Author Profile
Karina Kosasih
Offensive Security Lead, Alpha Code Technologies
Karina leads penetration testing and red-team engagements for Indonesian banks, aligning technical assurance with regulatory expectations.
LinkedInArticles by Karina Kosasih
Who is allowed to run a bank's penetration test: in-house, third party, or an offshore vendor
POJK 11/2022 requires banks to test their cyber security, but it does not require an external tester and does not bar a foreign vendor. What decides it is competence, supervision, and OJK's right of examination. Here it is article by article.
CybersecurityWhat Is Penetration Testing? Methods, Types, and How to Choose
A penetration testing guide for Indonesian businesses: the difference between black box, grey box, and white box, types of pentest by target, the testing process, and how to choose the right provider.
CompliancePenetration Testing Requirements for Indonesian Banks Under POJK 11/2022
What POJK 11/2022 and its cyber security circular SEOJK 29/2022 require of Indonesian banks for penetration testing: cadence, scope, reporting, and remediation.