Why Indonesian banks are under more scrutiny than ever
In May 2023, Bank Syariah Indonesia (BSI), one of the largest Islamic banks in the country, suffered a ransomware attack that took ATM networks and mobile banking offline for several days. Millions of customers couldn't access their accounts. LockBit later claimed responsibility, demanded USD 20 million in ransom, and after negotiations failed, published 1.5 terabytes of stolen customer and employee data on the dark web.1
OJK was watching. Within weeks, regulators had issued additional guidance on incident reporting timelines and started tightening supervisory expectations around IT risk management. The message to Indonesia's banking sector was clear: cybersecurity compliance is no longer optional, and failure has both operational and regulatory consequences.
This guide covers what OJK actually requires of banks and financial institutions today. Not the theoretical framework, but the specific controls, timelines, and governance structures you need to have in place.
The regulations that apply
OJK's cybersecurity requirements for banks are spread across several regulations. The two most important ones:
POJK No. 11/POJK.03/2022: information technology implementation by commercial banks
This regulation replaced POJK No. 38/POJK.03/2016 on IT risk management, and it covers considerably more ground: IT governance, IT architecture, IT risk management, cyber resilience and security, use of IT service providers, placement of electronic systems, data management, internal audit, and reporting. Core obligations:
- Explicitly defined IT authority and responsibilities for the Board of Directors and the Board of Commissioners
- An annual self-assessment of cyber security maturity, taken at the end of December and reported to OJK
- A Disaster Recovery Plan tested at least once a year against all critical applications and infrastructure
- Initial notification of a significant IT incident to OJK within 24 hours of the incident becoming known, followed by a full incident report within 5 working days
SEOJK No. 29/SEOJK.03/2022: cyber resilience and security for commercial banks
This circular letter implements Chapter V of POJK 11/2022 and carries the most detailed technical requirements. It covers inherent cyber security risk assessment, cyber security risk management, the cyber resilience process (identifying assets, threats and vulnerabilities, protecting assets, detecting incidents, and handling and recovering from them), cyber security maturity assessment, cyber security testing, the unit that handles cyber resilience and security, and cyber incident reporting. The framework maps to ISO 27001 and NIST CSF with Indonesia-specific additions layered on top.
Both instruments remain the operative reference as at the August 2026 update of this review. We are asked often enough whether a new cyber security POJK for commercial banks has landed in 2026. Until a replacement is promulgated, POJK 11/2022 and SEOJK 29/2022 are what examiners work from, and compliance work is better anchored to those than to a circulating draft.
Supporting regulations
- POJK No. 38/POJK.03/2016 on IT risk management for commercial banks, as amended by POJK No. 13/POJK.03/2020: both revoked by POJK 11/2022, though they still turn up as references in older policies and documents
- PBI No. 9/15/PBI/2007 on IT risk management for commercial banks: Bank Indonesia's pre-OJK predecessor to this regime, superseded once banking supervision moved to OJK but still cited in older material. Bank Indonesia remains relevant to banks through its payment system rules rather than through this instrument
- PP No. 71/2019 on the implementation of electronic systems and transactions: places security, reliability, and personal data obligations on electronic system operators, administered mainly by Kominfo with a BSSN role. It is often miscited as a national cyber security strategy framework, which it is not
What OJK actually requires: eight areas
1. IT governance and board accountability
OJK requires board-level ownership of IT and cyber risk. You cannot delegate this entirely to the IT team.
- The Board of Directors must set IT policies, standards, and procedures, and communicate them to both the IT function and IT users
- The Board of Commissioners must receive periodic accountability reports on material cyber risk, covering progress, problems, and the corrective steps taken or planned
- An IT steering committee must exist, chaired by a director and including the director responsible for IT, the director responsible for risk management, and the heads of the IT provider and IT user units
- The unit handling cyber resilience and security must be independent of the IT management function, meaning IT planning, development, operation, and monitoring
Note the wording on cadence here. For board reporting the rules say periodic, not quarterly: neither POJK 11/2022 nor SEOJK 29/2022 sets a frequency for reporting to the Board of Commissioners, so the bank picks its own cadence and has to defend it. The regulation does put a number next to one control, offering three months as an example for reviewing user access authorisation, but that example does not carry across to board reporting. In practice, your CISO needs a direct reporting line to a Director, and board minutes need to show real discussion of IT risk, not just a sign-off on an annual report.
2. Asset inventory and classification
You cannot protect what you cannot see. OJK requires banks to maintain a complete, current inventory of all IT assets, classified by criticality.
