Compliance guide

PADG 24/2024 Compliance Guide

PADG 24/2024 is the operational rulebook that turns Bank Indonesia's PBI 2/2024 into concrete duties: an annual information-security and cyber-resilience audit, a maturity rating, and a report due every 31 January. Claro helps you exercise and evidence the human layer that runs through it.

Regulator
Bank Indonesia
Applies to
Payment system operators (PJP), money and forex market players (PUVA), and other Bank Indonesia-supervised parties

Overview

Peraturan Anggota Dewan Gubernur No. 24 of 2024 on Information System Security and Cyber Resilience, known in Indonesian as Keamanan Sistem Informasi dan Ketahanan Siber or KKS, is the implementing regulation for Bank Indonesia Regulation No. 2 of 2024 (PBI 2/2024). Where PBI 2/2024 sets the legal mandate, PADG 24/2024 supplies the operational detail: what a supervised party must actually do, how its cyber resilience is measured, and how results are reported to Bank Indonesia. The two are read together, with PADG 24/2024 as the practical rulebook underneath the parent regulation.

Its scope is broad. Beyond payment service providers (PJP) and payment system infrastructure operators (PIP), PADG 24/2024 reaches money market and foreign exchange market players (PUVA), currency exchange operators, supporting institutions, and other parties regulated and supervised by Bank Indonesia. In practice this means a large part of Indonesia's payment and market ecosystem is expected to run a comparable, proportional cyber-resilience program rather than treating security as an IT-only concern.

PADG 24/2024 is commonly described through several pillars: governance and a security-aware culture that reaches every employee; risk prevention through identification, protection, and early detection; incident response and recovery with tested plans and simulations; reporting and transparency to Bank Indonesia; collaboration and threat-intelligence sharing across institutions; and proportional implementation scaled to each organization's risk profile. The most operationally significant duties are the requirement to run a KKS audit at least once a year, to rate cyber-resilience maturity on a defined scale, and to submit the audit result and maturity level to Bank Indonesia no later than 31 January each year for the previous year, with the first cycle covering 2025 and due in January 2026.

This page offers general information and is not legal advice. Supervised parties should confirm the precise scope, article-level obligations, timelines, maturity methodology, and reporting format that apply to them with qualified counsel and their Bank Indonesia supervisory contacts. Claro supports the human-layer elements of KKS, including awareness, phishing simulation as part of resilience exercises, and the evidence to back them up, but Claro alone does not make an organization compliant. Compliance depends on the full governance, prevention, response, audit, and reporting program that PADG 24/2024 and PBI 2/2024 require.

What the rule expects

Governance and a security-aware culture

PADG 24/2024 expects cyber resilience to be governed from the top with clear policies, roles, and a culture that reaches every employee, not just the IT team. A workforce that understands its role in defense is part of that culture.

Risk prevention and early detection

Supervised parties must identify threats, protect systems, and detect suspicious activity early. People who spot and report a lure quickly are often the earliest detection layer, ahead of any technical control.

Incident response and recovery

Response and recovery plans must exist and be exercised through simulations, not just documented. The human layer of detecting, reporting, and escalating a cyber event is a natural part of those exercises.

Annual KKS audit

An information-security and cyber-resilience (KKS) audit must be carried out at least once a year, using an internal or qualified external auditor. Structured records of awareness activity and simulation results support the human-layer scope of that audit.

Cyber-resilience maturity rating

Results are expressed as a maturity level on a defined scale, commonly described as basic, intermediate, and advanced. Measuring how the workforce detects and reports over time gives defensible input to that rating.

Reporting to Bank Indonesia by 31 January

The audit result and maturity level must be reported to Bank Indonesia no later than 31 January each year for the prior year. Evidence packages and audit-ready reports make that submission accurate and timely.

Proportional implementation and collaboration

Obligations are scaled to each organization's risk profile, and the regulation encourages threat-intelligence sharing across institutions. A repeatable awareness and simulation program keeps a proportional program running as threats change.

How Claro helps you comply

  • Phishing simulation for resilience exercises

    Claro runs realistic, bilingual phishing campaigns with scheduling, throttling, and per-recipient tracking. These can form the human-layer component of the resilience simulations PADG 24/2024 expects and produce a clear record of how staff responded. Scenarios can reflect the lures that target payment and market operations, so the exercise mirrors real risk.

  • Security culture across every employee

    PADG 24/2024 pushes cyber resilience beyond IT to the whole workforce. Claro's continuous, role-relevant micro-modules and just-in-time awareness help embed the security-aware culture the governance pillar calls for, in English and Bahasa Indonesia.

  • Phish-report button strengthens early detection

    The Claro reporting button for Outlook and Gmail turns employees into human sensors who flag suspicious mail in one click. Faster detection shortens dwell time and supports the prevention and response the regulation expects.

  • Human-risk scoring and maturity evidence

    Claro scores human risk by user and department and tracks how detection and reporting improve over time. This gives defensible, trend-based input to the cyber-resilience maturity rating and shows where exposure concentrates.

  • Evidence packages for the KKS audit and 31 January report

    Claro generates evidence packages and Claro-style PDF reports backed by detailed audit logs. Each exercise leaves a documented trail of participation, results, and follow-up training, giving auditors and Bank Indonesia structured material for the annual KKS audit and the report due by 31 January.

  • Repeatable, scheduled testing

    Claro's campaign engine and scheduled report delivery make it straightforward to run recurring simulations and produce results on a regular cadence, supporting the at-least-annual audit and the ongoing, proportional program the regulation calls for.

Frequently asked questions

  • PADG 24/2024 is Peraturan Anggota Dewan Gubernur No. 24 of 2024 on Information System Security and Cyber Resilience (KKS). Issued by Bank Indonesia, it is the technical implementing rule for PBI 2/2024 and sets out the operational duties, including an annual KKS audit, a maturity rating, and reporting to Bank Indonesia.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo