Cybersecurity Guideline Digital Financial Asset Trading Pro…

A

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia The Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia is intended to enhance the understanding and awareness of stakeholders.

Disclaimer 1. This guideline provides general guidance and is not intended to replace applicable laws and regulations. This should be read in conjunction with relevant laws, regulations, and other guidelines issued by OJK or other regulatory authorities. 2. Any products or services mentioned in this document are not endorsed by us but are merely used as examples of commonly adopted practices.

2

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Hasan Fawzi Chief Executive Financial Sector Technological Innovation, Digital Financial Asset and Crypto Asset Supervision and Member of The Board Commissioners of Indonesian Financial Services Authority

Foreword

Assalamu’alaikum warahmatullahi wabarakatuh.

We offer our praise and gratitude to Allah SWT, the Almighty God, for by His abundant grace, blessings, and approval, Indonesian Financial Services Authority (OJK) has been able to complete the development of the Cybersecurity Guideline for Providers of Digital Financial Asset Trading in Indonesia. This document is the result of strategic synergy and collaboration across stakeholders who share a strong commitment to strengthening the integrity and resilience of the national financial ecosystem, particularly in supervising the increasingly dynamic digital financial asset industry. As one of the countries with the fastest-growing digital financial asset markets in Southeast Asia, Indonesia faces the crucial challenge of building an adaptive, robust, and visionary supervisory and protection system. A report by Chainalysis recorded that in 2024, global losses due to cyberattacks in the digital financial asset sector increased by 21% compared to the previous year, with total losses reaching approximately USD 2.2 billion. This marks the fourth consecutive year in which global losses from digital financial asset breaches have exceeded USD 1 billion. This fact serves as a

3

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

“cybersecurity is not only a necessity but also the spearhead in ensuring consumer protection and the sustainability of trustworthy digital financial services”

serious warning of the importance of cybersecurity as a key pillar in maintaining stability and public trust in the sector.

The importance of strengthening cybersecurity is also reinforced by Act Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (P2SK Act), which grants OJK a new mandate to regulate and supervise the Financial Sector Technology Innovation, Digital Financial Assets, and Crypto Assets (IAKD) sectors starting in January 2025. This transition marks a crucial phase in the supervision of the IAKD sector, in which cybersecurity is not only a necessity but also the spearhead in ensuring consumer protection and the sustainability of trustworthy digital financial services. In line with this context, this guideline has been developed as a living document that prioritizes the principles of secure by design and resilience by architecture, while also responding to the ever- evolving needs of the industry. Cybersecurity expert Bruce Schneier once emphasized that “Security is not a product, but a process,” a sentiment that resonates with the spirit of these guidelines, where building a cybersecurity defense framework is not a static endeavor but an ongoing process. Therefore, this guideline is designed to remain relevant, progressive, and adaptive to the dynamics of cyber threats in the future.

4

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Several key strategic substances highlighted in this guideline include: 1. Implementation of the Zero Trust Principle, which eliminates implicit trust within networks and promotes multi-layered authentication systems, device management, and dynamic access policies. 2. Cyber Risk Management based on both national and international frameworks such as ISO, NIST, CSMA BSSN, and CREST, aimed at measuring the cybersecurity maturity level of each Provider. 3. Data and Wallet Protection, through the implementation of cold wallets for the majority of consumer assets and end-to- end encryption using cryptographic algorithms that meet industry standards. 4. Incident Response Plan, developed with principles of effective coordination, swift recovery, and integrated reporting to OJK and all relevant stakeholders. 5. Enhancement of Technical Competence, conducted continuously through intensive training, professional certifications (such as CISA, CISSP, and CISM), and incident simulations to strengthen operational readiness. In addition to these technical substances, the guideline holistically integrates principles of sound information security governance, referencing international best practices while also considering the unique characteristics of Indonesian society within the context of an inclusive digital asset trading ecosystem. It is important to note that in this context, cybersecurity is not merely a technical matter, but an integral part of a comprehensive governance system. Therefore, this guideline emphasizes the importance of security governance, regular maturity assessments, independent audits, human resource capacity-building, and a culture of cybersecurity awareness throughout all levels of the organization. Furthermore, collaboration among regulators, industry actors, associations, academics, and the public serves as a fundamental principle for building strong national cyber resilience. As a regulator, OJK believes that the implementation of this guideline

5

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

will not only enhance consumer protection but also increase the global competitiveness of Indonesia’s digital financial asset industry. Cybersecurity is a long-term commitment that reflects institutional integrity, accountability, and responsibility in responding to digital transformation in the financial services sector. Finally, OJK extends its highest appreciation to all parties who contributed to the drafting of this guideline, particularly the British Embassy Jakarta for providing Technical Assistance, as well as OJK’s internal team, the cybersecurity professional community, industry actors, academics, and other relevant institutions and stakeholders. It is our hope that this guideline will serve as a strategic reference in building a secure, resilient, and sustainable digital asset trading ecosystem for Indonesia.

Wassalamu’alaikum warahmatullahi wabarakatuh. Jakarta, August 12, 2025

Hasan Fawzi Chief Executive

Financial Sector Technological Innovation, Digital Financial Asset and Crypto Asset Supervision and Member of The Board Commissioners of Indonesian Financial Services Authority

6

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Table of Content Foreword

2

CHAPTER 2 Cybersecurity Governance in the Digital Financial Asset Ecosystem 2.1 Blockchain Technology 18 2.2 Urgency of Cybersecurity 21 2.3 Vital Information Infrastructure 26 CHAPTER 3 Data Protection 3.1 Data Protection Policy 31 3.2 Principles of Data and Information Security 32 3.2.1 Confidentiality 33 3.2.2 Integrity 34 3.2.3 Availability 34 3.2.4 Accountability 35 3.2.5 Authentication 35 3.2.6 Authorization 36 3.2.7 Non-repudiation 36

CHAPTER 1 Introduction 1.1 Background

10 12 14

1.2 Objective

1.3 Scope

7

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

CHAPTER 4 Cybersecurity Strategy for Providers 4.1 Cybersecurity Implementation 40 4.1.1 Zero Trust Implementation 41 4.1.2 Access Control 43 4.1.3 Secure Storage Media 47 4.1.4 End-to-End Encryption 51 4.1.5 Network Segmentation 54 4.1.6 Multi-Layered Authentication Protocol 56 4.1.7 Wallet Protection 59 4.1.8 Secure Coding 65 4.2 Cybersecurity Maturity Level Assessment 67 4.3 Cybersecurity Ancillaries 71 4.3.1 Training 71 4.3.2 Awareness Building 74 4.3.3 Collaboration 75 4.4 Incident Response 78 4.4.1 Incident Response Phases 79 4.4.2 Resource Allocation 90 4.4.3 Cybersecurity Synergy 92 4.4.4 Incident Reporting 93

CHAPTER 5 Cyber Risk Management 5.1 Risk Assessment

98 101

5.2 Risk Treatment

5.3 Anti-Money Laundering (AML)

104

5.4 Third Party Risk Management

106 108

5.5 Audit

Glossary and Appendix Glossary: Definitions of key terms and acronyms in cybersecurity

112

Appendix: Cybersecurity Guidelines Implementation Checklist for Providers

117

Contact Person

146

8

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Introduction CHAPTER 1

9

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

10

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

1.1 Background

Article 215 of Act Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (P2SK Act) mandates that one of the principles of Financial Sector Technology Innovation (ITSK), including the Digital Financial Asset and Crypto Asset (AKD/ AK) industries, is the implementation of the security and reliability of information systems, including cyber resilience. Presidential Regulation Number 47 of 2023 on the National Cybersecurity Strategy and Cyber Crisis Management also regulates the importance of cybersecurity and incident response. The mandate of the Government Regulation of the Republic of Indonesia Number 49 of 2024 includes, among other things, the transfer of regulatory and supervisory authority over digital financial assets, including crypto assets, from the Commodity Futures Trading Supervisory Agency (BAPPEBTI) to Indonesian Financial Services Authority (OJK) on January 10, 2025. To carry out this supervisory and regulatory duty, OJK issued OJK Regulation Number 27 of 2024 concerning the Implementation of Trading in Digital Financial Assets, including Crypto Assets, which also emphasizes the importance of cybersecurity and cyber resilience. Providers of Digital Financial Asset Trading, hereinafter referred to as Providers, include Bourses, Clearing Institutions for Guarantees and Settlements, Custodians, Exchanges, and other parties designated by OJK. The cybersecurity landscape in Indonesia is rapidly evolving, driven by the increasing use of technology in the financial services sector. However, this development also brings cybersecurity challenges, including the risk of cyberattacks, data breaches, and other illegal activities. Cybersecurity has become a major concern among Financial Services Industry actors.

11

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

As of June 2025, there are 20 Exchanges licensed by OJK. In addition, there are three supporting entities in the ecosystem, namely one Bourse, one Clearing Institution for Guarantees and Settlements, and one Custodian. During the same period, the number of crypto consumers reached 16.32 million, based on the number of consumers who had conducted transactions on Exchange platforms, with the total value of crypto asset transactions reaching Rp. 226.5 trillion. In Indonesia, there was a hacking incident involving a crypto exchange platform that resulted in the loss of digital assets. The incident began with unauthorized access to the Exchange’s backend system, allegedly carried out through phishing . After obtaining the credentials, the perpetrator exploited a security vulnerability and began transferring funds from the Exchange’s wallet to an anonymous wallet. Meanwhile, abroad, one of the largest cybersecurity incidents in the history of crypto exchanges occurred in February 2025, when a crypto Exchange platform was hacked, resulting in losses of over $1.5 billion in Ethereum and other ERC-20 tokens. The attack took place during a routine transfer between the Exchange’s cold wallet and hot/warm wallet. The hacker injected malicious JavaScript code that exploited a vulnerability in the user interface of the

12

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

custodial system being used, modifying the smart contract logic and disguising the true nature of the transaction. As a result, what appeared to be a legitimate transaction to the Exchange’s security team actually diverted funds to a wallet controlled by the hacker. Based on the incidents described above, Providers need to have clear guidelines for implementing effective and efficient cybersecurity measures. This guideline provides a risk management framework to help create a balanced ecosystem between innovation development, cyber resilience, and consumer protection. To achieve this, several key actions must be taken. First, Providers must implement the cybersecurity guideline. Second, ensure that cybersecurity practices are integrated and not overlooked during innovation development. Third, it is important to continuously follow technological advancements and update this guideline so it remains beneficial for consumers and the digital financial ecosystem in Indonesia.

1.2 Objective

The rapid growth of Crypto Asset adoption in Indonesia has made crypto asset trading a vital component of the country’s digital financial ecosystem. As the regulatory authority overseeing financial services, OJK recognizes the importance of maintaining a secure and trustworthy environment, including for crypto asset transactions. This guideline outlines cybersecurity measures specifically designed for Providers operating in Indonesia.

13

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2

1

Strengthening the resilience of

Serving as a standard technology security framework that can be used as a reference in the development, management, and supervision of Providers’ information systems.

Providers’ platforms against cyber threats, whether technical, social, or operational in nature.

The objectives of this guideline include:

3

4

5

Protecting consumers from negative impacts such as financial loss, data theft, or reputational damage caused by cyber incidents.

Promoting public and consumer

Ensuring the protection of consumers’ assets and data.

trust through the implementation of reliable security controls, transparency, and compliance with applicable regulations.

This guideline also emphasizes the importance of increasing consumer trust and enhancing security as key factors in driving sustainable market growth. By aligning the need for reliable security with the flexibility to adapt to technological advancements, this guideline prioritizes the integrity, resilience, and inclusivity of the crypto market.

14

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

1.3 Scope

This guideline provides a framework for Providers, covering data protection, cybersecurity strategies, incident response, maturity assessments, employee training, and risk management. The scope of this guideline includes, among others:

1.

Exchanges of Digital Financial Assets are business entities that conduct the trading of Digital Financial Assets, either on their own behalf and/or by facilitating consumers.

2.

Providers of Digital Financial Assets including Crypto Asset Bourse are business entities that organize and provide systems and/or means to facilitate activities related to the trading of Digital Financial Assets, including Crypto Assets, and/or provide reports on Digital Financial Asset trading.

Clearing Institutions for Guarantees and Settlements for the Trading of Digital Financial Assets including Crypto Assets, are business entities that provide services for the settlement of Digital Financial Asset trading transactions and guarantee of the settlement of Digital Financial Asset transactions. 3.

15

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

4.

Custodians for Digital Financial Assets including Crypto Assets are business entities that manage the storage of Digital Financial Assets for the purposes of safekeeping, maintenance, supervision, and/or delivery of Digital Financial Assets.

To support the effective implementation of this guideline, a checklist is provided as part of this Guideline to serve as a reference for verifying and controlling cybersecurity measures for Providers.

16

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

CHAPTER 2

Cybersecurity Governance in the Digital Financial Asset Ecosystem

17

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

18

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2.1 Blockchain Technology

Blockchain is a decentralized digital ledger composed of a continuously growing series of records known as blocks, securely linked to one another using cryptographic hashes. Each block is uniquely structured and contains three main elements: 1.  Cryptographic Hash : a unique digital fingerprint that identifies the previous block, ensuring the continuity and integrity of the chain against unauthorized changes. 2. Timestamp: indicates the exact time the block was created, providing a chronological framework for all transaction activities. 3. Transaction Data: contains detailed information about the activity or exchange recorded within the block.

19

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

This interlinked structure forms a chain in which each block depends on the integrity of the previous block. Once a block is added to the chain, its data cannot be changed. Any alteration of information would require the recalculation of the cryptographic hash of the relevant block and all subsequent blocks in the chain. Such changes also require consensus from the distributed network participants, making blockchain very difficult to manipulate and highly secure in nature 1 . Consensus can be achieved through mechanisms such as: a. Proof of Work (PoW): a consensus mechanism in blockchain that relies on computational power to maintain network security. In this system, miners compete to solve complex mathematical puzzles to gain the right to add a new block to the blockchain. The first miner to succeed is rewarded with incentives in the form of cryptocurrency. While PoW is proven to be reliable in maintaining network integrity, it requires significant energy and computing power, and is often considered inefficient in terms of energy consumption 2 . b.  Proof of Stake (PoS): an alternative consensus mechanism that is more energy-efficient than PoW. Instead of using computational power, PoS selects validators to create and verify new blocks based on the amount of cryptocurrency they “stake” in the network. The greater the stake, the higher the chance of being selected as a validator. With this approach, PoS significantly reduces energy usage (more efficient) while maintaining network security and decentralization 3 .

1 Zairis, Antonios, and George Zairis. “Digital Innovation: The Challenges of a Game-Changer.” European Conference on Innovation and Entrepreneurship, vol. , no. , 2022, pp. 630-637. 2 https://www.forbes.com/advisor/investing/cryptocurrency/proof-of-stake/; Sivianes Castaño, Manuel. “Design of a Blockchain-based Platform for Peer-to peer Energy Trading.” 2021, https://core.ac.uk/download/483360619.pdf. 3 https://www.forbes.com/advisor/investing/cryptocurrency/proof-of-stake/

