POJK Cybersecurity for Financial Institutions: An Implementation Guide from a Financial Investigation Perspective
Indonesia's financial sector faces increasingly sophisticated cyber threats. In 2025 alone, BSSN — the national cyber and crypto agency — recorded thousands of cyber attacks targeting Indonesian financial institutions, from phishing aimed at customers through to ransomware against banking infrastructure. But the greatest threat is not the technical attack itself — it is the intersection between cybercrime and financial crime, the cyber-financial crime nexus, which produces far larger losses.
As a former central bank financial investigator with investigative experience across the Asia-Pacific region, I have watched financial crime evolve from wholly manual to a digital-physical hybrid. This article examines the POJK cybersecurity regulation not merely from a technical IT perspective, but from the angle more relevant to our readers: how the regulation protects financial institutions from financial and reputational loss.
The Cyber-Financial Crime Nexus: A Threat Few People Understand
Most discussion of cybersecurity in financial services focuses on the technical: firewalls, encryption, vulnerability assessment. From a financial investigation perspective, however, what is more worrying is how cybercrime becomes the enabler for much larger financial crime.
Here are several patterns we identified while working in a financial intelligence unit:
- Business Email Compromise (BEC) + wire fraud: The attacker compromises a company executive's email, then instructs a transfer to an account they control. Losses per case can run to billions of rupiah
- Account takeover + money mule: A customer account is hijacked and funds moved through a network of "mule" accounts recruited via social media
- Data breach + identity fraud: Stolen KYC data is used to open fictitious accounts that then serve as laundering vehicles
- Ransomware + extortion: A ransomware attack followed by threats to publish customer data if the ransom goes unpaid
- Insider threat + data exfiltration: An employee about to resign steals customer data to sell to a fraud syndicate
A real case (anonymised): A mid-sized bank in Southeast Asia suffered a data breach exposing the KYC records of 50,000 customers. Over the following 6 months we detected a 400% increase in fictitious account openings using the identities of those customers. Those accounts were used as mule accounts to receive fraud proceeds. The total loss from fraud using the stolen data far exceeded the direct loss from the breach itself.
Understanding this nexus matters a great deal, and it is covered in Module 1: The Financial Sector Cyber Threat Landscape of our POJK Cybersecurity course, as well as in the Financial Crime Investigation course.
Breaking Down the POJK Cybersecurity Requirements
Module 2: The POJK Cybersecurity Regulatory Framework provides an in-depth analysis of the requirements. Here is a summary of the principal obligations financial institutions must meet:
1. Cybersecurity Governance
- Appointing a Chief Information Security Officer (CISO) or an officer of equivalent rank
- Establishing an information security unit or function independent of operational IT
- Adopting a cybersecurity policy approved by the board of directors
- Periodic reporting on cybersecurity posture to the board of directors and board of commissioners
2. Cyber Risk Management
- Identifying and classifying information assets by criticality
- Periodic risk assessment covering current cyber threats
- Implementing security controls proportionate to the risk profile
- Security testing (penetration testing, vulnerability assessment) at least annually
3. Cyber Resilience
- A Business Continuity Plan covering cyber incident scenarios
- A Disaster Recovery Plan with defined RPO and RTO
- Regular cyber incident simulations and drills
- The ability to restore critical services within a defined window
4. Incident Reporting
- An obligation to report cyber incidents to OJK within a defined deadline
- Incident classification by severity
- Root cause analysis for every significant incident
- Post-incident follow-up and remediation
Comparison: POJK vs BNM RMiT (Malaysia)
From experience working under the Bank Negara Malaysia regulatory framework, this comparison offers a valuable perspective. BNM issues Risk Management in Technology (RMiT), one of the most comprehensive cybersecurity regulations in ASEAN.
