Indonesia Cyber Resilience & Digital Security Monitor — First Evidence Update 2026

ArrezaMP Research — Research & Evidence Intelligence

Indonesia Cyber Resilience & Digital Security Monitor — First Evidence Update 2026

R6 Research Update #1

Research Series R6 — Indonesia Cyber Resilience & Digital Security Monitor
Research Area Cyber Resilience, Digital Security & Government Systems
Publication Type Research Update
Publication ID R6-UPD-2026-01-v1.0
Update Period Evidence available through 5 September 2026
Evidence Type Official Regulation, Government Institutional Evidence, Operational Indicators & Authoritative Reported Data
Status Update
Indonesia Cyber Resilience & Digital Security Monitor — First Evidence Update 2026

Executive Summary

Indonesia’s cyber-resilience challenge is increasingly defined by two developments occurring at the same time.

First, digital systems operate in an environment of persistent potentially malicious activity. BSSN reported approximately 5.16 billion internet traffic anomalies during 2025. In the same August 2026 statement, BSSN separately reported an average of 182 potential cyber threats per second and emphasized that detected traffic anomalies do not necessarily represent actual cyberattacks. These figures therefore describe an operating environment requiring continuous monitoring rather than a count of successful compromises. Source: ANTARA / BSSN statement.

Second, Indonesia is strengthening the institutional foundations required to manage that environment.

National cyber-incident governance is supported by Peraturan BSSN Nomor 1 Tahun 2024 tentang Pengelolaan Insiden Siber, which covers Cyber Incident Response Teams, incident reporting, incident handling, and preparedness. Source: BPK Regulation Database.

Professional cybersecurity capability has also become more formally structured. Peraturan BSSN Nomor 2 Tahun 2026, effective 17 June 2026, establishes Indonesian National Qualification Frameworks across Security Operations Center operations, cybersecurity testing, information-security auditing, cryptography, information-security awareness, information security, and cyber incident response. Source: BPK Regulation Database.

At the regional level, evidence during 2026 shows continued institutionalization of Cyber Incident Response Teams. Lampung conducted accelerated assistance for four regencies still forming their TTIS, while West Nusa Tenggara reached formal formation and registration across all ten regencies/cities. These developments indicate progress in institutional coverage, while not by themselves proving equivalent operational maturity. Lampung source and NTB source.

Indonesia’s digital-trust infrastructure is also operating at substantial government scale. As observed on the official BSrE website on 5 September 2026, BSrE displayed approximately 1.1 million service users, 1.6 million electronic certificates, 890 million electronic signatures, and 147 million electronic seals, with collaboration covering 139 ministries/agencies and 531 local governments. Source: BSrE.

Meanwhile, security is becoming embedded more directly into Indonesia’s digital-government architecture. The Rencana Induk Pemerintah Digital 2025–2045, launched in February 2026, explicitly promotes secure and privacy-by-design principles. By August 2026, Bappenas was also conducting a process described as updating the Rencana Induk Pemerintah Digital Nasional 2026–2045 and sharpening the Rencana Aksi Nasional Pemerintah Digital 2026–2030, with digital security positioned as a foundation of integrated digital government. Bappenas source.

Cyber resilience is not simply the ability to prevent an attack. It is the institutional ability to know what must be protected, detect abnormal activity, respond under clear authority, preserve trusted identities and data, recover services, and produce evidence showing that those capabilities actually worked.

For municipal governments, this increasingly turns cybersecurity from a narrow technical responsibility into a wider governance and public-service continuity capability.

Ringkasan Eksekutif

Tantangan ketahanan siber Indonesia semakin ditentukan oleh dua perkembangan yang berlangsung secara bersamaan.

Pertama, sistem digital beroperasi di tengah aktivitas anomali dan potensi ancaman yang berlangsung secara terus-menerus. BSSN melaporkan sekitar 5,16 miliar anomali trafik internet sepanjang 2025. Dalam pernyataan yang sama pada Agustus 2026, BSSN juga menyebut rata-rata 182 potensi ancaman siber per detik, sekaligus menegaskan bahwa anomali trafik belum tentu merupakan serangan siber. Karena itu, kedua angka tersebut tidak boleh dibaca sebagai jumlah serangan yang berhasil.

Kedua, Indonesia terus memperkuat fondasi kelembagaan keamanan siber.

