South East Asia

External attack surface management for Indonesian organisations

Indonesia asks organisations to write down their internet-facing estate. BSSN Regulation 1 of 2024 requires every organisational CSIRT to register with the national CSIRT, and the registration must list the public asset names, IP addresses and domains it covers. EASMLens builds and maintains that list from the outside, and shows where it has gaps.

Serving organisations in Jakarta, Surabaya, Bandung, Medan.

What the rules in Indonesia expect

BSSN Regulation 1 of 2024: CSIRT registration

BSSN Regulation 1 of 2024 on cyber incident management (Peraturan BSSN 1/2024 tentang Pengelolaan Insiden Siber) came into force in January 2024. It requires operators of vital information infrastructure (Infrastruktur Informasi Vital, IIV) and other electronic system operators to form an organisational CSIRT and register it with the national CSIRT.

Article 11(2)(c) is the attack surface requirement in plain terms: the registration file must include the publicly accessible electronic assets of the CSIRT’s constituents, including asset names, IP addresses and domain names. Registration lasts three years for organisational CSIRTs and must be renewed when the organisation changes, so the list has to be kept current. Article 26 requires IIV operators to run incident response and continuity simulations at least every two years.

Vital information infrastructure: Perpres 82/2022

Presidential Regulation 82 of 2022 sets the framework for identifying and protecting vital information infrastructure, with BSSN as coordinator. BSSN has issued implementing regulations under it, including the CSIRT regulation above. A Cyber Security and Resilience Bill (RUU Keamanan dan Ketahanan Siber) was being debated in the DPR in 2026 and is not yet law.

OJK: cyber resilience for commercial banks

For banks, OJK’s SEOJK 29/SEOJK.03/2022 implements POJK 11/POJK.03/2022. The cyber resilience process starts with identifying assets, threats and vulnerabilities. Banks run annual risk and maturity self-assessments, vulnerability-based testing followed by penetration tests, and must give OJK an initial incident notice within 24 hours of becoming aware, with a full report within five working days. Bank Indonesia sets its own information security and cyber resilience rules for payment system operators under PBI 2/2024.

Personal data: UU PDP

Under Law 27 of 2022 on Personal Data Protection (UU PDP), fully in force since October 2024, a controller must notify data subjects and the authority in writing within 3 x 24 hours of a failure of personal data protection. Implementing regulation PP 33/2026 applies from 16 January 2027. Recent incidents, such as the June 2024 ransomware attack on the temporary National Data Centre that disrupted services for around 280 government agencies, have made regulators and boards far more attentive to where data sits and what is exposed.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
BSSN Reg 1/2024 art 11(2)(c)Registration lists public asset names, IP addresses and domainsA complete, current list of your public assets, discovered rather than remembered
BSSN Reg 1/2024 art 12Re-register on expiry or organisational changeA change history that shows when new domains, IPs or cloud services appear
SEOJK 29/2022Identify assets, threats and vulnerabilities; vulnerability-based testingExposed services with known vulnerabilities, so testing covers the real external estate
UU PDP art 463 x 24 hour notice after a data protection failureExposed databases, storage and forgotten systems before they cause a notifiable failure

Reporting clocks

  • Vital information infrastructure (BSSN Reg 1/2024)

    1 x 24 hours to the sectoral CSIRT, copied to the national CSIRT, for high-risk incidents

  • Commercial banks (OJK)

    24 hours initial notice; full report within 5 working days

  • Personal data (UU PDP)

    3 x 24 hours to data subjects and the authority

Questions for the board

  1. 1Our CSIRT registration must list our public IPs, domains and asset names. Is that list complete today, and who updates it when a new domain or cloud service goes live?
  2. 2If a data leak surfaced tonight, could we meet the 3 x 24 hour UU PDP notice and, for banks, OJK’s 24-hour notice, with facts about which exposed system was involved?
  3. 3What independent view do we have of internet-exposed systems at our hosting and cloud providers?

How EASMLens supports these obligations

  • A continuously discovered list of public domains, IP addresses and asset names for CSIRT registration
  • Change detection when new internet-facing assets appear, supporting re-registration
  • Exposure intelligence on known vulnerabilities and exposed data stores
  • Email domain security grading to reduce spoofing of your brand

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Who must register a CSIRT under BSSN Regulation 1 of 2024?
Operators of vital information infrastructure and other electronic system operators must form an organisational CSIRT and register it with the national CSIRT, including a list of their publicly accessible assets.
Is there a Bahasa Indonesia version of EASMLens content?
Not yet. Contact us if you need Indonesian-language material for your team or board, and we will provide it.
Does EASMLens scan our systems?
Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test.

More in South East Asia