- An IT asset inventory covering hardware, software, data, network, and infrastructure, used to set asset priority
- Assets analysed, valued, and classified by criticality and sensitivity, informed by the bank's business impact analysis
- Effective configuration records for hardware and software, for example through system configuration management
- The asset inventory repeated on a regular cycle
SEOJK 29/2022 does not prescribe a fixed number of classification tiers or a specific review interval, so a bank that classifies by criticality and sensitivity and can show the inventory is genuinely current is meeting the requirement on its own terms. Without classification, you cannot risk-rate an asset. Everything else in your risk assessment depends on this.
3. Access control and privileged account management
Most bank breaches start with compromised credentials. OJK's access control requirements are specific:
- Authentication built on unique single IDs, with defined expiry for user account access rights
- Documented procedures to add, change, or remove access rights when staff move between roles
- Administrator access rights explicitly defined on devices and systems, with database access limited, for example read-only for anyone other than the database admin
- Third-party and subcontractor access to sensitive or critical bank data tracked actively on a privilege basis, with strong authentication on every external connection
- Periodic review of user access authorisation, for which the annex offers every three months as its worked example
- MFA for access to sensitive data or to the whole network where needed, and confirmation that cloud providers have MFA in place
Two things worth being precise about. MFA appears in SEOJK 29/2022 as a control criterion in the maturity annex, qualified with "where needed", not as a blanket mandate on every system touching customer data. And neither instrument puts a clock on deprovisioning. In practice, examiners do ask how quickly departing staff lose access, and a 24-hour internal SLA is a common answer, but that is the bank's own standard rather than a rule you can cite.
4. Security monitoring and incident response
This is where many Indonesian banks fall short. OJK requires continuous monitoring of IT systems, not just perimeter firewalls.
For monitoring, you need:
- Log collection from critical systems (network, servers, applications, databases)
- Detailed logging held on a centralised log server, with backup and controls against unauthorised access or alteration
- Anomaly detection for suspicious access patterns and data exfiltration
For incident response:
- A documented containment and recovery plan that considers a range of cyber incident scenarios and lines up with the BCP, the disaster recovery plan, and the crisis management plan
- A cyber incident response team with defined roles, led by someone from the cyber unit, running regular incident response drills
- Defined escalation and internal reporting paths, with the staff involved in escalation identified in advance
- An initial incident notification sent to OJK within 1x24 hours of discovering a cyber incident
- A full incident report submitted within 5 working days, covering the chronology, impact assessment, and root cause analysis
These deadlines come from Pasal 60 ayat (1) of POJK 11/2022 and are detailed in SEOJK 29/SEOJK.03/2022, and the reporting duty covers cyber incidents broadly: anything affecting customer-facing systems, involving data exfiltration, or triggering BCP activation clearly qualifies. The trigger is an incident that potentially or actually caused significant loss or disrupted smooth operations, and the clock runs from when the incident became known rather than from when it happened.
One provision is routinely missed and it changes the escalation plan. Pasal 60 ayat (4) and (5) provide that where another authority requires faster notification, the bank reports to OJK at the same time, and that is treated as satisfying the 24 hour deadline. For a bank that is also a payment system operator, PBI 2/2024 Pasal 40 requires initial notification within 1 hour, so the effective deadline to OJK becomes 1 hour too. Where the incident touches personal data, the UU PDP clock runs separately, at 3x24 hours to the data subject and the authority under Pasal 46.
5. Penetration testing and vulnerability management
OJK requires formal testing of your defences, not just scanning.
- Scenario-based cyber security testing at least once a year, with the results reported to OJK within 10 working days of the test finishing
- Vulnerability-analysis-based testing on a regular cycle, with results submitted as part of the annual IT status report
- Findings documented with risk ratings, and tracked through to remediation on timelines the bank sets
- Test results submitted to the Board of Directors as the basis for improving governance, policies, and internal control
- Results documented and secured, since the regulation treats test output as confidential
Banks can run this testing in-house or through a third party. SEOJK 29/2022 romawi VII point 5 says so directly: a bank may carry out the testing itself or use a third party. The rules do not require an external tester, though banks without a mature internal testing team generally use one. Where a third party is used, its competence is evidenced among other things by certification or recognition from an authorised body in Indonesia or abroad, and responsibility for the testing stays with the bank.
Three reporting details are worth recording, because all three are commonly misread. First, the 10 working day deadline for scenario test results runs from the point the result report has finished being compiled, not from the last day of testing activity, and the SEOJK states that explicitly. Second, vulnerability-analysis results, penetration tests included, go in as a compilation at most 15 working days after the end of the reporting year, rather than one report per test. Third, the format is not open: Lampiran VI of SEOJK 29/2022 carries the scenario test report table, and its parties-involved column explicitly covers a third party the bank used to test.
The full detail, including the SEOJK's own worked deadline examples, is in what goes in an OJK cyber security test report and an IT incident report. For the question of who may test, the offshore vendor case included, see who is allowed to run a bank's penetration test.
Banks applying for or renewing SWIFT connectivity face additional testing requirements under SWIFT's Customer Security Programme (CSP), which OJK aligns with.
6. Business continuity and disaster recovery
OJK requires banks to show they can survive a major IT failure, not just claim it on paper.
- A Disaster Recovery Plan the bank can actually execute, so operations keep running through a disaster or a disruption to the IT it relies on
- A DR test at least once a year, covering all critical applications and infrastructure identified by the business impact analysis, with IT users involved
- The Disaster Recovery Plan reviewed at least once a year
- Backup systems and a tested, adequate DR plan extended to arrangements with IT service providers
- Cyber incident containment and recovery planning that works through a range of incident scenarios, ransomware included
One correction worth making, because it circulates widely: POJK 11/2022 and SEOJK 29/2022 set no RTO or RPO figures for banks, and no tabletop frequency. Those numbers come from your own business impact analysis. Core banking usually lands at the demanding end, but if you present a four-hour RTO to an examiner as an OJK requirement, you are citing something that is not there. DR test results should still be documented and gaps remediated on a defined timeline.
7. Third-party and cloud risk management
As Indonesian banks increase their use of cloud services and fintech partnerships, third-party requirements have become harder to ignore.
- A documented policy and procedure for using IT service providers, covering how the need is identified, how providers are selected, how the working relationship runs, how the risk is managed, and how provider performance and compliance get assessed
- Separate cyber risk policies and procedures for third parties and their subcontractors, covering how they handle bank and customer data
- A written agreement carrying confidentiality commitments, periodic independent IT audit results delivered to the bank, bank approval before any subcontracting, a critical event reporting mechanism, termination arrangements, and the provider's willingness to give OJK access for examination
- Comprehensive controls over logical access to bank systems, and a classification policy for the criticality and sensitivity of data held in the cloud
- Electronic systems placed in data centres and disaster recovery centres inside Indonesia, unless OJK grants permission to place them abroad
The cloud point is often stated loosely. POJK 11/2022 does not ask for notification before a cloud deployment. It requires your electronic systems to sit in Indonesian data centres and disaster recovery centres by default, and offshore placement needs OJK permission against defined criteria, which is a higher bar than telling the regulator afterwards. The bank also stays responsible for the outsourced activity regardless of what the contract says.
8. Internal IT audit, and the one external-party obligation
This is where the most misunderstood requirement sits. Pasal 54 ayat (4) of POJK 11/2022 requires an internal audit of IT implementation at least once a year, according to need, priority, and the results of IT risk analysis. Pasal 55 ayat (1) requires an internal IT audit charter.
Then Pasal 55 ayat (2): the bank must review its internal IT audit function at least once every three years using the services of an independent external party, and submit the result to OJK. That is the only place in this regime where an independent external party is mandated.
Note what is being reviewed, because this is where the confusion starts. It is the bank's internal IT audit function, not the bank's systems, and the cycle is three years. So the statement that OJK requires an external party is true of Pasal 55 ayat (2) and untrue of cyber security testing. The two get conflated routinely, and the conflation usually surfaces when someone is selling the wrong piece of work.
Penalties for non-compliance
OJK has real enforcement power and is using it.
| Violation | Consequence under POJK 11/2022 |
|---|---|
| Failure to meet a cyber resilience, testing, or cyber unit obligation | Written warning |
| Failure to report, or reporting late, against the deadlines | Written warning |
| Still not compliant after the written warning | Ban on issuing new bank products |
| Still not compliant after the written warning | Suspension of certain business activities |
| Still not compliant after the written warning | Downgrade of the governance factor in the bank's soundness rating |
The ladder is deliberately short: a written warning first, then one or more of the three escalations, which POJK 11/2022 allows OJK to apply together. Two things people expect to see here are absent. The regulation provides for no monetary fines, and no revocation of a banking licence. What it does reach is the soundness rating, and a downgraded governance factor follows a bank into every other supervisory conversation it has, which is why this is taken more seriously than the short list suggests.
After the BSI incident, OJK publicly stated it would increase the frequency and technical depth of IT examinations for systemically important banks. Mid-tier banks have seen more IT-focused examination questions in recent supervisory cycles too.
Building a compliant security program: a practical roadmap
Phase 1: gap assessment (months 1-2)
Before you can close gaps, you need to find them. Map your current controls against SEOJK No. 29:
- Have you run the inherent cyber risk and maturity self-assessments, and filed the resulting cyber risk level with OJK? This is the one gap that shows up immediately in supervision, because OJK is expecting the submission
- Is your IT asset inventory complete, classified by criticality and sensitivity, and genuinely current?