Peraturan BSSN Nomor 1 Tahun 2024 telah memberikan kerangka formal untuk pengelolaan insiden siber, sedangkan Peraturan BSSN Nomor 2 Tahun 2026 memperkuat struktur kompetensi profesi pada bidang SOC, pengujian keamanan, audit, kriptografi, keamanan informasi, dan tanggap insiden.

Pada pemerintah daerah, penguatan TTIS juga terus berlangsung. Lampung masih melakukan akselerasi pembentukan di sejumlah kabupaten pada Mei 2026, sementara Nusa Tenggara Barat telah mencapai pembentukan dan registrasi pada seluruh 10 kabupaten/kotanya pada Juni 2026. Namun, pembentukan dan registrasi tidak boleh otomatis dianggap sama dengan tingkat kematangan operasional.

Ekosistem kepercayaan digital pemerintah juga telah mencapai skala besar. Website resmi BSrE pada 5 September 2026 menampilkan sekitar 1,1 juta pengguna layanan, 1,6 juta sertifikat elektronik, 890 juta tanda tangan elektronik, 147 juta segel elektronik, dan kolaborasi dengan 531 pemerintah daerah.

Evidence awal R6 menunjukkan bahwa persoalan keamanan siber pemerintah bukan lagi sekadar memasang teknologi keamanan. Yang semakin penting adalah kemampuan organisasi untuk membuktikan: aset apa yang dimiliki → apa yang harus dilindungi → apa yang sedang terjadi → siapa yang berwenang merespons → bagaimana layanan dipulihkan → dan evidence apa yang menunjukkan bahwa kontrol benar-benar bekerja.

1. Purpose of This Research Update

The R6 Foundation established the scope, governance model, methodology, taxonomy, and baseline analytical framework for the Indonesia Cyber Resilience & Digital Security Monitor.

The Foundation deliberately deferred a quantitative evidence baseline until the first Research Update.

This publication begins that layer.

Its objective is not to claim a complete measurement of Indonesia’s cybersecurity maturity. Instead, Research Update #1 establishes several initial evidence signals that future R6 publications can monitor longitudinally:

  1. threat environment;
  2. national incident governance;
  3. cybersecurity professional capability;
  4. regional incident-response institutionalization;
  5. digital identity and trust infrastructure;
  6. security within digital-government architecture; and
  7. emerging resilience requirements.

2. Measurement Discipline: Not Every Cybersecurity Number Means the Same Thing

A recurring problem in cybersecurity reporting is the use of the word attack for fundamentally different observations.

R6 therefore applies the following distinction.

Traffic Anomaly

An unusual network event identified through monitoring. An anomaly can indicate suspicious or potentially malicious activity but does not establish that a system was successfully compromised.

Potential Threat

Activity assessed as potentially capable of causing harm. It remains different from a confirmed successful incident.

Security Event

An observable occurrence relevant to cybersecurity monitoring.

Cyber Incident

An event that affects or has material potential to affect systems, information, services, or security objectives and requires management or response.

Confirmed Compromise

An event supported by evidence demonstrating unauthorized access, manipulation, disruption, disclosure, or another successful security impact.

This taxonomy matters directly to the 2025 BSSN figure.

BSSN reported approximately 5.16 billion traffic anomalies and separately described an average of 182 potential cyber threats per second. BSSN also explicitly stated that traffic anomalies are not necessarily cyberattacks.

Accordingly, R6 does not describe Indonesia as having experienced “5.16 billion successful cyberattacks.” That conclusion would not be supported by the evidence.

3. Evidence Signal 01 — Persistent High-Volume Threat Activity

The 2025 BSSN observation provides the first quantitative signal in this R6 baseline.

Approximately 5.16 billion internet traffic anomalies were reported as having been observed during 2025.

The significance is not the headline number by itself.

The evidence indicates that potentially malicious activity exists at a scale requiring security operations to assume that monitoring cannot be occasional.

Research interpretation

Cyber defence for important government systems increasingly requires capabilities such as:

  • centralized logging;
  • continuous monitoring;
  • network and endpoint visibility;
  • identity monitoring;
  • vulnerability management;
  • alert triage;
  • incident correlation; and
  • evidence retention.

Periodic manual checks can remain useful, but they cannot be the only detection mechanism in an environment characterized by persistent automated activity.

4. Evidence Signal 02 — Incident Response Is Becoming a Formal Governance Function

Indonesia already has a national regulatory framework specifically governing cyber incidents.

Peraturan BSSN Nomor 1 Tahun 2024 tentang Pengelolaan Insiden Siber has been effective since 18 January 2024.

