OJK Cyber Security Compliance in Indonesia: The 2026 Guide for Financial Institutions

Primary Guard · July 21, 2026 · 8 min read

Indonesia's OJK requires banks to meet strict cyber resilience rules under POJK 11/2022 and SEOJK 29, with new IT governance rules live from March 2026.

Indonesia's financial regulator has spent the last four years turning cyber resilience from good practice into hard obligation. The Otoritas Jasa Keuangan (OJK) now requires commercial banks and other financial institutions to run formal cyber risk assessments, stand up an independent cyber security function, test their defences, and report incidents. A new IT governance regulation taking effect on 1 March 2026 raises the bar again.

This guide explains the OJK cyber framework as it stands in 2026: the core regulations, what they require in practice, the recent changes financial institutions need to plan around, and how to approach compliance. It is written for boards, IT and risk teams, and security leaders at banks, digital banks, and financial technology firms operating in Indonesia.

What is OJK, and why does cyber compliance matter?

The Otoritas Jasa Keuangan is Indonesia's Financial Services Authority, the body that regulates and supervises the banking, capital markets, and non-bank financial sectors. As Indonesia's digital financial ecosystem has grown, OJK has treated cyber risk and IT governance as strategic priorities, issuing a connected set of regulations that make robust technology risk management a licensing-level expectation rather than an optional extra.

For financial institutions, the consequence is clear. Cyber security in Indonesia is now measured against specific regulatory requirements, assessed annually, and reported to the regulator. Institutions that treat it as an IT housekeeping task rather than a governed, board-level programme are exposed both to supervisory action and to the operational risk the rules are designed to reduce.

The core OJK cyber regulations

Three instruments form the backbone of the current framework, with two more recent additions extending it.

POJK No. 11/POJK.03/2022 on the Implementation of Information Technology by Commercial Banks is the foundation. It sets out the general framework, principles, and requirements for how banks govern and use information technology, covering:

  • IT governance and IT risk management
  • Cyber security and cyber resilience
  • The engagement of IT service providers
  • The location of electronic systems
  • The assessment of a bank's digital maturity
  • It replaced the earlier POJK 38/2016 on IT risk management.

    SEOJK No. 29/SEOJK.03/2022 on Cyber Security and Resilience for Commercial Banks, issued in December 2022, is the implementing circular that puts detail behind POJK 11. It was Indonesia's first cyber security regulation written specifically for banks, and it defines cyber resilience, cyber security, inherent risk parameters, and incident reporting. It runs to ten chapters and functions as a practical reference for implementation, not just a rulebook.

    SEOJK No. 24/SEOJK.03/2023 on the Assessment of Digital Maturity of Commercial Banks adds the maturity dimension, requiring institutions to evaluate themselves across leadership, governance, operational monitoring, training, resilience, and data protection.

    Two newer developments extend the framework and should be on every compliance plan:

    BOC OJK Regulation No. 1 of 2026 on Information Technology Governance for Commercial Banks took effect on 1 March 2026, revoking and replacing the older OJK Circular Letter 21/2017. As an implementing regulation of POJK 11/2022, it provides more comprehensive guidance on:

  • IT governance and IT risk management
  • Cyber security and cyber resilience
  • IT service provider engagement
  • Electronic system location
  • IT-based transactions
  • Digital maturity assessment It also adjusts report and licensing application formats, so institutions must submit reports in the new format and within the new timelines from the effective date.

POJK No. 30 of 2025 on Governance and Risk Management for Financial Sector Technology Innovation organisers introduces stricter governance and risk management standards for financial technology firms. It takes effect on 1 July 2026, but its implications are immediate for firms currently licensed or operating within OJK's regulatory sandbox.

Observers have noted that this body of regulation covers much of the same ground as the European Union's Digital Operational Resilience Act, including IT risk management, incident reporting, and third-party IT risk, which gives internationally active institutions a familiar reference point.

What OJK actually requires

Underneath the regulations sit a set of concrete obligations. These are the ones financial institutions most need to operationalise.

An independent cyber security function

SEOJK 29 requires banks to have a cyber security unit or function that is independent from the IT management function. The separation matters: the team responsible for defending and challenging the bank's security posture should not sit inside the same function it is meant to hold to account. For many institutions, standing up or formalising this independent function is the first structural change the rules demand.

Annual cyber risk assessment

Banks must identify their cyber security inherent risk through a series of assessments and processes conducted on an annual basis. Inherent risk is judged against parameters including technology, products, organisational characteristics, and the institution's track record of cyber incidents. This is a recurring, evidenced exercise, not a one-time baseline.

Cyber security testing

Institutions must test their defences, and the results of that testing must be included in the report on the current condition of the bank's IT system implementation and submitted to OJK. In practice this means a disciplined programme of vulnerability assessment and penetration testing, with findings documented to a standard a regulator will read.

