Skip to main content
← BlogCompliance

What goes in an OJK cyber security test report and an IT incident report

POJK 11/2022 names three minimum contents for the scenario test report, a 10 working day deadline, and incident deadlines of 24 hours and 5 working days. Here it is article by article, including the rule for when another regulator moves faster.

M
Mirna Indriasari · Security Program Manager
August 21, 2026·8 min read

POJK 11/2022 names the minimum content of the report, and SEOJK 29/2022 sets its format in Lampiran VI. For the scenario-based cyber security test report, Pasal 25 ayat (4) sets three things: a summary of how the test was carried out, lessons learned or observations drawn from the results, and the plan or the corrections already carried out. The format follows Lampiran VI of SEOJK 29/2022, and submission is online through the OJK reporting system under Pasal 62 ayat (1).

Three items is less than most people expect, and it does not mean a thin report will do. Minimum content is the floor for compliance, not a measure of a useful report.

Two kinds of testing, two reporting routes

Pasal 23 requires two forms of testing, one based on vulnerability analysis and one based on scenarios, and each is reported differently. This distinction is a frequent source of confusion.

For vulnerability-analysis testing, which is the stream a penetration test belongs to, Pasal 24 ayat (1) requires it to be carried out periodically without naming a figure, and ayat (2) requires the results to be submitted to OJK as part of the report on the current condition of the bank's IT implementation. The deadline for that sits in SEOJK 29/2022 romawi VII point 4 letter b: at most 15 working days after the end of the reporting year. What goes in is a compilation, not one report per test. The SEOJK's own worked example makes it concrete: a bank that ran penetration tests in March, July, and November 2022 submits the compilation by 20 January 2023 at the latest.

For scenario-based testing, Pasal 25 ayat (1) sets a minimum of once a year, and ayat (3) gives it a deadline of its own: the report goes to OJK at most 10 working days after the cyber security testing is completed. When the testing counts as completed is not left to interpretation. SEOJK 29/2022 romawi VII point 4 letter b defines it: the testing is deemed complete when the test report has finished being compiled. So the count starts from the completion of the report, not from the last day of testing activity, and the SEOJK's example shows it: a test run on 3 November 2023 whose report was finished on 14 November 2023 must be submitted by 28 November 2023.

What the scenario test itself has to cover

Before the report, Pasal 25 ayat (2) sets the coverage of the test itself, at least four things: setting the objectives, scope, and test scenarios; carrying out the test; evaluating the results; and assessing the effectiveness of the bank's mitigation, response, and recovery measures against cyber attacks.

That fourth item is the one most often missed. A test that produces only a list of vulnerabilities has not met this ayat, because what is asked for is an assessment of how effectively the bank contains and recovers. That puts scenario-based testing closer to an incident response exercise than to a technical scan, and it means the bank's incident response team has to be genuinely involved.

The IT incident report: 24 hours and 5 working days

Pasal 60 ayat (1) governs a different route from test reporting. Where an IT incident occurs that potentially or actually caused significant loss or disrupted the smooth running of the bank's operations, the bank must submit an initial notification at most 24 hours after the IT incident became known, and an IT incident report at most 5 working days after the IT incident became known.

Two things in that sentence deserve attention. The count starts from when the incident became known, not from when it happened, which makes the record of the discovery time an important document. The trigger is also not every incident, but one that potentially or actually caused significant loss or disrupted operations, and that assessment sits with the bank. For the initial notification, Pasal 60 ayat (2) states it is submitted in writing by electronic means to OJK based on the initial information available. So the 24 hour notification does not demand a settled root cause, only the initial information you have.

When another regulator moves faster

The part that is least known sits in Pasal 60 ayat (4) and (5). Where another authority regulates the submission of an initial notification or an incident report within a faster period, the bank must submit to OJK at the same time as that authority's rule requires. A bank that has done so is treated as having met the 24 hour and 5 working day requirements.

The consequence is real for a bank that is also a payment system operator. PBI 2/2024 Pasal 40 requires an initial cyber incident notification within 1 hour, so the effective deadline to OJK becomes 1 hour as well, not 24 hours. The fastest clock pulls the others with it, and that changes how the escalation procedure has to be built.

For incidents involving personal data, the UU PDP clock runs separately and to different recipients. Pasal 46 ayat (1) requires written notice within 3x24 hours to the data subject and to the authority, and ayat (2) sets its minimum content: the personal data that was exposed, when and how it was exposed, and the controller's handling and recovery efforts. We cover the detail in vendor obligations and DPAs under UU PDP.

The format does exist, in Lampiran VI of SEOJK 29/2022

POJK 11/2022 names only the minimum content, which makes it easy to conclude that no official format exists. That conclusion is wrong. SEOJK 29/2022 romawi VII point 4 letter b requires scenario test results to be submitted in the format set out in Lampiran VI, which forms an inseparable part of the circular.

Lampiran VI is a table headed "Laporan Hasil Pengujian Keamanan Siber Berdasarkan Skenario", filled in per test, with the bank name and year above it. Its columns are the test objective, the type of test, the test scope, the date testing started, the date testing finished, the parties involved, the test result, the corrections carried out, and the follow-up plan.

Two of its footnotes are worth reading. The parties-involved column explicitly covers the IT service provider or third party the bank used to perform the testing, so the form itself treats a third-party tester as ordinary. And the corrections column is filled in where the bank has already remediated, while the follow-up plan is filled in where it has not, so the two are not meant to be completed together.

For submission, Pasal 62 ayat (3) of POJK 11/2022 leaves the online reporting procedure to the OJK rules on bank reporting through the OJK reporting system. So Lampiran VI governs the content and shape of the report, while those reporting rules govern the mechanics of sending it.

In practice, the gap we find most often is not the format but the third item in Pasal 25 ayat (4). Reports name a remediation plan with no owner and no date, or claim corrections already made with no retest evidence. Both pass formally and are hard to defend in an examination.

Sanctions for late and incomplete reports

Pasal 27 sets the sanctions for failing to test: a written warning first, then a ban on issuing new bank products, suspension of certain business activities, or a downgrade of the governance factor if the requirement is still not met. For reporting, Pasal 63 sets the same pattern for a bank that is late with the initial IT incident notification. Pasal 62 ayat (2) states that breaches relating to report submission carry an administrative sanction, and Pasal 64 provides that a bank submitting an incomplete report is sanctioned for information error under the bank reporting rules. There is no fine in any of those articles.

For the wider picture of the testing obligation and who may carry it out, see who is allowed to run a bank's penetration test and cybersecurity compliance for commercial banks.

References

  1. OJK Regulation No. 11/POJK.03/2022 on Information Technology Implementation by Commercial Banks, BPK RI regulation database. Pasal 23 to 27 govern testing and its sanctions, Pasal 60 governs incidental reports, and Pasal 62 to 64 govern report submission and its sanctions.
  2. Law Number 27 of 2022 on Personal Data Protection, BPK RI regulation database, Pasal 46 for notification of a personal data protection failure.
  3. SEOJK No. 29/SEOJK.03/2022 on Cyber Resilience and Security for Commercial Banks, OJK (full text). Romawi VII point 4 sets the submission deadlines for both kinds of test result and defines when testing is complete, point 5 governs who may run the testing, and Lampiran VI carries the report format.
  4. Bank Indonesia Regulation No. 2 of 2024 on Information System Security and Cyber Resilience, Bank Indonesia, Pasal 40 for the cyber incident notification deadline.
WhatsApp