National cyber security guidance

Strengthen the human layer BSSN guidance emphasizes

BSSN promotes national standards for security awareness, incident response, and the resilience of electronic systems. Claro helps you build and evidence the human-layer controls that sit at the centre of that guidance.

Regulator
Badan Siber dan Sandi Negara (BSSN)
Applies to
Government bodies, critical infrastructure, and enterprises in Indonesia

Overview

Badan Siber dan Sandi Negara (BSSN) is Indonesia's National Cyber and Crypto Agency. Rather than a single numbered statute, BSSN issues guidance, technical standards, and maturity expectations that shape how government bodies and operators of critical information infrastructure defend their electronic systems. Its remit spans security awareness, incident response readiness, and the protection of national data assets. For most organizations, BSSN guidance is the practical reference point for what a credible cyber security posture looks like in Indonesia.

A recurring theme across BSSN guidance is that people are both the most targeted and the most improvable part of any defence. Phishing and social engineering remain the primary way attackers gain an initial foothold, so workforce awareness and the ability to report suspicious activity quickly are treated as core capabilities, not optional extras. BSSN also encourages organizations to stand up incident response functions such as Computer Security Incident Response Teams (CSIRTs) that can triage and contain threats. Fast human reporting is what feeds those teams the early signal they need, often well before automated tooling would flag the same activity. In an Indonesian context, where attacks frequently use local language and locally relevant pretexts, awareness content that reflects those tactics matters a great deal.

BSSN guidance further emphasizes continuous improvement: measuring where you are, closing gaps, and demonstrating that controls actually work over time. This favours programs that generate evidence, such as awareness metrics, simulation results, and reporting rates, rather than one-off training that is hard to verify. Resilience is framed as an ongoing discipline across people, process, and technology, with the human layer often being the fastest to strengthen and the easiest to neglect.

This page is general information to help you plan a human-risk program aligned to BSSN guidance; it is not legal advice. BSSN expectations evolve and can be interpreted alongside sector rules, so confirm the current requirements with official BSSN publications and qualified counsel. Claro supports the awareness, simulation, reporting, and evidence controls that BSSN guidance emphasizes, but a tool alone does not make an organization compliant; that depends on how you operate people, process, and technology together.

What the rule expects

Build organization-wide security awareness

BSSN guidance treats a security-aware workforce as a foundational control against social engineering. Organizations are expected to run ongoing awareness activity rather than a single annual briefing, and to reach every role that touches sensitive systems or data.

Reduce exposure to phishing and social engineering

Because phishing is a leading initial-access vector, BSSN emphasizes practical resilience against deceptive emails, messages, and calls. This means testing how people actually respond to realistic lures, not just whether they can recite policy.

Establish rapid incident reporting and CSIRT workflows

BSSN encourages incident response capability, including CSIRTs that can triage and contain threats quickly. A fast, low-friction way for staff to report suspected phishing is what gives those teams early warning and shortens detection time.

Protect the confidentiality and integrity of electronic systems

Guidance stresses safeguarding national and organizational data across its lifecycle. Human error and credential theft are common causes of exposure, so awareness and reporting controls directly support the protection of electronic systems.

Measure security maturity and demonstrate improvement

BSSN favours a continuous-improvement posture: know your baseline, close gaps, and show progress over time. Organizations should be able to evidence that awareness and behaviour are actually improving, not just that training was delivered.

Prioritize protection for critical information infrastructure

Operators of critical infrastructure face heightened expectations for resilience and readiness. Awareness and reporting programs should give extra attention to high-risk roles and departments that would cause the greatest impact if compromised.

Support national data residency and sovereignty

Government bodies in particular value keeping sensitive data within controlled, sovereign environments. Any awareness and simulation platform handling employee data should offer deployment and data-handling options that respect these expectations.

How Claro helps you comply

  • Localized phishing simulations for real resilience

    Claro runs bilingual (English and Bahasa Indonesia) phishing simulations with scheduling, throttling, and per-recipient tracking of opens, clicks, submissions, and reports. This tests how staff genuinely respond to social engineering, which is exactly the human-layer resilience BSSN guidance prioritizes.

  • A phish-report button that feeds CSIRT workflows

    The Claro phish-report button, delivered through an Outlook add-in and a Gmail extension, turns employees into human sensors. Reports flow into a central loop that shortens detection time and gives incident responders the early signal that CSIRT-style workflows depend on.

  • Just-in-time training the moment someone slips

    When a user fails a simulation, Claro shows an instant awareness page and auto-enrols them in role-relevant micro-modules. This converts a mistake into a targeted teaching moment and sustains the ongoing awareness BSSN expects.

  • Bilingual micro-modules and learning paths

    Claro's micro-module training system delivers short bilingual lessons, supports SCORM 1.2 import, and organizes content into learning paths with automated assignment rules. This keeps awareness continuous and role-appropriate across the whole workforce.

  • Risk scoring to focus on your highest-risk people

    Per-user and per-department risk scoring, backed by a gamification and behaviour engine, highlights where exposure concentrates. That lets you give critical-infrastructure roles and repeat-clickers the extra attention BSSN guidance calls for.

  • Evidence packages and on-premise deployment

    Claro's compliance module produces control-coverage mapping, evidence packages (ZIP bundles of PDFs and CSVs), and Claro-style reports for leadership. On-premise deployment with per-tenant isolation and AES-256-GCM encryption at rest supports data-residency expectations valued by Indonesian government bodies.

Frequently asked questions

  • No. BSSN issues guidance, standards, and maturity expectations rather than one numbered pass-or-fail certification. The practical goal is a demonstrable security posture, including a security-aware workforce and incident response readiness, that you can evidence over time.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo