Resources

Guides, checklists,and field-tested playbooks

Practical resources on phishing simulation, security awareness, and Indonesian compliance, written for security and compliance leaders.

Guide

What Is Smishing? SMS and WhatsApp Phishing Explained (and How to Defend Against It)

A text message from 'your bank' feels more urgent and more personal than an email ever could. Smishing exploits exactly that trust, and in a country where SMS and WhatsApp are the primary channel for banking, courier, and government notifications, the attack works disturbingly well.

Jul 29, 20267 min read
Read more
Report

Phishing Benchmarks for Indonesian Organisations: What Published Data Shows

A synthesis of published 2025 and 2026 figures from BSSN and the Verizon DBIR, assembled for Indonesian security teams who need defensible external reference points. Not original research, and the gaps are stated as plainly as the numbers.

Jul 28, 202610 min read
Read more
Checklist

Security Awareness Platform RFP Checklist for Indonesian Organisations

A vendor-neutral requirements checklist for procuring a security awareness and phishing simulation platform in Indonesia, covering the questions that separate vendors rather than the ones every vendor answers yes to.

Jul 28, 202611 min read
Read more
Guide

UU PDP Sanctions: What Non-Compliance Actually Costs

Indonesia's Personal Data Protection Law carries administrative, civil and criminal consequences. A practical breakdown of the 2 percent administrative fine, the criminal provisions under Article 67, and the additional penalties that apply to corporations.

Jul 28, 20269 min read
Read more
Guide

Data Protection Officer under UU PDP: When You Must Appoint One

UU PDP requires certain organizations to appoint an officer performing the personal data protection function. The three triggers in Article 53, what the role actually does, and how it differs from the GDPR DPO.

Jul 28, 20268 min read
Read more
Guide

Personal Data Classification under UU PDP: Specific vs General

UU PDP Article 4 splits personal data into two categories, and the distinction drives most of your obligations. What counts as specific personal data, what counts as general, and why the boundary matters operationally.

Jul 28, 20267 min read
Read more
Guide

ISO 27001 Certification Cost in Indonesia: What Drives the Number

Certification quotes vary widely, and the headline audit fee is rarely the largest line. A breakdown of every cost component, the variables that move them, and the ones organizations consistently underestimate.

Jul 28, 20268 min read
Read more
Guide

IT Risk Management under OJK: What Banks Must Demonstrate

OJK expects Indonesian banks to run information technology risk management as a governed, evidenced discipline. What the regulator looks for, where the human factor sits, and how to evidence the awareness component.

Jul 28, 20268 min read
Read more
Guide

What Is Quishing? QR Code Phishing Explained (and How to Defend Against It)

A QR code looks harmless because it looks like nothing at all: no visible link to inspect, no domain to squint at. That is exactly why quishing, phishing delivered through QR codes, is becoming one of the fastest-growing attack vectors in Indonesia's QRIS-first payment culture.

Jul 25, 20267 min read
Read more
Checklist

Mapping Security Awareness Training to Compliance Evidence: A Practical Checklist for OJK, UU PDP, and ISO 27001

Auditors do not want to hear that you 'ran some phishing tests.' They want to see evidence: who was tested, who failed, who was retrained, and how risk changed over time. Here is how to build that evidence pack before the audit, not during it.

Jul 22, 20268 min read
Read more
Guide

ISO/IEC 27001 Annex A Awareness Controls in Practice

Awareness and training obligations in ISO/IEC 27001 Annex A are easy to state and hard to evidence. Here is how phishing simulation and training programs translate into audit-ready ISMS records.

Jul 18, 20269 min read
Read more
Guide

Reducing Repeat Clickers: A Behaviour-Change Playbook

A small group of habitual clickers usually drives most of an organization's phishing risk. Here is a fair, evidence-based way to identify them and move them toward safer behaviour.

Jul 15, 20269 min read
Read more
Guide

Just-in-Time Awareness: Teaching at the Moment of the Click

The single most effective moment to teach someone about phishing is right after they almost fall for it. Here is how just-in-time awareness pages work, and why they outperform annual training.

Jul 11, 20267 min read
Read more
Guide

How to Measure Security Culture: Beyond Completion Rates

Completion rates tell you who clicked through a course, not who behaves differently under pressure. Here is how to build a real security-culture scorecard.

Jul 8, 20268 min read
Read more
Guide

WhatsApp Phishing in Indonesia: Why It's the Channel Attackers Prefer

In Indonesia, WhatsApp is where business actually happens, and attackers know it. This guide covers what WhatsApp phishing looks like, the red flags employees should learn to spot, and how to build reporting habits that close the gap email-only training leaves open.

Jul 4, 20267 min read
Read more
Guide

OJK POJK 11/2022 and Phishing Resilience: What Banks Must Prove

OJK's POJK 11/2022 raises the bar for cyber resilience at Indonesian banks, and human risk is very much part of that picture. This guide breaks down what the regulation implies for phishing readiness, and how a structured simulation and training program gives boards and examiners the evidence they need.

Jun 30, 20269 min read
Read more
Guide

What Is Vishing (Voice Phishing) and How to Simulate It

Vishing, or voice phishing, uses a phone call instead of an email to pressure someone into handing over credentials, one-time passwords, or money. This guide explains why the phone remains such an effective attack channel, how vishing shows up in Indonesia, and how security teams can simulate it responsibly.

Jun 25, 20268 min read
Read more
Guide

How to Build a Security Awareness Program from Scratch

A security awareness program is more than an annual training video. This guide walks through setting a baseline, choosing the right cadence, using just-in-time training, building a reporting culture, and picking metrics that actually predict risk.

Jun 22, 20269 min read
Read more
Guide

Human Risk Management vs Security Awareness Training: What's the Difference

Security awareness training teaches people what phishing looks like. Human risk management measures and reduces the actual risk each person represents. This guide explains the difference, why completion rates are a vanity metric, and how risk scoring changes what success means.

Jun 18, 20267 min read
Read more
Guide

BSSN and Security Awareness: What Indonesian Organizations Should Know

BSSN (Badan Siber dan Sandi Negara) plays a central role in shaping Indonesia's national cybersecurity posture. This guide explains BSSN's general role, what public bodies and critical infrastructure operators are generally expected to demonstrate, and how ongoing awareness, simulation, and evidence support that readiness.

Jun 15, 20268 min read
Read more
Guide

How to Reduce Your Phish-Prone Rate: A Practical Guide for Indonesian Organizations

A field guide to lowering your organization's phish-prone rate through realistic simulation, just-in-time training, and a reporting culture that turns employees into a human sensor network.

May 30, 20266 min read
Read more
Guide

UU PDP Readiness: A Practical Guide to Workforce Awareness and Breach Reporting

A working guide to Indonesia's Personal Data Protection Law (UU PDP, Law 27/2022) for security and compliance leaders, focused on the two areas regulators look at first: workforce awareness and breach notification.

May 26, 20269 min read
Read more
Checklist

The OJK Cyber Resilience Checklist for Indonesian Banks

A practical, evidence-first checklist for Indonesian banks building cyber resilience under POJK 11/2022 and SEOJK 29/2022, with the human layer treated as a controlled, measurable line of defense.

May 19, 20268 min read
Read more
Guide

What Is Phishing Simulation? A Practical Guide for Security and Compliance Leaders

Phishing simulation sends safe, controlled fake phishing emails to your own employees to measure who is vulnerable and turn that data into targeted training. Here is how it works and how to run a program that actually reduces human risk.

May 12, 20267 min read
Read more

Ready to act on it?

See how Claro turns these ideas into a running program.

Request a demo