Indonesia pushes cybersecurity law as rising ransomware attacks spark concerns over digital transformation
The push for the legislation comes as South-east Asia’s largest economy deals with the fallout from a ransomware attack on its national data centre
[JAKARTA] Indonesia is pushing ahead with a long-awaited cyber-resilience law, seen as an essential long-term solution to tackle escalating cybersecurity issues, following a series of high-profile data breaches.
Meutya Hafid, a lawmaker and chair of the First Commission of the House of Representatives, said the new Bill proposes requiring all government agencies and regional administrations to store their data on regional cloud servers, including private data centres, rather than storing all the information at national facilities. “The law will also push us to have a backup in local data centres,” she told The Business Times (BT).
The proposed law, which includes fines of up to 10 billion rupiah (S$827,627) or up to 10 years in prison for organisations or individuals, is intended to serve as an umbrella for all cybersecurity laws and regulations in Indonesia.
However, it still remains unclear whether private sector companies are subject to the backup data localisation requirement.
The Bill was first introduced in parliament in 2020 but faced criticism for being overly cumbersome and costly for businesses, leading to its withdrawal from the legislative agenda.
The push for the law comes as South-east Asia’s largest economy grapples with a significant cybersecurity incident involving a recent ransomware attack on its national data centre, managed by the Ministry of Communications and Informatics.
The centre houses a critical database essential to the functioning of government agencies.
Indonesian authorities said that the attack involved software developed by the Russian ransomware group LockBit, leading to widespread disruption and significant data loss across 230 public agencies, including immigration offices that affect airport operations, ferry services and passport verification systems. Officials are working to gradually restore operations but have refused to pay the hefty US$8 million ransom to retrieve the encrypted data.
The country’s cybersecurity agency attributed the core issue to the lack of backups in the national data centre.
Hinsa Siburian, chief of the national cyber and crypto agency, was quoted as saying in a Kompas report that 98 per cent of the government data stored in one of the two national data centres had not been backed up.
Responding to the cyberattacks, Indonesian President Joko Widodo directed officials to audit the country’s data centres.
The incident has sparked criticism among the public as it exposed vulnerabilities in Indonesia’s digital infrastructure, raising concerns about the potential impact on national security and public trust.
Communications and Informatics Minister Budi Arie Setiadi is under mounting public pressure to resign, with a petition amassing thousands of signatures.
Rising attacks deter digital transformation goals
Indonesia is a fast-growing Internet market with its digital economy reaching US$70 billion in 2021. According to a joint study by Kearney and Google, this figure is projected to increase to US$130 billion by 2025.
Widodo has made digital transformation a priority agenda, emphasising its potential to streamline state bureaucracy and enhance public services, especially in response to the Covid-19 pandemic.
While Indonesia’s digital transformation offers significant economic opportunities, it has also increased the exposure to cyberthreats.
Experts warn that the long-term implications of such breaches could hinder Indonesia’s goal of optimising its digital economy, underscoring the need for enhanced cybersecurity measures and robust incident response strategies.
Muhamad Erza Aminanto, an assistant professor of cybersecurity at Monash University in Australia, said that the incident demonstrates a lack of cybersecurity awareness among officials and the public, despite the country’s ongoing efforts to comply with international digital security standards.
“Human error significantly contributes to cybersecurity incidents. While compliance with international standards cannot guarantee zero incidents, it can help minimise risks,” he told BT.
He said that Indonesia needs to prevent data breaches by intensifying public campaigns to educate people on how to protect their information, while also allocating more budget to purchase data backup plans provided by cybersecurity services.
Indonesia has experienced at least 10 major data leaks in the public and private sectors since 2020, according to the South-east Asian Freedom of Expression Network, an Internet watchdog. Indonesia reported 61 digital security incidents in the first quarter of this year alone.
In May 2023, LockBit claimed to have stolen 1.5 terabytes of data from Indonesia’s largest syariah lender, Bank Syariah Indonesia (BSI), causing disruptions to bank services, including mobile banking and ATMs, for an entire week.
This ransomware attack on BSI highlighted the ongoing cybersecurity challenges faced by financial institutions, even after the enactment of the country’s privacy law in 2022.
Nigel Ng, senior vice-president for Asia-Pacific and Japan at Tenable, an exposure management company, said LockBit’s repeated involvement in high-profile attacks across the globe demonstrates the evolving threat landscape that Indonesia must be prepared for.
“This incident highlights the critical importance of continuous monitoring and real-time threat detection to mitigate the impact of such sophisticated attacks,” he said.
“The situation exemplifies the necessity for robust collaboration between government agencies and private sector companies.”
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
What role can Japan play in Asean’s future?
From folding clothes to factory work: Why China is sending humanoid robots to school