Its regulated areas include:

  • Tim Tanggap Insiden Siber;
  • cyber-incident reporting;
  • cyber-incident handling; and
  • preparedness for cyber incidents.

Research interpretation

This establishes an important governance principle.

Incident response is not simply an informal technical activity conducted when an administrator discovers a problem.

Effective response requires an institutional model involving:

authority → reporting → coordination → handling → recovery → evidence

This becomes particularly relevant for government institutions where response decisions may affect public services, citizen information, inter-agency systems, financial operations, official communications, and accountability.

5. Evidence Signal 03 — Cybersecurity Roles Are Becoming More Professionally Structured

The development of Peraturan BSSN Nomor 2 Tahun 2026 provides another important institutional signal.

The regulation was established on 22 May 2026, promulgated on 17 June 2026, and became effective on 17 June 2026.

It establishes KKNI structures for:

  • Security Operation Center;
  • cybersecurity security testing;
  • information-security auditing;
  • cryptography;
  • information-security awareness;
  • information security; and
  • cyber incident response.

Research interpretation

This reinforces the distinction between general IT capability and specialized cybersecurity capability.

IT operations ≠ SOC ≠ security testing ≠ security audit ≠ incident response

These functions can cooperate closely. They should not automatically be treated as interchangeable responsibilities.

Cyber resilience therefore depends not only on acquiring security technology, but also on having people with the authority and competence to operate, evaluate, test, monitor, and respond.

6. Evidence Signal 04 — Regional Incident-Response Coverage Is Expanding

Regional evidence demonstrates continuing development of TTIS structures during 2026.

Lampung

On 19 May 2026, BSSN and the Lampung provincial government conducted assistance for four regencies undergoing accelerated TTIS formation:

  • Pesisir Barat;
  • Mesuji;
  • Tulang Bawang; and
  • Tulang Bawang Barat.

The stated objective was to accelerate the process so regional governments would have TTIS registered within the national ecosystem.

Nusa Tenggara Barat

By June 2026, official information from the Lombok Tengah local government reported that NTB had achieved 100% formation and registration of TTIS across all ten regencies/cities.

Research interpretation

Taken together, these examples show that regional cyber incident-response institutionalization is continuing.

However, R6 distinguishes four maturity conditions:

TTIS Formed

TTIS Registered

TTIS Operational

TTIS Mature

A registration record demonstrates institutional establishment. It does not, by itself, prove continuous monitoring capability, sufficient staffing, response speed, evidence quality, exercise performance, recovery effectiveness, or operational maturity.

Future R6 measurement should therefore move beyond counting teams toward evaluating demonstrated capabilities.

7. Evidence Signal 05 — Audit Is Becoming Part of Government Cybersecurity Capability

In April 2026, the Bali Provincial Government conducted technical guidance on Electronic System Security Auditing with BSSN participation.

The activity emphasized the relationship between:

assets → risks → controls

and the need for periodic evaluation of electronic systems.

The Bali government reported approximately 132 electronic-system applications as assets requiring periodic auditing within its environment.

Research interpretation

This represents another stage of cyber-resilience development.

Security capability is not complete when an organization merely deploys controls. A mature organization also needs to ask:

  • Is the control present?
  • Is it configured correctly?
  • Does it address the relevant risk?
  • Is it still operating?
  • Can its effectiveness be demonstrated?

This moves cybersecurity toward assurance and evidence.

8. Evidence Signal 06 — Digital Trust Has Become Operational Infrastructure

BSrE provides an important indicator of the scale of digital trust within government.

As observed on its official website on 5 September 2026, BSrE displayed:

Indicator Website-Displayed Scale
Service users1.1 million
Electronic certificates1.6 million
Electronic signatures890 million
Electronic seals147 million
Ministries / agencies139
Local governments531
Universities47

These values are dynamic website counters and should therefore be treated as an observed snapshot rather than calendar-year statistics.

Research interpretation

Government cybersecurity is no longer only concerned with protecting servers and networks.

Government operations increasingly depend on trusted digital identity, including:

  • electronic certificates;
  • electronic signatures;
  • electronic seals;
  • signing authority;
  • certificate lifecycle;
  • verification;
  • application integration; and
  • identity assurance.

A compromise affecting these trust mechanisms could damage authenticity and integrity even where the affected service remains technically available.

9. Evidence Signal 07 — Security Is Moving into Digital-Government Architecture

On 26 February 2026, Indonesia launched the Rencana Induk Pemerintah Digital 2025–2045.

Bappenas states that the plan serves as a national roadmap for integrated, data-driven digital government and includes the application of secure and privacy by design principles.

A later development requires careful nomenclature.

On 10 August 2026, Satu Data Indonesia reported that Bappenas was conducting a process described as:

Pemutakhiran Rencana Induk Pemerintah Digital Nasional 2026–2045

alongside refinement of:

Rencana Aksi Nasional Pemerintah Digital 2026–2030.

The process explicitly identified integrated services, data, technology, and digital security as foundations of digital government.

Research interpretation

The significant point is not simply the naming of the documents.

The policy direction indicates that security is increasingly expected to be integrated into digital-government architecture rather than applied only after systems have already been designed.

Digital transformation increases public-service capability, but each new digital dependency also creates something that must remain trusted, protected, observable, and recoverable.

10. Emerging Risk — Security Decisions Have a Long Time Horizon

In August 2026, the Ministry of Communication and Digital Affairs highlighted the emerging harvest now, decrypt later threat model.

The scenario involves adversaries collecting encrypted information today and retaining it for possible future decryption if advances in quantum computing weaken currently deployed cryptographic mechanisms.

The government communication also emphasized security by design and the need to place security considerations earlier in system planning.

Research interpretation

This should not be interpreted as evidence that Indonesian government encryption is currently being broken by quantum computers.

Instead, it demonstrates an emerging resilience problem: some information must remain confidential for many years.

Cybersecurity planning must therefore consider not only:

Can the information be protected today?

but also:

For how long must that protection remain trustworthy?

11. Municipal Government Implications

The national evidence does not establish that every municipality faces identical threats or has identical maturity.

It does, however, identify a set of capabilities increasingly relevant to local digital government.

11.1 Know the Digital Asset Surface

Local governments should maintain an authoritative inventory covering, at minimum:

  • domains and subdomains;
  • public websites;
  • internal applications;
  • internet-facing applications;
  • APIs;
  • databases;
  • servers and cloud services;
  • security certificates;
  • administrative accounts;
  • third-party services; and
  • critical digital-service dependencies.

An organization cannot reliably protect assets that it does not know exist.

11.2 Establish Clear Incident Authority

A cyber incident should not trigger uncertainty about who receives the first alert, who validates it, who may isolate systems, who authorizes emergency changes, who contacts external authorities, who communicates with management, who preserves evidence, and who declares recovery complete.

Incident response is therefore both a technical and governance process.

11.3 Build Detection, Not Only Protection

Protective controls attempt to stop threats. Detection controls answer a different question: Did something abnormal still happen?

Municipal systems should progressively develop visibility across authentication, privileged activity, endpoints, networks, web applications, system logs, vulnerabilities, and significant configuration changes.

11.4 Treat Digital Identity as a Critical Dependency

Certificates, electronic signatures, electronic seals, official accounts, service accounts, and administrator identities should be governed throughout their lifecycle.

issuance → authorization → use → monitoring → rotation → revocation

11.5 Test Recovery

Having a backup is not equivalent to having a recoverable service.

  • Can the backup actually be restored?
  • How long will restoration take?
  • Which service is restored first?
  • Who authorizes restoration?
  • How is system integrity checked afterward?
  • Is the recovered environment still compromised?

11.6 Preserve Evidence

Resilience must be demonstrable.

Useful operational evidence can include security alerts, system logs, timestamps, incident tickets, investigation records, approvals, isolation actions, configuration changes, backup restoration records, recovery validation, and post-incident findings.

12. First R6 Research Findings

Finding 1 — Indonesia operates in a persistent cyber-threat environment

The reported volume of internet traffic anomalies supports continuous rather than episodic security monitoring.

Finding 2 — Cyber incident response is becoming institutionalized

National regulation and regional TTIS development demonstrate movement toward formal incident-management structures.

Finding 3 — Cybersecurity capability is becoming professionally differentiated

The 2026 KKNI framework distinguishes multiple specialized cybersecurity functions rather than treating cybersecurity as one generic IT responsibility.

Finding 4 — Digital trust is already a large-scale government dependency

The BSrE ecosystem demonstrates widespread operational reliance on electronic certificates, signatures, seals, and associated trust services.

Finding 5 — Security is increasingly part of digital-government design

National digital-government planning explicitly integrates security and privacy into the design and architecture of digital services.

Finding 6 — Formal establishment does not equal operational maturity

TTIS formation and registration are important milestones, but future resilience assessment should measure whether those teams can actually detect, coordinate, respond, recover, and produce evidence.

Finding 7 — Cyber-resilience measurement needs stronger discipline

Traffic anomalies, potential threats, incidents, confirmed compromises, institutional coverage, audit readiness, and recovery capability represent different measurements. They should not be collapsed into a single “cyberattack” indicator.

13. R6 Measurement Model v0.1

Threat Environment

Asset & Exposure Awareness

Protection

Detection

Incident Response

Identity & Trust Protection

Recovery

Evidence & Assurance

Institutional Learning

Future R6 updates should measure not only whether these components exist, but whether they operate as a connected resilience system.

14. Evidence Gaps for Future Updates

This first baseline also reveals important areas where stronger public evidence would improve national and municipal resilience measurement.

Priority indicators include:

  • confirmed cyber incidents by sector;
  • incident severity;
  • successful compromise rates;
  • mean time to detect;
  • mean time to contain;
  • mean time to recover;
  • vulnerability remediation time;
  • systems under continuous monitoring;
  • operational TTIS maturity;
  • incident-response exercise performance;
  • privileged-identity incidents;
  • certificate-related incidents;
  • third-party and supply-chain incidents;
  • backup restoration success; and
  • post-incident recovery effectiveness.

R6 should add these indicators only when measurement definitions and evidence quality are sufficient.

15. Evidence Governance Rule

Beginning with this update, quantitative R6 indicators should follow the canonical chain:

Metric

Definition

Measurement Period

Authoritative Source

Evidence Grade

Limitation

Interpretation

A number without a clear measurement definition should not become a Research Finding.

Conclusion

Indonesia’s digital transformation is increasing both the value and dependency of government digital systems.

The first R6 quantitative evidence shows persistent high-volume anomalous activity in the national internet environment. At the same time, regulatory frameworks, professional qualification structures, regional incident-response teams, security-audit capability, digital trust services, and national digital-government planning are becoming more institutionalized.

The direction of travel is important.

protecting individual systems

building institutions capable of sustaining trusted digital services under adverse conditions

For municipal government, this means cyber resilience increasingly depends on the ability to continuously answer six questions:

  1. What do we operate?
  2. What must be protected?
  3. What is happening?
  4. Who is authorized to respond?
  5. How will the service recover?
  6. What evidence proves the controls worked?

That evidence-driven capability—not the deployment of any single security product—is the baseline R6 will continue to monitor.

Sources & Evidence

  1. ANTARA News — BSSN statement on 2025 internet traffic anomalies and potential cyber threats, 6 August 2026.
  2. Peraturan BSSN Nomor 1 Tahun 2024 — Pengelolaan Insiden Siber.
  3. Peraturan BSSN Nomor 2 Tahun 2026 — Penerapan KKNI bidang-bidang keamanan siber.
  4. CSIRT Provinsi Lampung — Asistensi Pembentukan TTIS bagi empat kabupaten, May 2026.
  5. Diskominfo Kabupaten Lombok Tengah — TTIS registration and NTB regional coverage, June 2026.
  6. Pemerintah Provinsi Bali — Bimtek Audit Keamanan Sistem Elektronik, April 2026.
  7. Balai Besar Sertifikasi Elektronik — official service-scale indicators, observed 5 September 2026.
  8. Kementerian PPN/Bappenas — Rencana Induk Pemerintah Digital 2025–2045, February 2026.
  9. Satu Data Indonesia/Bappenas — Digital Government Master Plan update and National Action Plan refinement, August 2026.
  10. Kementerian Komunikasi dan Digital — quantum-era cybersecurity and harvest-now-decrypt-later risk, August 2026.

Related Research

R6 Foundation — Indonesia Cyber Resilience & Digital Security Monitor

Establishes the scope, governance, methodology, taxonomy, and research framework used by this Research Update.

Research Note

This Research Update intentionally distinguishes between:

anomaly ≠ potential threat ≠ incident ≠ confirmed compromise

and:

TTIS formation ≠ TTIS registration ≠ TTIS operational capability ≠ TTIS maturity

These distinctions form part of the permanent R6 measurement methodology.

Indonesia Cyber Resilience & Digital Security Monitor — First Evidence Update 2026


ArrezaMP Research

Research & Evidence Intelligence

R6 — Indonesia Cyber Resilience & Digital Security Monitor

From evidence to resilience.



0 Komentar