AI Has Made Cyber Attacks Cheap. Indonesia's Regulators Are Responding.
On 13 August, Indonesia's national cyber agency and its banking regulator each set out what they now expect from organisations running AI. They spoke hours apart, about different halves of the same problem.
AI Has Lowered the Cost of Attacking
Image source via ANTARA News
Edit Prima, Director of Cyber Security and Cryptography for Finance, Trade and Tourism at BSSN, described an attack cycle that AI has made faster and cheaper at every stage. With AI, he said, fraud has become "very easy, very personal, very convincing", almost free of the grammatical errors that used to give it away and hard to tell apart from the real thing.
Three things follow. Attackers can go after thousands of targets at once, analysing data to make each approach more targeted. Every stage of an attack has sped up, from reconnaissance through to exploitation, and AI can adapt to evade traditional security systems. And because AI tools and services are cheap and widely available, a sophisticated attack no longer requires strong technical skills.
Edit also pointed to an obligation that is already in force. Regulation, he said, requires organisations in the financial industry to have, form and operate a cyber incident response team, and to register that team with BSSN. He framed this alongside closer collaboration between BSSN, OJK and Bank Indonesia.
Supervision Is Testing What Banks Can Demonstrate
Image source via Jakarta Globe
Dian Ediana Rae, Chief Executive of Banking Supervision at OJK, set out how the regulator checks whether banks are ready for cyber threats. OJK supervises both off site and on site, testing readiness, evaluating how effective a bank's existing knowledge is, and identifying where it needs to strengthen. Banks follow up on those findings as part of continuous improvement.
He also pointed to rules already on the books. OJK has issued regulations covering digital business models, the delivery of technology-based products and services, the management of the risks attached to them, and the assessment of a bank's digital maturity. These are existing obligations rather than proposals.
On cyber crime and fraud, Dian said recent incidents show the threat no longer comes only from weaknesses in technology. It also comes from a widening range of methods used by criminals who increasingly work as organised groups rather than alone.
On AI, his position was that successful adoption in banking is determined not only by how sophisticated the technology is, but by the quality of the governance around it. Banks, he said, are obliged to apply AI governance that delivers artificial intelligence that is "trustworthy, responsible, transparent, and human-oriented", and AI should improve efficiency and innovation while maintaining public trust, strengthening consumer protection and supporting financial inclusion.
Between the two statements sits a demand that lands on regulated sectors first and spreads outward. Move quickly on AI, and be able to show, on request, that what has been deployed is under control. The skills that evidence AI oversight, run a registered incident response team and stand up to an on-site examination are the same scarce skills, and talent is already among the constraints Indonesian enterprises name most often.
Both Agencies Take the Question Further in Jakarta
BSSN and OJK are both on the agenda at the AIBP Conference and Exhibition Indonesia 2026, endorsed by the Ministry of Communication and Digital Affairs (KOMDIGI), with two closed-door sessions convened alongside the CyberSG TIG Collaboration Centre, a joint venture between the Cyber Security Agency of Singapore (CSA) and the National University of Singapore.
Securing Indonesia's Digital Economy: Trust, AI and Resilience for Financial Services and Digital Business, on 26 August, picks up where Dian left off. If governance quality counts for as much as technical capability, the practical question for a bank is what it hands over when OJK asks. That means documentation of how a model works, a record of who approved it going live, and a trail showing how its decisions were reached and reviewed. Most institutions have some of this. Few have all of it, and there is no published standard for how much is enough. The session puts financial services leaders working to the same supervisory expectations in one discussion, so that judgement gets made against what peers are actually holding rather than guessed at alone.
Protecting Critical Infrastructure and National Cyber Resilience: OT, Threat Intelligence and Assurance, on 27 August, takes the same question to energy, utilities, telecoms and data centre operators. Registered incident response teams reporting into BSSN are already the model in financial services, and setting up such a team is not the hard part. The hard part is the exchange that follows: which incidents an operator has to report and how quickly, and what the agency sends back in return. Threat intelligence only helps if it arrives fast enough and with enough detail to act on, and an operator cannot patch a plant network the way it patches an office network.
Singapore and Malaysia on the Same Question
Bondan Widiawan, Deputy for Cybersecurity and Cryptography Operations at BSSN, speaks on the main stage on Day 2. Two regional speakers follow the same thread from outside Indonesia.
Willis Lim, Executive Director of the CyberSG TIG Collaboration Centre, presents What Singapore Learned: Building Trusted Adoption in an Interconnected Economy, covering AI, supply chain and third party risk, and the assurance mechanisms that moved Singapore enterprises from pilot into production. The relevance is structural: Indonesian enterprise dependencies run through regional providers and regional infrastructure, so third party risk arrives from outside the jurisdiction supervising it.
Dr Faisha Shahriman, Head of Risk and Resilience at PLUS Malaysia Berhad, presents Lessons from Malaysia's Digital Tolling Journey: From Risk Oversight to Responsible Innovation. PLUS is a critical infrastructure operator rather than a supervised financial institution, running a public-facing automated system at national scale. Its account of moving from oversight into deployment is the closest case on the agenda to the position most Indonesian enterprises are in: carrying the cost of controls without a regulator mandating them.
The session also includes a panel on whether existing cyber strategies fit an AI-first enterprise, with Arief Noorman of Allo Bank, Anas Dwi Vidianto of Astra International and Edy Susanto of Trans Retail Indonesia.
Key questions the sessions are set up to address:
What supervisors now expect to see, and how an enterprise evidences that its AI is under control.
How incident reporting works in both directions between an operator and a national agency.
Who carries the cost of cyber and AI controls in sectors where no regulator is mandating them.
Request a seat at the Cyber Connect sessions, 26 and 27 August, Four Seasons Hotel Jakarta.