Indonesia Cyber Protection 2026 Encourage Financial Industry to Strengthen Cyber Resilience Based on the AI Era

JAKARTA - Like the two sides of the coin, the acceleration of digital transformation in the Indonesian financial sector brings great opportunities while increasing the complexity of cyber threats. The use of artificial intelligence (AI), cloud, open API, and digital financial services makes data protection, system security, and operational resilience increasingly important to maintain public trust.

This has been highlighted in the Indonesia Cyber Protection 2026: "Securing Indonesia's Financial Digital Future" organized by Warta Ekonomi, bringing together regulators, governments, the financial industry, and cyber security practitioners to discuss strategies to face increasingly sophisticated cyber threats.

Indonesia currently has more than 235 million internet users, while digital transactions and financial services continue to grow. BSSN recorded 3.64 billion cyber attack anomalies occurred throughout January-July 2025.

Warta Ekonomi CEO Muhamad Ihsan said that digital growth must be followed by readiness to maintain data and system security. According to him, today's cyber threats are not only getting bigger, but also more complex as the use of AI increases.

"We need more adaptive security technology, stronger digital talent, more mature data governance, and collaboration between the government, industry, technology providers, and the community," said Muhamad Ihsan in Jakarta in a written statement, Sunday, August 15.

In line with this view, the Director of Cyber Security and Financial, Trade, and Tourism Security of BSSN, Edit Prima, emphasized that the cyber security challenge is now at a much larger and systemic scale, as digitalization increases across all levels of society.

Based on BSSN data, almost 74% of the Indonesian population has carried out digital activities. As many as 80% of the public use e-wallets or digital payments in daily transactions. Meanwhile, QRIS has nearly 60 million active users and 39 million registered merchants, 93% of which are micro, small and medium enterprises.

He revealed that the limited capacity of BSSN monitoring only covers less than 10% of the activity. "Like CCTV in a residential complex, it can only monitor less than 10% of the total roads. This means that more than 90% of the abnormal activities in front of the house or on the streets cannot be monitored. This is a big PR for the capacity of the state in helping all stakeholders detect increasingly massive threats," said Edit.

From the perspective of the financial services sector regulator, OJK emphasized that the increasing complexity of the threat ultimately boils down to one crucial thing, namely public trust.

Advisor to the OJK Group of Digital Services and Cyber Security Specialists, Rela Ginting, emphasized that cyber security is directly related to public confidence in financial services institutions. As of July 2026, there were 22.69 million digital financial consumer accounts and 18.80 million users of aggregation services. For this reason, trust must be built from readiness to face incidents, not from promises of free disruption.

"Trust is not built by promising that incidents will never happen, because it is unrealistic in the face of ever-changing threats. Trust is built through evidence that institutions have prepared, are able to detect quickly, report early, communicate honestly, and are responsible for the impact," explained Rela.

If BSSN and OJK highlight the aspects of systems and trust, then from the operational side of the industry, the real challenges actually occur at the human and process levels, which are the main entry points for cyber attacks.

Director of IT and Digital PT Pegadaian Yos Iman Jaya Dappu highlighted the importance of people and process aspects in cyber security. According to him, security technology will not be optimal if human governance and business processes are not strengthened from the beginning.

He described the importance of governance through the analogy of home security. The more doors and access a business has, the more important it is to have rules about who can enter, into which room, and with what kind of access.

He also highlighted the increasing risks due to the use of AI, including the potential for AI against AI in cyber attacks and defense. Pegadaian itself strengthens security through system testing, periodic audits, and internal awareness programs. "The first step in cyber security is to make people aware," he said.

To complement this view, the Chairman of CISSReC Pratama Persadha emphasized that this increasingly sophisticated threat can no longer be faced with a traditional approach, but requires a comprehensive paradigm shift.

"When the enemy is AI, yes, we find it difficult to use manual methods, so compliance must be followed by protection and security, which ultimately is resilience," he said.

In terms of the financial technology ecosystem, AFTECH added that industry readiness still faces gaps, especially in third-party risk management and optimization of the use of AI for security.

The AI AFTECH Department and Director of Government Relations Advance Intelligence Indonesia, Entin Rostini, explained that based on the findings of AMS 2025-2026, as many as 84 percent of members have adopted AI, although its use for cyber security is still limited.

"In fact, earlier you all conveyed our homework that in the future the attack will use AI. Why not? This is for cyber security, we must also try to increase it from 20 percent," he said.