January. We checked each date against Indonesia's 2027 joint decree on public holidays and collective leave:
The Q4 launch trap. This is our inference from the rules above, not a quoted article. A digital channel that goes live between October and December needs its final pentest report before mid-January to make the 21 January LKTPTI and the 29 January BI filing. If it's the bank's first digital service, the independent outside opinion under POJK 21/2023 has to exist before the licence.
We counted the controls in SEOJK 29's two control matrices, ID by ID, on 25 September 2026:
| Matrix | Controls | By domain |
|---|---|---|
| Annex I.b, risk management implementation | 56 | Governance 7 · framework 20 · process, people and systems 20 · internal control 9 |
| Annex I.c, cyber resilience process | 24 | Identify 3 · protect 10 · detect 5 · respond and recover 6 |
| Total | 80 | Each with a document-reference column in Annex II.b and II.c |
That column is defined as the document that can serve as the reference for assessing whether the control is in place. An ISO 27001 certificate proves a management system exists and has been audited. It doesn't prove that the 5 detection controls and 6 response controls in Annex I.c were running last month. For those 11, the examiner will ask for logs, incident tickets and test reports.
The named pentest and scenario-testing duties sit in POJK 11, which covers banks. Insurers and multifinance companies fall under POJK 4/2021 (9 March 2021), which doesn't mention pentests and leaves DRP test frequency to the company's own written policy (Article 16(5)). Their incident report is due in 5 working days. UU PDP applies to everyone equally. At an insurer or multifinance company, what gets examined is the internal policy and the vendor contracts, so that's where the numbers above need to be written down.
Our view: if you only get to negotiate one clause before signing, make it the incident notification clock. A certificate can be requested later and an audit can be scheduled. A 24-hour clock already written into the contract can't be shortened once the incident has happened, and BI only gives you one hour.
Of the WEBARQ projects with published case studies, two touch the layers above. For CGS International, investor onboarding runs through a web form with OCR, plus video call and self-verification, connected to banks, CGS-CIMB, KSEI and Dukcapil, Indonesia's civil registry. For BCA Group, the CMS behind three divisional sites uses draft, preview, merge and multi-layer approval, which is maker-checker applied to content on a regulated channel. Both describe what the case studies say, not a claim of compliance with any particular rule. If you're preparing a digital channel and want this evidence list built in from the design stage, see our website development service.