From Financial Services to Critical Infrastructure, The Cyber Risks Indonesian Organisations Are Preparing For
Indonesia recorded 5.5 billion cyberattacks in 2025, according to data from the National Cyber and Crypto Agency (BSSN) cited by the Office of the Presidential Chief of Staff. Another 1.52 billion attacks were recorded between January and 15 April 2026.
Those numbers show the scale of the problem, but they do not explain where organisations are feeling the pressure.
AIBP’s 2025–2026 Enterprise Market Overview points to some of the wider challenges behind that pressure. Cybersecurity and privacy concerns were cited by 41% of Indonesian enterprises as a challenge to digital transformation, while 40% pointed to a lack of talent and expertise to execute on their vision.
For financial institutions, the pressure is around whether employees are putting sensitive information into AI tools, or whether an AI system can be governed across different business units. For organisations operating physical infrastructure, the challenge is different. Security has to be managed alongside the need to keep operations running.
These questions came across two days in Jakarta during the Singapore Cyber Security Mission to Indonesia, held alongside the 54th AIBP Conference & Exhibition Indonesia with the CyberSG TIG Collaboration Centre. Day 1 focused on Banking, Financial Services and Insurance with OJK, while Day 2 examined critical infrastructure and national cyber resilience with the National Cyber and Crypto Agency (BSSN) and organisations across energy, mining, telecommunications and logistics. The mission brought together Singaporean cyber security companies and Indonesian organisations to exchange perspectives on the risks emerging across the region.
What emerged was less about any single type of attack and more about how organisations are having to rethink security as their technology environments become more complex.
Financial services are dealing with a wider AI risk surface
For Indonesia’s financial services regulator (OJK), the main conference raised a fundamental question: how can AI governance scale across different business units and use cases? The emphasis was on clear accountability, human oversight and practical governance that can adapt as AI adoption grows.
Following the session, the conversation continued with financial institutions as discussions shifted from governance principles to the practical realities of AI adoption, particularly around data, visibility and third-party risk.
One of the practical challenges is visibility. Having a governance framework in place does not necessarily mean an organisation can see where AI is actually being used across the business. Employees can access external tools, business units can adopt different applications, and sensitive information can move through third parties and wider supply chains.
Indonesia’s central bank raised a different part of the problem. With many potential AI use cases and limited resources, the challenge is deciding where to focus. A senior digital strategy leader also pointed to the need for business units to build stronger data capabilities, supported by tools and mechanisms that allow them to work with data within a clear governance framework.
Third parties create another point of exposure. A representative from one of Indonesia’s largest Islamic banks highlighted the need to understand how data and documents are handled when organisations use external AI services. This makes visibility and control over third parties an important part of managing security risks.
This makes AI security broader than protecting the AI system itself. Organisations also have to understand the data surrounding it, the people using it and the external parties connected to it.
That also brings security and business teams into closer contact. A digital banking representative described the relationship between teams responsible for providing solutions and those responsible for challenging how those solutions are introduced. The discussion ultimately came back to collaboration, with both sides working together to provide a safe environment for business units.
The CyberSG TIG Collaboration Centre brought a regional perspective to this issue, highlighting how increasingly interconnected digital supply chains can expand the environment organisations need to secure. As more services, systems and data move between organisations, cyber risk becomes harder to contain within a single organisation’s boundaries.
The challenge for financial institutions is therefore not simply deciding whether AI should be adopted. It is building enough visibility around its use that security can keep pace with the business.
Critical infrastructure has a different problem to solve
The National Cyber and Crypto Agency (BSSN) opened the second day by highlighting how the threat landscape is changing. Traditional security approaches are under pressure as attackers use new methods and vulnerabilities become harder to detect. The discussion also raised longer-term concerns around threats such as quantum computing and the impact this could have on current encryption.
The conversation continued with organisations across critical infrastructure, where the focus shifted from the changing threat landscape to what cyber resilience means when the systems being protected are directly tied to physical operations.
For critical infrastructure, however, the issue is not only how attacks are detected. It is what happens when the systems being targeted are responsible for keeping physical operations running.
An Indonesian electricity utility illustrated this through the difference between IT and OT. IT environments generally have more flexibility when it comes to applying controls or taking systems offline. OT systems are different. Devices may need to keep running, and a cyber incident can quickly become an operational resilience issue.
A major Indonesian mining company faces a different challenge. Operations can be spread across remote locations, making security awareness harder to maintain. Cyber security is not only about the technology deployed at a site. Employees also need to recognise threats and understand their role in protecting the operation.
This becomes more important as AI becomes more accessible. A technology leader from a large Indonesian industrial group captured the change simply, saying, “With AI, everybody can do things.” The more people who can use these tools, the harder it becomes to manage AI through traditional controls alone.
Telecommunications faces a different set of risks. A telco representative highlighted the exposure around SIM-linked financial accounts and reliance on third-party technology providers, while also preparing for emerging threats such as quantum computing.
A state-owned Indonesian port operator faces another layer of complexity. Its systems connect different applications and stakeholders across a large operating environment. That makes cyber security closely tied to staff capability and the organisation’s ability to understand how its systems connect.
CyberSG TIG also highlighted how the risks can extend beyond an organisation’s own environment. As critical infrastructure becomes more connected to suppliers, partners and external services, knowing where those connections exist and how they could affect operations becomes an important part of building resilience.
The examples are different, but the underlying issue is similar. Critical infrastructure cannot always separate cyber security from day-to-day operations. Keeping services running, managing people and understanding dependencies are all part of resilience.
What this means for organisations
Across the two days, the Singapore Cyber Security Mission to Indonesia brought together organisations facing very different security environments. Financial institutions are dealing with questions around AI use, data, employees and third parties, while critical infrastructure operators are balancing cyber security with OT, remote operations, connectivity and the need to keep services running.
AI is adding to that complexity, but it is not replacing the risks organisations already face. Employees can access new tools more easily, data can move through new channels, and organisations can become more dependent on external providers.
The discussions also showed why cyber security cannot sit entirely within the security function. Managing these risks involves business teams, technology teams, employees and third parties, with different parts of the organisation affecting the overall security posture.
For security leaders, the challenge is therefore not just preparing for the next attack. It is knowing where the organisation is exposed as its technology, people and partners change, and making sure it can respond when that exposure becomes a real problem.
That is where cyber resilience becomes part of how the organisation keeps operating as its technology, people and risks continue to change.
Want to explore the discussions further? Read our Day 1 and Day 2 insights from the 54th AIBP Conference & Exhibition Indonesia 2026.
About ASEAN Innovation Business Platform (AIBP)
The ASEAN Innovation Business Platform (AIBP) is an initiative focused on enabling innovation and strategic partnerships across public and private organisations in Southeast Asia. Through curated engagement activities, AIBP supports the growth of regional government agencies, enterprises and solution providers in navigating key themes such as innovation, digital transformation, and sustainability.
Learn more at www.aibp.sg