Incident reporting to OJK

Cyber incidents must be reported to OJK. The circular treats a cyber incident as a threat, activity, or action that results in the failure of an electronic system, and names malware, web defacement, denial of service, and distributed denial of service as examples. Institutions need an incident response process capable of detecting, classifying, and reporting incidents within the regulator's expectations, which requires monitoring and detection capability rather than paperwork alone.

IT governance and third-party risk

POJK 11 requires good IT governance with clear duties and responsibilities at board and director level, and it requires due diligence before selecting an IT service provider. With banks increasingly dependent on cloud and outsourced technology, third-party and supply chain risk management is a first-order compliance concern, not a procurement afterthought.

Digital maturity and data protection

The digital maturity assessment ties these threads together, evaluating the institution across governance, operational monitoring, resilience, and data protection. Consumer protection rules, including POJK 22/2023, reinforce the expectation that financial services businesses secure their information systems and maintain cyber resilience to protect consumers.

How to approach OJK compliance

A practical sequence starts with governance. Establish or formalise the independent cyber security function and confirm board-level ownership of technology risk, because the structure has to exist before the controls beneath it can be assured. Then build the recurring assessment engine: the annual inherent-risk assessment, the digital maturity evaluation, and the testing programme whose results feed the reports OJK expects.

The capability that most often needs strengthening is detection and response. The incident reporting obligation is only meaningful if the institution can actually detect incidents quickly and classify them accurately, which depends on continuous monitoring across the environment. Finally, review IT service provider arrangements against the due diligence and third-party risk requirements, and make sure the 1 March 2026 reporting formats under BOC OJK Reg 1/2026 are reflected in how the institution reports to OJK from the effective date.

Where a managed security partner fits

Several OJK obligations are, at their core, security operations capabilities. Continuous monitoring, incident detection, and the ability to report incidents to OJK on time align with a managed detection and response and security operations centre model. The cyber security testing requirement aligns with breach and attack simulation and penetration testing services. Third-party and IT service provider risk aligns with threat intelligence and attack surface monitoring. Governance, assessment, and regulator-ready reporting align with a structured security services programme.

Primary Guard operates across Indonesia, Malaysia, and Thailand, pairing regional security operations with governance and testing services suited to regulated financial institutions. For banks and fintech firms weighing whether to build these capabilities in-house or partner, a free assessment is a practical way to benchmark current posture against OJK's expectations. Institutions regulated in more than one ASEAN market may also find it useful to read this alongside our BNM RMiT compliance guide, since the Malaysian and Indonesian financial cyber regimes share much of the same DNA.

Key takeaways

Indonesia's OJK framework has made cyber resilience a governed, annually assessed, and regulator-reported obligation for financial institutions. The essentials are an independent cyber security function, recurring risk assessment, tested defences, and timely incident reporting, with the 2026 additions raising governance expectations further. The institutions that treat this as a continuous security operations programme, rather than an annual documentation exercise, are the ones that will satisfy OJK and reduce real risk at the same time.


This article is provided for general information and does not constitute legal or regulatory advice. Financial institutions should refer to the relevant OJK regulations and circulars and consult qualified advisers on their specific obligations.

Frequently Asked Questions

Is OJK cyber security compliance mandatory?

Yes. OJK's regulations, including POJK 11/2022 and SEOJK 29/2022, impose mandatory cyber security and resilience obligations on commercial banks and other regulated financial institutions in Indonesia, assessed annually and reported to the regulator.

What is the difference between POJK 11/2022 and SEOJK 29/2022?

POJK 11/2022 is the overarching regulation on IT implementation and governance for commercial banks. SEOJK 29/2022 is the implementing circular that details the cyber security and resilience requirements, including the independent cyber security function, risk assessment, testing, and incident reporting.

What changed with BOC OJK Regulation No. 1 of 2026?

It took effect on 1 March 2026, replacing OJK Circular Letter 21/2017, and provides more comprehensive IT governance guidance along with revised report and licensing application formats that institutions must use from the effective date.

Do banks have to report cyber incidents to OJK?

Yes. Cyber incidents, including malware, web defacement, and denial of service attacks, must be reported to OJK. Institutions need a detection and response process capable of identifying, classifying, and reporting incidents within the regulator's expectations.

Does OJK require an independent cyber security team?

Yes. Under SEOJK 29, banks must maintain a cyber security unit or function that is independent from the IT management function.

Does OJK cyber regulation apply to fintech firms?

The core banking regulations apply to commercial banks, but POJK 30/2025, effective 1 July 2026, extends stricter governance and risk management requirements to financial sector technology innovation organisers, including firms in OJK's regulatory sandbox.