- Do you have a unit handling cyber resilience and security that is independent of IT management, or is cyber still sitting inside the IT team?
- Do you have documented policies for third-party cyber risk, incident containment and recovery, and disaster recovery?
- Is security testing happening in both forms the regulation recognises, and are the results reaching OJK on time?
- Are logs being collected centrally, protected against tampering, and monitored?
Phase 2: governance foundation (months 2-4)
If your board is not actively engaged with IT risk, that is the first gap to close.
- Formalise the IT steering committee with the composition POJK 11/2022 actually requires: chaired by a director, including the IT director, the risk management director, and the heads of the IT provider and IT user units
- Stand up the unit or function handling cyber resilience and security, independent of IT management, with the coordination duties SEOJK 29/2022 gives it
- Get IT policies, standards, and procedures board-approved and on a defined review cycle
- Set a reporting cadence to the Board of Commissioners on material cyber risk and hold to it. The rule says periodic, so quarterly is a defensible choice rather than a requirement, and what matters is that you can evidence the cadence you picked
- Hire or designate a CISO with a clear mandate and escalation path
Phase 3: technical controls (months 3-9)
Priority order:
- MFA on remote access and critical systems: highest risk reduction per effort
- Privileged access management: inventory and monitor all admin accounts
- Log management and SIEM: you cannot detect or report incidents without visibility
- Vulnerability management: establish a scan-track-remediate cycle
- Endpoint detection and response (EDR): important for catching ransomware early
Phase 4: testing and documentation (ongoing)
Compliance is not a one-time project:
- A scenario-based test at least once a year, budgeted and scheduled, with the report filed within 10 working days of the test finishing
- A vulnerability-analysis testing cycle, penetration tests included, at a frequency you set from system criticality and change exposure, with results filed in the annual IT status report
- The inherent risk and maturity self-assessments taken at the end-December position, submitted with the cyber risk level within 15 working days of the reporting year end
- Annual DR test and annual DRP review, with a board readout
- Tabletop exercises covering ransomware and data breach scenarios
The deadlines are the part banks most often miss. The controls tend to exist; what fails is filing the result inside the window.
How managed security services can help
Most Indonesian banks, particularly regional banks (BPD) and mid-tier commercial banks, don't have the headcount to run continuous security monitoring in-house. That's not a criticism; it's just the reality of the sector.
A qualified MSSP can:
- Provide 24/7 SOC coverage for log monitoring and incident detection. POJK 11/2022 Pasal 53 ayat (4) huruf a asks for "pemantauan secara terus menerus", continuous monitoring, rather than a set staffing pattern, and round-the-clock cover is one way to satisfy it
- Conduct or coordinate the annual scenario-based exercise and your penetration testing cycle, with the scenario report drafted to the Lampiran VI format in SEOJK 29/2022
- Help draft and maintain policy documents (IRP, BCP, TPRM policy) aligned to SEOJK No. 29
- Generate board-ready reports showing control status against OJK requirements
The question is finding a partner who actually understands Indonesian regulatory expectations. An MSSP that simply maps international frameworks to OJK requirements and hopes the mapping holds up under examination is a risk, not an asset.
What examiners actually look for
In OJK IT examinations, the same questions come up repeatedly:
- Show me your latest self-assessment. The inherent risk rating, the maturity level, the cyber risk level you filed, and the reasoning behind them. OJK reviews these and can revise a rating it does not find credible.
- Show me your asset register. They want it current, classified by criticality and sensitivity, and owned by someone named.
- Walk me through your last incident. A timeline, escalation evidence, and the post-incident report, set against your 24-hour notification and 5-working-day filing.
- When was your last DR test? What failed? They want honest documentation, not a clean report.
- Show me access reviews for your core banking system. Who has admin access, when was it last reviewed?
- What happened with your last test findings? Whether findings were tracked to closure on the timeline you committed to. Since the regulation sets no remediation clock, the deadline in your own policy is the one you get held to, and long-open critical vulnerabilities are the red flag.
If you cannot answer these questions quickly and with documentation, you have a compliance gap, regardless of what your policies say.
For a dedicated guide to what OJK IT examinations cover and how banks prepare, see our cyber resilience audit service page.
Next steps
If you are not sure where your bank stands, start with a structured IT risk gap assessment against SEOJK No. 29/SEOJK.03/2022. That gives you a prioritised compliance roadmap you can take to your board and, if needed, to OJK supervisors.
Alpha Code Technologies works with Indonesian banks to assess, build, and operate security programs that meet OJK requirements. To discuss your bank's current posture, contact our team.
References
Footnotes
-
Bank Syariah Indonesia Cyber Attack: LockBit Demands $20m Ransom - The Cyber Express, May 2023 ↩