Skip to main content

Cybersecurity Blog

Security intelligence for Indonesian enterprises

FeaturedCompliance

UU PDP vs GDPR: How Indonesia's Data Protection Law Compares

UU PDP vs GDPR side by side: lawful bases, DPO triggers, the 3x24 hour breach notice and who must be told, fines, and what compliance takes for businesses in Indonesia.

N
Naren Krishnan
12 min read · May 30, 2026Read more
What goes in an OJK cyber security test report and an IT incident report
Compliance

What goes in an OJK cyber security test report and an IT incident report

POJK 11/2022 names three minimum contents for the scenario test report, a 10 working day deadline, and incident deadlines of 24 hours and 5 working days. Here it is article by article, including the rule for when another regulator moves faster.

M
Mirna Indriasari8 min · Aug 21
Who is allowed to run a bank's penetration test: in-house, third party, or an offshore vendor
Compliance

Who is allowed to run a bank's penetration test: in-house, third party, or an offshore vendor

POJK 11/2022 requires banks to test their cyber security, but it does not require an external tester and does not bar a foreign vendor. What decides it is competence, supervision, and OJK's right of examination. Here it is article by article.

K
Karina Kosasih8 min · Aug 19
DPAs and vendor agreements under UU PDP: what the law actually requires
Compliance

DPAs and vendor agreements under UU PDP: what the law actually requires

UU PDP has no GDPR Article 28 equivalent, so there is no mandatory data processing agreement form. What Pasal 51 requires is processing on instruction, written consent for sub-processors, and a clear split of liability. Here is what that means for your vendor contracts.

T
Tyas Suci6 min · Aug 17
PCI DSS for Indonesian Businesses: Who Must Comply and How to Meet It
Compliance

PCI DSS for Indonesian Businesses: Who Must Comply and How to Meet It

A PCI DSS guide for Indonesian businesses that handle payment card data: who must comply, the four merchant levels, the twelve core requirements, and practical steps toward compliance.

T
Tyas Suci5 min · Jul 22
What Is a CISO and When Does Your Business Need a vCISO
Cybersecurity

What Is a CISO and When Does Your Business Need a vCISO

The role of a CISO in an organization, what their responsibilities really are, and when a virtual CISO (vCISO) becomes the more sensible choice for mid-sized companies in Indonesia.

N
Naren Krishnan5 min · Jul 18
Cybersecurity Careers in Indonesia: Roles, Skills, and Salary Outlook
Cybersecurity

Cybersecurity Careers in Indonesia: Roles, Skills, and Salary Outlook

A guide to starting a cybersecurity career in Indonesia: the most in-demand roles, the skills and certifications employers look for, salary ranges, and entry paths for beginners and career changers.

T
Tyas Suci5 min · Jul 14
What Is Penetration Testing? Methods, Types, and How to Choose
Cybersecurity

What Is Penetration Testing? Methods, Types, and How to Choose

A penetration testing guide for Indonesian businesses: the difference between black box, grey box, and white box, types of pentest by target, the testing process, and how to choose the right provider.

K
Karina Kosasih6 min · Jul 4
Antivirus is not enough anymore. Here is why you need EDR.
Endpoint Security

Antivirus is not enough anymore. Here is why you need EDR.

Antivirus still blocks known malware, but it misses fileless attacks and everything an intruder does after they get in. Here is what EDR adds, from someone who works with endpoints daily.

R
Rizki Pratama5 min · Jun 24
Why the IT penetration testing playbook fails in OT environments
OT Security

Why the IT penetration testing playbook fails in OT environments

From direct experience: why standard IT pentest tools and methods are dangerous in OT/ICS environments, and what a proper OT VAPT approach actually looks like.

M
Mohit Bhansali6 min · Jun 17
WhatsApp