OJK Cyber Resilience Rules for Digital Banks in Indonesia 2026

OJK Cyber Resilience Rules for Digital Banks in Indonesia 2026

Written by

July 31, 2026

Indonesia now has 17 licensed digital banks, more than any other country in Southeast Asia. Digital banking penetration has grown alongside them, from 31% of the population in 2022 to a projected 39%, roughly 75 million people, by 2026.

Operating a digital bank Indonesia service places an institution at the centre of this rapid expansion. Most compliance teams at these banks have spent the last two years focused on Undang-Undang Perlindungan Data Pribadi (UU PDP), Indonesia’s data protection law.

That focus is necessary. It is not sufficient, because the Financial Services Authority (OJK) has built an entirely separate operational rulebook that most compliance calendars still treat as an afterthought.

What OJK Regulates That UU PDP Doesn’t

UU PDP governs how personal data is collected, stored, and shared. It says almost nothing about whether a bank’s systems stay online during an attack, whether a fraudulent transfer gets caught before it clears, or whether a third-party IT vendor quietly becomes the weakest link in the chain.

UU PDP Covers Privacy, Not Bank Operations

UU PDP, formally Law No. 27 of 2022, has been fully in force since October 2024. It splits personal data into general information, such as name and address, and specific, sensitive information, such as health records and financial details, which requires stronger protection.

Its dedicated regulator, the Personal Data Protection Authority or Lembaga PDP, is still being built, and as of mid-2026 enforcement sits with a directorate inside the communications ministry, Komdigi, on a temporary basis.

A Digital Bank Is Defined by Its Channel, Not Its Branches

A digital bank Indonesia entity, under POJK 12/POJK.03/2021, is an Indonesian bank that conducts its business mainly or entirely through electronic channels, with no branch network or a very limited one.

New entrants need at least IDR 10 trillion in paid-up capital. That definition explains why OJK cares so much about uptime and transaction integrity: for these banks, the app isn’t a channel, it’s the bank.

The OJK Cyber Rulebook, Piece by Piece

Three regulations, plus one that only just took effect, form the current cyber resilience stack for commercial and digital banks in Indonesia. Each one builds on the last.

1. SEOJK 29/2022 Built the Operational Core

SEOJK 29/SEOJK.03/2022, issued in December 2022, requires banks to assess their inherent cyber risk, score their own cyber security maturity level, run regular security testing, and maintain a dedicated unit responsible for cyber security and resilience.

It was built on POJK 11/POJK.03/2022, the earlier regulation on IT implementation, which already required due diligence before a bank signs with any IT vendor.

2. POJK 12/2024 Added a Fraud-Specific Layer

Under the OJK digital bank regulatory framework, POJK 12/2024 (effective October 2024) followed a period in which synthetic identity scams, phishing, and loan fraud cost Indonesian banks more than IDR 2.5 trillion between 2022 and the first quarter of 2024.

It requires a four-pillar anti-fraud strategy covering prevention, detection, investigation and reporting, and ongoing monitoring, plus a named unit led by a certified officer. Significant fraud incidents must reach OJK within three business days of discovery.

3. BOC OJK Regulation No. 1/2026 Closes the Loop on Privacy

On 1 March 2026, BOC OJK Regulation No. 1/2026 took effect, replacing a 2017 rule that had grown out of date. It covers IT governance, vendor engagement, and digital maturity assessment, and it now requires banks to reassess the materiality of every IT vendor whenever something changes at that vendor’s end, not just at contract renewal.

In the regulator’s own words, it also folds in “a more comprehensive framework for data management and personal data protection,” which means OJK isn’t staying in its lane on privacy either.

Why a Once-a-Year Review Doesn’t Hold Up

Indonesia’s National Cyber and Crypto Agency logged 5.2 billion internet traffic incidents with potential cyberattack risk in 2025, and 94% involved high-risk malware capable of developing into ransomware.

Against the broader backdrop of cybersecurity Indonesia threat metrics, an annual compliance review proves very little, especially for a digital bank Indonesia institution with no teller to fall back on when a system goes down.

  • A digital-only channel has no manual fallback when systems fail. If the app or core banking platform goes dark, there’s no branch to redirect customers to.
  • Annual penetration tests can’t see what changed last month. A test run in January says little about the API a bank shipped in June.
  • Fraud moves in seconds, quarterly reviews don’t. A synthetic identity or a socially engineered transfer can clear before most legacy monitoring cycles even run.
  • One overlooked vendor can undo four regulations’ worth of controls. A bank can pass every internal audit and still be exposed through a payment gateway it didn’t fully vet.

