ZENTARA

Securing IKN Nusantara: A Guide to OT and IIoT Cybersecurity

Learn how enterprises and contractors can strengthen IKN Nusantara cybersecurity by securing OT, IIoT, smart buildings, and connected infrastructure.

Zentara Team9 min read
Securing IKN Nusantara: A Guide to OT and IIoT Cybersecurity

Securing IKN Nusantara: A Guide to OT and IIoT Cybersecurity

Ibu Kota Nusantara (IKN) is being built as a smart, connected city where digital technology will play a central role in how infrastructure and public services operate.

From smart buildings and intelligent transportation to water management and energy systems, connected technologies will help manage critical infrastructure across the new capital.

The Otorita IKN's Smart City Blueprint and technical guidelines already outline specific frameworks for intelligent mobility, smart buildings, and water management. Water distribution plans, for example, rely heavily on telemetry sensors and robust SCADA security controls across treatment plants and supply networks. 

This creates a new architectural vulnerability. As the city's smart infrastructure becomes increasingly interconnected, protecting operational networks, sensor grids, and third-party dependencies becomes critical to national resilience. 

For enterprises, technology vendors, and engineering contractors operating within IKN Nusantara, cybersecurity cannot be treated as an IT add-on at the end of a project. It must be embedded directly into physical and digital systems from day one. 

Why Cybersecurity Matters for IKN Nusantara

Smart municipal systems create immense efficiency by linking physical equipment to digital management platforms. Field sensors aggregate real-time telemetry, industrial controllers adjust physical equipment, and central platforms enable operators to monitor conditions dynamically. 

However, every connected endpoint expands the potential entry surface for adversarial exploitation. A compromised field sensor may not appear critical in isolation, but if that endpoint bridges into an internal operational network, an attacker can move laterally into core municipal control systems. 

This risk is particularly acute in environments where OT security dictates physical safety. In these operational domains, a cyber incident impacts more than data confidentiality—it can interrupt essential services, damage physical assets, or cause structural operational downtime. Because capital systems manage core urban functions, cybersecurity must protect both the digital control layer and the physical assets that rely upon it. 

The Growing OT and IIoT Attack Surface

Traditional enterprise IT security focuses primarily on preserving data confidentiality and managing user endpoints. Conversely, operational technology security enforces a different priority: system availability, process integrity, and physical safety. 

In an industrial or infrastructure environment, availability and safety are often just as important as confidentiality.

OT systems may control water treatment, energy distribution, building management, traffic systems, and other physical processes. IIoT devices add another layer by connecting sensors, machines, and equipment to digital networks and cloud platforms.

This creates several potential risks.

  1. More connected devices

Every sensor, controller, gateway, and connected device can introduce another potential attack surface. Organisations need visibility into what is connected, where it is located, and what systems it can communicate with.

  1. Coexistence of Legacy and Modern Hardware

Infrastructure projects frequently combine legacy industrial controllers—designed before modern threat vectors existed—with modern industrial IoT edge devices. Connecting legacy hardware to modern networks without strict security barriers introduces unexpected vulnerabilities. 

  1. IT and OT convergence

As OT environments become connected to corporate IT networks and cloud platforms, the traditional separation between IT and OT becomes less clear.

An attacker who compromises an IT environment may attempt to move towards operational systems. Conversely, a vulnerable connected device may provide a pathway into wider corporate networks.

  1. Third-party and contractor access

Large infrastructure projects involve multiple contractors, system integrators, technology providers, and maintenance teams.

Each third party may require some level of access to systems or devices. Without strong identity controls, network segmentation, and monitoring, these connections can increase the overall attack surface.

Cybersecurity Challenges for Enterprises and Contractors in IKN

The cybersecurity challenge is not simply protecting individual devices. It is securing the entire ecosystem around them.

  1. Securing OT without disrupting operations

Unlike traditional IT systems, OT environments cannot always be taken offline for patching or security testing. Organisations need to understand which systems are critical, identify vulnerabilities, and apply security controls without affecting essential operations.

This requires a risk-based approach that considers both cybersecurity and operational impact.

  1. Managing IIoT device security

Deploying thousands of field sensors across expansive geographic areas makes device management complex. Establishing structured IoT security protocols—such as enforcing secure baseline configurations, automating firmware updates, and monitoring device behavior for anomalies—is vital to prevent physical tampering or remote takeover. 

  1. Controlling remote access

Remote access is often necessary for contractors and vendors to maintain infrastructure. However, unmanaged remote connections can become a significant security weakness.

Access should be limited to authorised users, restricted to specific systems, protected by strong authentication, and monitored continuously.

  1. Protecting the supply chain

A smart infrastructure project may involve dozens of technology providers and contractors.

A vulnerability in one supplier's system can potentially affect the wider environment. Cybersecurity requirements therefore need to extend beyond the organisation itself and into procurement, contracts, vendor assessments, and third-party monitoring.

A Secure-by-Design Approach for IKN Nusantara

The most effective way to protect smart infrastructure is to build security into the architecture from the beginning. This is the principle behind secure by design.

Core Principle: Security must be integrated across planning, procurement, engineering design, construction, and final commissioning, rather than added after deployment. 

