South East Asia
External attack surface management for Indonesian organisations
Indonesia asks organisations to write down their internet-facing estate. BSSN Regulation 1 of 2024 requires every organisational CSIRT to register with the national CSIRT, and the registration must list the public asset names, IP addresses and domains it covers. EASMLens builds and maintains that list from the outside, and shows where it has gaps.
Serving organisations in Jakarta, Surabaya, Bandung, Medan.
What the rules in Indonesia expect
BSSN Regulation 1 of 2024: CSIRT registration
BSSN Regulation 1 of 2024 on cyber incident management (Peraturan BSSN 1/2024 tentang Pengelolaan Insiden Siber) came into force in January 2024. It requires operators of vital information infrastructure (Infrastruktur Informasi Vital, IIV) and other electronic system operators to form an organisational CSIRT and register it with the national CSIRT.
Article 11(2)(c) is the attack surface requirement in plain terms: the registration file must include the publicly accessible electronic assets of the CSIRT’s constituents, including asset names, IP addresses and domain names. Registration lasts three years for organisational CSIRTs and must be renewed when the organisation changes, so the list has to be kept current. Article 26 requires IIV operators to run incident response and continuity simulations at least every two years.
Vital information infrastructure: Perpres 82/2022
Presidential Regulation 82 of 2022 sets the framework for identifying and protecting vital information infrastructure, with BSSN as coordinator. BSSN has issued implementing regulations under it, including the CSIRT regulation above. A Cyber Security and Resilience Bill (RUU Keamanan dan Ketahanan Siber) was being debated in the DPR in 2026 and is not yet law.
OJK: cyber resilience for commercial banks
For banks, OJK’s SEOJK 29/SEOJK.03/2022 implements POJK 11/POJK.03/2022. The cyber resilience process starts with identifying assets, threats and vulnerabilities. Banks run annual risk and maturity self-assessments, vulnerability-based testing followed by penetration tests, and must give OJK an initial incident notice within 24 hours of becoming aware, with a full report within five working days. Bank Indonesia sets its own information security and cyber resilience rules for payment system operators under PBI 2/2024.
Personal data: UU PDP
Under Law 27 of 2022 on Personal Data Protection (UU PDP), fully in force since October 2024, a controller must notify data subjects and the authority in writing within 3 x 24 hours of a failure of personal data protection. Implementing regulation PP 33/2026 applies from 16 January 2027. Recent incidents, such as the June 2024 ransomware attack on the temporary National Data Centre that disrupted services for around 280 government agencies, have made regulators and boards far more attentive to where data sits and what is exposed.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| BSSN Reg 1/2024 art 11(2)(c) | Registration lists public asset names, IP addresses and domains | A complete, current list of your public assets, discovered rather than remembered |
| BSSN Reg 1/2024 art 12 | Re-register on expiry or organisational change | A change history that shows when new domains, IPs or cloud services appear |
| SEOJK 29/2022 | Identify assets, threats and vulnerabilities; vulnerability-based testing | Exposed services with known vulnerabilities, so testing covers the real external estate |
| UU PDP art 46 | 3 x 24 hour notice after a data protection failure | Exposed databases, storage and forgotten systems before they cause a notifiable failure |
Reporting clocks
Vital information infrastructure (BSSN Reg 1/2024)
1 x 24 hours to the sectoral CSIRT, copied to the national CSIRT, for high-risk incidents
Commercial banks (OJK)
24 hours initial notice; full report within 5 working days
Personal data (UU PDP)
3 x 24 hours to data subjects and the authority
Questions for the board
- 1Our CSIRT registration must list our public IPs, domains and asset names. Is that list complete today, and who updates it when a new domain or cloud service goes live?
- 2If a data leak surfaced tonight, could we meet the 3 x 24 hour UU PDP notice and, for banks, OJK’s 24-hour notice, with facts about which exposed system was involved?
- 3What independent view do we have of internet-exposed systems at our hosting and cloud providers?
How EASMLens supports these obligations
- A continuously discovered list of public domains, IP addresses and asset names for CSIRT registration
- Change detection when new internet-facing assets appear, supporting re-registration
- Exposure intelligence on known vulnerabilities and exposed data stores
- Email domain security grading to reduce spoofing of your brand
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Who must register a CSIRT under BSSN Regulation 1 of 2024?
- Operators of vital information infrastructure and other electronic system operators must form an organisational CSIRT and register it with the national CSIRT, including a list of their publicly accessible assets.
- Is there a Bahasa Indonesia version of EASMLens content?
- Not yet. Contact us if you need Indonesian-language material for your team or board, and we will provide it.
- Does EASMLens scan our systems?
- Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test.
Primary sources
- BSSN Regulation 1 of 2024 (peraturan.go.id)
- Perpres 82/2022 on vital information infrastructure (BSSN)
- SEOJK 29/2022 summary (OJK)
- UU PDP 27/2022, article 46
Regulatory content reviewed on . General information only, not legal advice.