BSSN's Role in Indonesia's Cybersecurity Landscape
BSSN, Badan Siber dan Sandi Negara, is Indonesia's national cyber and crypto agency, established in 2017 and reporting directly to the President. It coordinates national cybersecurity policy, plays a central role in incident response coordination at the national level, and works alongside sector regulators, such as OJK for financial services, and with operators of critical infrastructure to raise the country's overall baseline of cyber readiness.
BSSN's work spans policy guidance, coordination of national incident response capability, protection of critical information infrastructure, and capacity building across government and industry. Organizations that operate critical infrastructure or handle significant volumes of public data are generally expected to maintain a baseline level of cybersecurity readiness that includes a human element, not purely technical controls like firewalls and monitoring tools.
It is worth being clear about the limits of this article: specific obligations vary considerably by sector and organization type, and should be confirmed against current regulation together with legal and compliance advisors. What follows is general orientation on the topic, not legal advice, and should not be treated as a substitute for professional guidance specific to any organization's situation.
What Readiness Generally Looks Like for Public Bodies and Critical Infrastructure
In general terms, readiness expectations for public bodies and critical infrastructure operators include documented security policies, an incident response plan, regular risk assessment, and increasingly, evidence that staff understand and are resilient against social engineering, since people remain one of the most common entry points for attackers regardless of how strong an organization's technical controls are.
Readiness is increasingly evaluated as an ongoing program rather than a one-time certification exercise. This means organizations benefit from being able to show a continuous record: when awareness training was delivered and to whom, how staff responded to realistic simulated attacks over time, and what remediation followed when gaps were found. A single point-in-time exercise says far less than a running record of improvement.
There is meaningful overlap between this general expectation and frameworks many organizations already reference, ISO 27001 controls, or sector-specific rules such as POJK 11/2022 for financial institutions. A well-coordinated human risk program tends to generate evidence that supports several of these frameworks at once, rather than requiring a separate initiative to satisfy each one individually.
Why Awareness and Simulation Matter for Demonstrating Readiness
Phishing simulation, vishing simulation, and short micro-training modules naturally create an auditable trail as a byproduct of running them: campaign records, click and reporting rates over time, and a full history of training assignment and completion. That trail is genuinely useful evidence when demonstrating a functioning human risk program to internal auditors, a board, or an oversight body, because it shows activity rather than a claim of activity.
The real objective, though, is behavior change, not simply running simulations to produce a report. A click rate that declines and a reporting rate that rises across successive campaigns is a far more convincing signal of readiness than a single test conducted once and never repeated, because it demonstrates that the organization's people are actually getting better at recognizing attacks over time.
Combining channels, email phishing, voice phishing, and WhatsApp-based simulation, also reflects how attackers actually try to reach employees in Indonesia today. An organization that tests only email is measuring a narrowing slice of its real exposure, and a more complete simulation program across channels gives a fuller and more honest picture of where the organization actually stands.
Where BSSN Guidance Meets UU PDP and Sector Rules
Cybersecurity readiness in Indonesia does not sit in isolation from data protection. UU No. 27 Tahun 2022, the Personal Data Protection Law (UU PDP), places obligations on organizations that process personal data, including a duty to protect that data with appropriate security measures. Human error in phishing attacks is a common route to the kind of data exposure the law is concerned with.
For many organizations, the same social-engineering weakness that BSSN-aligned readiness expectations address is also a personal-data risk under UU PDP, and, for financial institutions, a matter covered by OJK rules such as POJK 11/2022. A single successful phishing attack can raise concerns across all three at once.
The practical upshot is that a well-run human risk program rarely serves just one requirement. Reducing the chance that an employee hands over credentials or customer data to an attacker supports national readiness expectations, personal-data protection duties, and sector supervision simultaneously, which is why treating them as one coordinated effort is more efficient than chasing each separately.
Building an Evidence Trail That Survives Scrutiny
When any reviewer, an internal auditor, a board committee, or an oversight body, asks how an organization manages human risk, the strongest answer is a record rather than an assurance. A continuous evidence trail shows what was done, when, and to what effect, which is far more convincing than a policy document describing what should happen.
A useful trail includes dated campaign records, click and reporting rates tracked over successive rounds, training assignment and completion history, and notes on the remediation that followed when gaps appeared. The value lies in continuity: a single exercise proves an event happened, while a running record proves a program exists.
Assembling this evidence after a request arrives is stressful and rarely complete. Generating it as a natural byproduct of an ongoing program means the record already exists when it is needed, which is both less work under deadline and considerably more credible than a hastily compiled snapshot.
Practical First Steps for an Indonesian Organization
For an organization starting from a limited awareness effort, the first move is a baseline: a realistic simulation across the workforce to establish where things actually stand before any content is chosen. Without that measurement, later improvement cannot be demonstrated, only asserted.
From there, a steady cadence of simulations paired with short training modules, delivered in Bahasa Indonesia and reflecting local lures, builds the habit and the record at the same time. Extending beyond email to voice and WhatsApp early on reflects how attackers actually operate in Indonesia and avoids measuring only a narrow slice of exposure.
Finally, decide up front how results will be reviewed and reported. Setting a regular review rhythm and a simple reporting format for leadership turns the program from a series of disconnected activities into a coherent, defensible effort, one that stands up whether the audience is an executive team or an external reviewer.
How Claro Supports This Without Replacing Legal Guidance
Claro's platform generates the underlying data, simulation results, training records, and risk scores, that a human risk program produces day to day, and compiles that data into structured reports and evidence packages that map to frameworks commonly referenced by regulated organizations operating in Indonesia.
It is worth restating clearly that Claro does not provide legal advice and does not guarantee regulatory compliance on its own. Organizations should validate their specific obligations with legal counsel and with the relevant regulator or oversight body for their sector before relying on any platform, including Claro, as their sole basis for a compliance position.
In practical terms, treating BSSN's broader guidance as a reason to run an ongoing, evidence-generating awareness program, rather than a one-off training push before an audit, is both good practice on its own merits and considerably easier to defend during any future review, since the evidence already exists rather than needing to be assembled after the fact.
Key takeaways
- BSSN coordinates Indonesia's national cybersecurity posture and works alongside sector regulators to raise baseline readiness.
- Readiness is increasingly judged as an ongoing program, not a one-time training event or certificate.
- A single human risk program can support BSSN-aligned readiness, UU PDP data-protection duties, and sector rules at once.
- Documented, continuous awareness and simulation records give organizations auditable evidence of a functioning human risk program.
- Combining email, vishing, and WhatsApp simulation reflects how attackers actually reach employees, not just one channel.
- This article is general orientation, not legal advice, confirm specific obligations with legal counsel and your sector regulator.