  1. Build a complete asset inventory

Organisations cannot protect what they cannot see. Every OT and IIoT asset should be identified, classified, and mapped to its network connections and business function. This includes sensors, PLCs, SCADA systems, industrial gateways, building management systems, and remote access points.

  1. Segment IT and OT networks

IT and OT systems should not have unrestricted connectivity.

Network segmentation can limit the ability of an attacker to move between environments and reduce the impact of a compromise. Critical systems should be isolated based on their operational importance and communication requirements.

  1. Apply Zero Trust principles

Trust should not be granted simply because a user or device is inside the network. Access to OT and IIoT environments should be based on verified identity, device status, least-privilege permissions, and continuous monitoring.

This is particularly important when multiple contractors and vendors require remote access.

  1. Monitor OT and IIoT activity

Traditional security monitoring may not detect every threat in an operational environment.

Organisations need visibility into network traffic, device behaviour, authentication events, and unusual changes in operational activity. Monitoring can help identify suspicious behaviour before it develops into a larger incident.

  1. Test security before deployment

Security testing should happen before systems become part of critical infrastructure. Vulnerability assessments, penetration testing, configuration reviews, and architecture assessments can identify weaknesses before they become operational risks.

For OT environments, testing should be carefully planned to avoid disrupting production systems.

What Contractors and Technology Providers Should Consider

Cybersecurity responsibilities should not stop at the organisation's own network.

Contractors working on IKN Nusantara projects may have access to sensitive systems, infrastructure, or operational environments. Their security practices can therefore have a direct impact on the wider ecosystem.

Before deployment, organisations should establish clear requirements for:

  • Secure system architecture
  • Device hardening
  • Identity and access management
  • Remote vendor access
  • Vulnerability management
  • Security monitoring
  • Incident reporting
  • Data protection
  • Business continuity
  • Secure system decommissioning

These requirements should be defined during procurement and contract negotiations rather than introduced after implementation. A secure smart city requires a secure supply chain.

Building Cyber Resilience Into IKN Nusantara

The development of IKN Nusantara presents an opportunity to approach infrastructure security differently.

Because many systems are being designed and deployed as part of a new smart city ecosystem, organisations have an opportunity to embed cybersecurity before technologies become deeply interconnected.

This is particularly important as IKN continues to develop its digital infrastructure.

In October 2025, the Otorita IKN highlighted cybersecurity and digital ecosystem protection as part of ongoing efforts to strengthen smart city governance. More recently, the authority has continued developing smart city infrastructure and cooperation, including the Smart City Cooperation Center.

Establishing robust smart city security requires aligning technical architecture with long-term risk management. 

A Practical Cybersecurity Blueprint for IKN Projects

A strong cybersecurity strategy for smart infrastructure should cover five areas:

  • Visibility: Know every asset, device, system, and connection within the environment.
  • Segmentation: Separate critical OT systems from corporate IT and less trusted networks.
  • Access control: Ensure users, devices, contractors, and vendors only have the access they need.
  • Monitoring: Continuously detect unusual activity across IT, OT, and IIoT environments.
  • Resilience: Prepare for incidents with tested response, recovery, and continuity plans.

Together, these controls help organisations move from reactive security to a more proactive approach that protects both digital systems and physical operations.

Securing the Future of IKN Nusantara

IKN Nusantara is being designed around connected infrastructure, smart services, and digital technologies. That connectivity can create significant benefits, but it also means cybersecurity must be part of the infrastructure itself.

For enterprises and contractors entering the IKN ecosystem, the priority should be clear: secure OT, IIoT, and connected systems before they become deeply embedded in critical operations.

Zentara helps organisations strengthen cybersecurity across complex technology environments, from assessing vulnerabilities and testing security controls to improving monitoring and incident readiness.

Our approach brings together cybersecurity strategy, VAPT, security monitoring, and risk management to help organisations build resilience across increasingly connected ecosystems.

Smart infrastructure should not just be connected. It should be secure by design.

Building or expanding your operations in IKN Nusantara? Explore Zentara's cybersecurity services to strengthen the security of your connected infrastructure before the next connection becomes the next attack path.

Frequently Asked Questions

  1. Why is cybersecurity important for IKN Nusantara?

As infrastructure becomes more connected, more infrastructure will depend on networks, cloud platforms, sensors, and connected devices. A cyberattack could therefore affect not only data and IT systems but also physical operations and essential services.

  1. What is OT cybersecurity?

OT cybersecurity protects systems that monitor or control physical processes and infrastructure. These may include industrial control systems, SCADA platforms, building management systems, and other technologies used to operate physical environments.

  1. What is IIoT security?

IIoT security focuses on protecting connected industrial devices such as sensors, controllers, machines, and gateways. It helps prevent attackers from exploiting vulnerable devices to access wider networks or disrupt operations.

  1. How can organisations secure smart infrastructure in IKN?

Organisations should build complete asset visibility, segmenting IT and OT networks, applying strong access controls, monitoring connected devices, and testing security before systems are deployed.

  1. How does Zero Trust help secure OT and IIoT?

Zero Trust limits access based on verified identities, device status, and least-privilege permissions, reducing the risk of compromised accounts or devices reaching critical systems.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.