Compliance guide

Bank Indonesia (PBI 2/2024) Compliance Guide

Bank Indonesia asks payment providers to manage cyber risk, test recovery, and run a cyber-resilience simulation at least once a year. Claro helps you exercise and evidence the human layer of that resilience.

Regulator
Bank Indonesia
Applies to
Payment service providers (PJP) and payment system infrastructure operators (PIP)

Overview

Bank Indonesia Regulation No. 2 of 2024 on Information System Security and Cyber Resilience, often referred to as ISSCR, strengthens cyber defenses across Indonesia's payment ecosystem. It applies to payment service providers, known as PJP, and payment system infrastructure operators, known as PIP, that operate under Bank Indonesia supervision. The regulation responds to the rising volume and sophistication of attacks on payment rails, where availability and trust are essential. Its aim is to raise the baseline of cyber risk management for both bank and non-bank players in the payment system.

The regulation expects providers to maintain adequate risk-management policies and standard operating procedures that govern how information systems are secured and how cyber risk is handled. Service availability is a specific concern, since disruption to payment services affects the wider economy. Providers are also expected to plan for recovery, with a disaster recovery plan that is not just documented but tested on a regular basis. Governance, documentation, and repeatable testing run through the regulation. Because the payment ecosystem includes many interconnected players, weakness at one provider can ripple outward, which is why the baseline expectations apply consistently across bank and non-bank participants.

A distinctive requirement is that providers must run a cyber resilience simulation at least once a year. This is an exercise-based expectation: it is not enough to describe resilience on paper, providers must practice how they would detect, respond to, and recover from a cyber event. The human layer is a natural part of such simulations, because the people who receive, report, and respond to suspicious activity are central to whether an attack succeeds. Providers are also expected to report their ISSCR implementation to Bank Indonesia.

This page offers general information and is not legal advice; PJP and PIP should confirm the precise scope, timelines, and reporting format that apply to them with qualified counsel and their Bank Indonesia supervisory contacts. Claro supports the human-layer elements of ISSCR, including awareness, phishing simulation as part of resilience exercises, and the evidence to back them up, but Claro alone does not make a provider compliant. Compliance depends on the full risk-management, availability, recovery, and reporting program the regulation requires.

What the rule expects

Risk-management policies and procedures

Providers must maintain adequate risk-management policies and standard operating procedures for information system security. These should govern how cyber risk, including the human element, is identified and controlled.

Service availability

Because payment disruption has wide economic impact, providers are expected to protect the availability of their services. Reducing successful attacks through a resilient workforce contributes to keeping services running.

Regular disaster recovery plan testing

A disaster recovery plan must be maintained and tested on a regular basis, not simply documented. Testing verifies that response and recovery actually work when they are needed.

Annual cyber resilience simulation

Providers must run a cyber resilience simulation at least once a year. This exercise should reflect realistic scenarios, and the human layer of detection and response is a natural part of it.

Human-layer detection and response

People who receive and report suspicious activity are central to whether an attack succeeds. A workforce that detects and reports quickly strengthens the response and recovery the regulation expects.

ISSCR reporting to Bank Indonesia

Providers are expected to report their ISSCR implementation to Bank Indonesia. Structured evidence of controls, tests, and results supports accurate and timely reporting.

Ongoing awareness across the payment ecosystem

Strengthening defenses across bank and non-bank payment players relies on a security-aware workforce. Continuing, role-relevant awareness keeps staff prepared as attacker techniques change.

How Claro helps you comply

  • Phishing simulation for resilience exercises

    Claro runs realistic, bilingual phishing campaigns with scheduling, throttling, and per-recipient tracking. These can form the human-layer component of an annual cyber resilience simulation and produce a clear record of how staff responded. Scenarios can reflect the lures that target payment operations, so the exercise mirrors real risk rather than a generic template.

  • Phish-report button strengthens response

    The Claro reporting button for Outlook and Gmail turns employees into human sensors who flag suspicious mail in one click. Faster detection shortens dwell time and supports the response and recovery the regulation expects.

  • Just-in-time awareness and training

    When a user fails a simulation, Claro shows an instant awareness page and auto-enrolls them in role-relevant micro-modules. This turns each exercise into measurable improvement in workforce readiness.

  • Human-risk scoring by user and department

    Claro scores human risk at the user and department level so payment providers can see where exposure concentrates. This supports the risk-management policies and targeted controls the regulation expects.

  • Evidence packages and reports for reporting

    Claro generates evidence packages and Claro-style PDF reports backed by detailed audit logs. This gives providers structured material to support ISSCR reporting to Bank Indonesia and internal governance. Each exercise leaves a documented trail of participation, results, and follow-up training, which is useful when demonstrating that the annual simulation was actually carried out.

  • Repeatable, scheduled testing

    Claro's campaign engine and scheduled report delivery make it straightforward to run recurring simulations and produce results on a regular cadence. This supports the repeatable testing the regulation calls for, including annual exercises.

Frequently asked questions

  • It applies to payment service providers, known as PJP, and payment system infrastructure operators, known as PIP, that operate under Bank Indonesia supervision. This covers both bank and non-bank players in the payment ecosystem.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo