Why a checklist beats a binder
Most Indonesian banks already have a thick information security policy. The gap regulators care about is rarely the existence of a policy. It is whether the bank can show, on demand, that the controls described actually operate and produce evidence. POJK 11/2022 (Penyelenggaraan Teknologi Informasi oleh Bank Umum) and its companion circular SEOJK 29/2022 push exactly in this direction: structured governance, cybersecurity maturity assessment, periodic testing, and disciplined incident reporting to OJK.
This guide turns those expectations into a working checklist. Treat each item as a question an examiner could ask: not 'do you have a policy on this?' but 'show me the last time this ran, who signed off, and what changed as a result.' The aim is to make resilience legible, not to add paperwork.
One caveat before you start. The text below is a practitioner summary, not legal advice. Always reconcile your program against the current official text of POJK 11/2022 and SEOJK 29/2022, and against any later OJK guidance, with your own compliance and legal functions.
1. Governance and accountability
Resilience starts with clear ownership. Confirm that a named unit or function is formally accountable for cyber resilience and security, and that this is reflected in your organizational structure, not just an email. POJK 11/2022 expects banks to have a function responsible for cyber resilience and security, with the Board of Directors carrying ultimate accountability for IT risk.
Checklist: a Board-approved IT and cyber risk policy that is reviewed at least annually; a documented IT risk appetite tied to the bank's overall risk appetite; a function or unit owning cyber resilience with a clear reporting line to the Board; and minuted Board or committee discussions where cyber risk and key incidents were actually reviewed. The evidence here is governance artifacts: approval dates, version history, attendance, and decisions.
If your Board reviews cyber risk once a year as a formality, that is a finding waiting to happen. Aim for a recurring cadence where real metrics (open incidents, testing results, training and phishing-simulation outcomes) reach the Board in a form they can challenge.
2. Risk identification, assessment, and third parties
You cannot protect what you have not mapped. Maintain a current inventory of critical electronic systems, the data they process, and their dependencies, including outsourced and cloud providers. POJK 11/2022 requires banks to identify, evaluate, and mitigate IT-related risks, including operational, data-breach, and cyber-attack risk, and sets expectations around the location of data centers and disaster recovery centers, with placement abroad generally requiring OJK approval.
Checklist: an asset and data inventory that is reviewed on a defined schedule; a documented IT risk assessment methodology with results that feed into mitigation plans; due diligence and ongoing monitoring for technology service providers, with contractual security and audit rights; and a clear record of where critical systems and data reside, plus the basis for any cross-border placement.
Third-party and concentration risk is a recurring examiner theme. For each material provider, be able to show the risk rating, the last review date, the right to audit, and the exit or continuity plan if that provider fails.
3. Cybersecurity maturity, testing, and the human layer
SEOJK 29/2022 brings cybersecurity testing and maturity assessment to the foreground. Banks are expected to assess their cybersecurity maturity and to test their defenses on a periodic basis. In practice this means vulnerability assessments, penetration testing, and, for systemically important banks, more advanced exercises. Document scope, findings, severity, remediation owners, and closure dates for each test cycle.
The human layer belongs inside this section, not as an afterthought. The dominant entry point for real attacks on banks is people: phishing, business email compromise, vishing, and increasingly WhatsApp-based social engineering. Treat your workforce as a control you can measure. That means running realistic phishing simulations, tracking click and report rates by department, delivering just-in-time training when someone falls for a simulation, and watching whether risk scores improve over time.
Checklist for the human layer: a baseline phishing-simulation result and a trend line, not a single annual number; mandatory security-awareness training with completion and assessment records; a frictionless way for staff to report suspicious messages, with reporting rate tracked as a positive signal; and remedial micro-training assigned automatically to repeat clickers. When OJK or an internal auditor asks how you manage human risk, you want a dashboard, not an anecdote. This is precisely the kind of measurable, behavior-change evidence Claro is built to produce.
4. Incident response and OJK reporting
Detection and response are where resilience is proven under pressure. POJK 11/2022 sets clear expectations for incident handling and for notifying and reporting IT and cyber incidents to OJK, including early notification of significant incidents followed by fuller reports. Your incident response plan must name the OJK reporting trigger and timeline explicitly, so the duty officer is never guessing during a live event.
Checklist: a documented incident response plan with severity classification and defined OJK notification triggers and timelines; named roles and an out-of-hours escalation chain; integration of your reporting tooling (SIEM, phish reporting, alerting) into the response workflow; and post-incident reviews that produce tracked corrective actions. Run at least one realistic tabletop exercise per year and keep the after-action record.
The most common failure mode is not the absence of a plan but a plan no one has rehearsed. If the people who would actually receive the 03:00 alert have never walked through the OJK notification steps, the plan does not yet protect you.
5. Resilience, continuity, and reporting to OJK
Resilience also means surviving disruption and proving you planned for it. Maintain and test business continuity and disaster recovery arrangements, including your data center and disaster recovery center setup, and align recovery objectives with the criticality of each system. POJK 11/2022 also obliges banks to submit a range of documents to OJK, such as IT strategic plans, reports on current IT implementation, incident notifications and reports, and realization reports.
Checklist: tested BCP and DRP with recovery time and recovery point objectives per critical system; evidence of the last failover or recovery test with results; a controlled change-management process with audit trails; and a tracking calendar for every periodic and event-driven OJK submission so nothing is filed late. Keep a single register that maps each regulatory obligation to an owner, a frequency, and the location of the latest evidence.
Pull the program together with one resilience evidence pack, refreshed each quarter: governance approvals, risk-assessment outputs, test and maturity results, human-risk metrics, incident and reporting logs, and continuity test results. When an examiner arrives, you hand over a coherent story rather than assembling it under deadline. That readiness is the real outcome of a good checklist.
Key takeaways
- POJK 11/2022 and SEOJK 29/2022 reward demonstrable, operating controls over thick but untested policy documents.
- Name a function accountable for cyber resilience and get real cyber metrics in front of the Board on a recurring cadence, not once a year.
- Treat the workforce as a measurable control: baseline phishing simulations, track click and report rates, and auto-assign remedial training.
- Make the OJK incident-notification trigger and timeline explicit in your response plan, then rehearse it with a yearly tabletop.
- Maintain a single resilience evidence pack and an obligation register so an examiner request becomes a handover, not a fire drill.