RMiT strengths Indonesia could adopt:
- Technology risk appetite statement: BNM requires banks to define a risk appetite specific to technology risk, separate from general operational risk appetite
- Third-party risk management: RMiT has highly detailed requirements on managing IT vendor risk, including cloud service providers
- Cyber threat intelligence sharing: BNM facilitates a highly effective inter-bank threat information sharing platform
- Board competency: RMiT requires at least one board commissioner to hold competency in technology or cybersecurity
Areas where POJK is already equal or better:
- Broader scope: POJK covers all financial services institutions, not banking alone
- Integration with data protection regulation: POJK is beginning to integrate the requirements of the Personal Data Protection Law, creating a more holistic framework
Standing Up a CSIRT: Computer Security Incident Response Team
Module 4: Cyber Incident Management and Reporting covers in detail how to build and run an effective CSIRT.
An effective CSIRT for a financial institution needs:
Team structure:
- Incident Commander: The primary decision-maker during an incident, usually the CISO or a deputy
- Technical Lead: Coordinates the technical response
- Communication Lead: Manages internal and external communication, including with the regulator
- Legal/Compliance Lead: Ensures the response meets regulatory obligations and preserves evidence for investigation
- Forensic Analyst: Performs digital forensic analysis
Response playbooks to prepare:
- Ransomware attack playbook
- Data breach playbook
- DDoS attack playbook
- Business Email Compromise playbook
- Insider threat playbook
- Third-party compromise playbook
From experience: When I helped a bank in the ASEAN region respond to a BEC incident that resulted in transfer fraud worth millions of dollars, the first 24 hours decided everything. The bank with a rehearsed BEC playbook managed to freeze the funds at the receiving bank within 4 hours. A bank without a playbook took 3 days to escalate properly — and by then the money had moved through 5 different countries.
Money Mule Detection: Where Cybersecurity Meets AML
Module 5: Financial Scams and Mule Accounts is a module you will not find on a conventional cybersecurity course. The material comes directly from financial intelligence unit experience.
Money mule accounts — accounts used to receive and move the proceeds of cybercrime — are the point where cybersecurity meets AML. Detecting them requires collaboration between the cybersecurity team and the AML/compliance team.
Characteristics of mule accounts:
- New accounts (opened less than 3 months ago) with a sudden surge in transaction activity
- A "receive and forward" pattern — taking in large sums then immediately transferring them onward, leaving a minimal balance
- An account holder inconsistent with the profile — a student or low-paid employee with transactions in the hundreds of millions
- Multiple accounts linked to a single phone number or IP address
- Transactions occurring outside the account holder's normal active hours
The detection strategy we recommend:
- Integrating fraud system alerts with AML system alerts
- Machine learning models that detect mule patterns through behavioural analytics
- Real-time monitoring for the "receive and forward" pattern
- Collaboration with other banks through information sharing mechanisms
For a deeper grounding in AML regulation, the AML/CFT Anti Money Laundering course provides comprehensive foundations.
Implementing an Information Security Framework: From ISO 27001 to Practice
Module 3: Implementing an Information Security Framework covers how to translate an international framework into an operational security programme. Financial institutions in Indonesia generally reference ISO 27001 and the NIST Cybersecurity Framework, but implementation is frequently inadequate.
The implementation approach we recommend:
- Gap assessment: Compare existing security controls against POJK requirements and international frameworks. Prioritise by risk, not by compliance checklist
- Risk-based prioritisation: Not every control matters equally. Focus on the controls protecting the most critical assets — customer data, core banking systems, and payment infrastructure
- Phased implementation: Roll out in stages, with quick wins early to build momentum and management support
- Continuous monitoring: Security is not a one-off project. Implement continuous monitoring against measurable KPIs
From watching implementations across a range of Southeast Asian financial institutions, the biggest mistake is treating cybersecurity as an IT project rather than a business programme. Cybersecurity has to be owned by senior management, not solely by the IT department.
A lesson from the field: One bank I helped evaluate held ISO 27001 certification, ran advanced firewalls, and had an expensive SIEM. Yet they suffered a large loss from a simple BEC attack, because they had no verification procedure for transfer instructions above a given threshold. Frameworks and tools are useless without the right operational procedures and people who understand them.
Designing an Effective Security Awareness Programme
Module 6: Security Awareness Programme stresses that technology alone is not enough. People remain both the weakest point and the strongest defence in cybersecurity.