A Framework for Continuous Compliance: CTEM

Continuous Threat Exposure Management (CTEM), a model defined by Gartner, replaces the point-in-time audit with an ongoing five-stage cycle.

1. Scoping

Define what actually matters: core banking systems, payment rails, customer data stores, and how success will be measured.

2. Discovery

Map the real attack surface, including shadow IT, exposed APIs, and every third-party connection, not just what sits on the official asset register.

3. Prioritisation

Rank exposures by what they would actually cost the bank, rather than by a generic severity score.

4. Validation

Test whether an exposure can really be exploited, the way an attacker would, instead of trusting a scanner’s output on faith.

5. Mobilisation

Turn findings into action, with named owners, deadlines, and evidence that can be shown to OJK on request. Run well, CTEM turns SEOJK 29/2022’s maturity assessment and POJK 1/2026’s digital maturity scoring from a once-a-year scramble into something a bank can evidence on any given day of the year.

Building Real-Time Transaction Monitoring

POJK 12/2024’s four pillars only work if detection actually happens in real time, not in a batch job that runs overnight. Deploying automated transaction monitoring ensures that any digital bank Indonesia operator can spot and stop illicit transfers before funds clear.

  • One unified view across channels. Mobile, web, API, and third-party integrations need to feed the same monitoring system, not five disconnected ones.
  • Behavioural analytics, not static rules alone. A rule that flags “transfer over IDR 50 million” misses the synthetic identity that behaves like a normal customer right up until it doesn’t.
  • Scenario simulation for what hasn’t happened yet. Fraud rings adapt quickly, and a system that only recognises last year’s patterns will always be a step behind.
  • Documentation that’s ready before OJK asks. The named fraud unit POJK 12/2024 requires evidence on hand, not evidence assembled after a request lands.

What to Do Before the Next Exam

Five steps reflect where the regulatory stack is heading, not just where it stands today.

  1. Name one owner for cyber resilience and fraud strategy. POJK 12/2024 already requires a certified officer. Don’t let the role sit vacant or shared between departments.
  2. Run the new vendor materiality test. Under POJK 1/2026, every IT provider needs reassessment when something material changes at their end. Build that trigger into vendor management before OJK asks to see it.
  3. Move testing to a CTEM cadence. A single penetration test a year cannot keep pace with a bank that ships weekly.
  4. Prepare incident reporting formats. POJK 1/2026 sets out new formats for IT development plans, current-condition reports, and incident notifications. Drafting these in advance beats drafting them under pressure.
  5. Evidence everything. A control that can’t be shown on request is, from OJK’s perspective, a control that doesn’t exist.

Resilience Gets Tested Between Exams, Not During Them

UU PDP and OJK’s cyber resilience stack are converging, but they still answer different questions. One asks whether a bank handles personal data lawfully. The other asks whether the bank stays standing, and keeps its customers’ money safe, when something goes wrong. A digital bank needs a real answer to both, not a binder that only gets opened before an audit.

Zentara’s Managed SOC runs on tiered response SLAs, critical incidents inside 15 minutes, and is built around the same compliance references banks are now being tested against, including OJK.

If your digital bank Indonesia security team is still running cyber resilience as an annual project instead of a continuous one, that’s worth fixing before OJK does it for you.

Explore Zentara or talk to a cybersecurity expert to see where your current setup stands.

Watch our FREE webinar: AI vs. Hackers - The Cyber Battle You Didn’t Know Was Happening

Marsha Widagdo, Zentara’s Head of Security Operations (Blue Team), will break down how defenders use AI to spot, triage, and contain real threats—and how attackers are weaponising it in return. Expect practical playbooks, recent cases, and clear steps you can apply.

Where Cybersecurity Meets Community

We’re building a space for cybersecurity practitioners, students, researchers, and enthusiasts to connect, learn, exchange ideas, and grow as a collective. A community built around discourse, industry insights, and driven by mutual goals.

Modern Cybersecurity Services, Built for Complexity

From threat intelligence to vulnerability assessments and incident response, Zentara helps governments and enterprises stay ahead of every attack vector