The elements of an effective security awareness programme:
- Phishing simulation: Send simulated phishing emails periodically, measure the click rate, and give targeted training to those who fail
- Role-based training: Different material for tellers (social engineering), IT staff (technical attacks), executives (BEC/whaling), and customer service (vishing)
- Gamification: Leaderboards, badges, and rewards to lift engagement
- Real incident sharing: Share genuine incidents (anonymised) from the industry as case studies
- Metric-driven: Measure programme effectiveness against clear KPIs — phishing click rate, time to report, completion rate
Customer data protection also has to form part of the awareness programme. The PDP Law Compliance for the Financial Industry course sets out the full framework of personal data protection obligations.
Common mistakes in awareness programmes:
- One-size-fits-all: Delivering identical material to every employee without regard to their role and specific risk. A teller faces face-to-face social engineering while treasury staff face BEC risk — the awareness material should differ
- Annual-only training: Awareness training once a year is not enough. Threats evolve weekly. An effective programme includes weekly micro-learning, a monthly newsletter, and quarterly full training
- Not measuring effectiveness: Many financial institutions run awareness programmes without measuring whether employee behaviour actually changed. Phishing simulation rate and incident reporting rate are the minimum metrics to track
- A blame culture: Punishing employees who fail a phishing test creates a culture of hiding incidents. An effective programme instead treats failure as a teaching moment and encourages reporting without fear
What the Course Covers
Our POJK Cybersecurity for Financial Institutions course is unusual in addressing not only the technical dimension but the financial investigation and compliance perspective as well. The module map:
- Module 1 — The Financial Sector Cyber Threat Landscape: The current threat landscape, the cyber-financial crime nexus, case studies of cyber attacks on ASEAN financial institutions
- Module 2 — The POJK Cybersecurity Regulatory Framework: A breakdown of the requirements, gap analysis against international standards, an implementation roadmap
- Module 3 — Implementing an Information Security Framework: ISO 27001, NIST CSF, and adapting them for Indonesian financial services. Prioritising controls by risk profile
- Module 4 — Cyber Incident Management and Reporting: Standing up a CSIRT, response playbooks, reporting to OJK, coordinating with BSSN and law enforcement
- Module 5 — Financial Scams and Mule Accounts: Money mule detection, social engineering attacks, BEC, and where cybersecurity meets AML
- Module 6 — Security Awareness Programme: Designing a measurable, effective awareness programme, phishing simulation, and security culture
The instructor is a practitioner with financial intelligence unit investigative experience, who understands that cybersecurity in financial services is not only about technology — it is about protecting the integrity of the financial system from exploitation.
FAQ: POJK Cybersecurity
Does the POJK cybersecurity regulation apply to every financial institution?
Yes. It applies to every financial services institution supervised by OJK, including banks, insurers, financing companies, securities firms, and fintechs. OJK does apply a proportionality principle, however — larger and systemically important institutions are expected to run a more comprehensive cybersecurity programme.
How does POJK cybersecurity relate to the Personal Data Protection Law?
The two are complementary. POJK focuses on system and infrastructure security, while the PDP Law focuses on protecting customers' personal data. In practice, good cybersecurity is a prerequisite for PDP compliance — you cannot protect personal data if your systems are open to attack. Our course covers integrating the two.
What does POJK cybersecurity implementation cost?
It varies widely with the size and complexity of the institution. For a mid-sized bank, initial investment might range from IDR 5-15 billion for infrastructure, tooling, and people. That cost is far smaller than the potential loss from a major cyber incident. A single data breach in financial services can cause losses in the hundreds of billions once fines, litigation, and lost customer trust are counted.
Does a bank need its own CSIRT, or can it outsource?
POJK expects financial institutions to hold internal incident response capability. That does not mean a large full-time CSIRT is required. Mid-sized and smaller banks can maintain a core internal team supported by a managed security service provider (MSSP) for monitoring and analysis. What matters is that the capability exists and has been tested, not the headcount.
What is the relationship between cybersecurity and AML?
This is a highly relevant question and one that is rarely asked. Modern cybercrime almost always resolves into financial crime — attackers breach systems not to demonstrate technical skill but to steal money. For that reason, the cybersecurity and AML/compliance teams have to work closely together. Alerts from both systems should be integrated, and every cyber incident investigation should consider the financial dimension.