20

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

By distributing the ledger across multiple nodes, blockchain technology eliminates single points of failure and enhances resistance to attacks. Within blockchain technology, there is the concept of a smart contract. A smart contract is an automated digital agreement based on code that executes independently within the blockchain network, without the need for third-party intervention. When certain predefined conditions embedded in the code are met, the smart contract automatically executes the specified instructions, such as transferring digital assets or granting access permissions automatically. Since smart contracts run on a blockchain platform, they share its characteristics, i.e., decentralization, transparency, and immutability, meaning that every execution of the contract is permanently recorded and cannot be manipulated. However, vulnerabilities can arise in unaudited smart contract code, making it susceptible to exploitation and potentially resulting in financial loss 4 . In addition to smart contracts, another critical aspect of blockchain security is wallet management. A wallet is a tool used to store and manage crypto assets using a private key and a public key, with the private key stored within the wallet. In practice, wallets can be classified into hot wallets (connected to the internet and easily accessible, but more vulnerable to attacks) and cold wallets (not connected to the internet, making them more secure against phishing, malware, and hacking). The use of cold wallet becomes a best practice standard for long-term crypto asset storage, particularly by entities such as digital asset bourses and virtual asset custodians. Thus, the integration of blockchain as the foundational infrastructure, smart contracts as the transaction automation logic, and wallet management as the access control to assets forms a technological ecosystem that complements and supports both security and efficiency in a blockchain-based digital economy.

4  https://link.springer.com/article/10.1007/s12083-021-01127-0

21

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2.2 Urgency of Cybersecurity

In an increasingly connected digital era, cybersecurity serves as a key pillar in maintaining service continuity and user trust, especially for Providers. The ever- evolving nature of cyber threats demands preparedness and swift response from all entities, as well as the ability to restore systems and services after an attack occurs. Cybersecurity encompasses efforts to protect the confidentiality, integrity, and availability of information and information systems connected via digital media.

22

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Beyond these three core pillars, cybersecurity also involves aspects such as authenticity, accountability, non-repudiation, and reliability of both processes and information systems. To fully understand the urgency of cybersecurity, it is important to recognize the various types of threats that could potentially disrupt information systems and digital assets. These threats are the main reason why cyber protection must be a strategic priority. Threats may not only come from malicious external actors but can also stem from internal errors, misuse of access, and unidentified vulnerabilities within the digital supply chain. Several forms of cyber threats that warrant special attention include:

1.

Malware

Malware (malicious software) is software designed to damage, steal data, or take control of a device without permission. Such disruptions can cause both direct and indirect losses to the system owner.

2. Ransomware

Ransomware is a type of malware that encrypts a victim’s files and demands a ransom to unlock the files. In other words, ransomware holds data hostage and demands payment for its release.

23

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Web defacement is an attack on a website by altering or modifying its appearance according to the attacker’s intent. This type of attack is often used to promote certain ideologies or as a form of electronic vandalism. 3. Web Defacement

4. Denial of Services (DoS) and

Distributed Denial of Services (DDos)

DoS and DDoS attacks disrupt the availability of electronic systems, such as transaction services or official access, by flooding the network or system with a massive number of access requests, making its capacity seemingly full.

5. Phishing

Phishing is a deceptive technique used to obtain personal or sensitive information such as login data, financial information, or other private data. It is typically carried out via email, text messages, or fake websites that mimic legitimate ones.

24

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

6. Social Engineering

Social engineering is the psychological manipulation of victims to perform actions that compromise their own or others’ security, such as clicking malicious links, sharing confidential information, or transferring money.

7.

Man-in-the-Middle (MitM)

Man-in-the-middle is a type of cyberattack in which the attacker secretly positions themselves between two communicating parties, whether between users and applications, or between systems, to steal, modify, or manipulate the exchanged information without either party’s knowledge.

8. Zero-Day Attack

Zero-Day Attack is a cyberattack that exploits vulnerabilities in software or systems that are unknown to or have not been fixed by the developer or vendor as no security patches or fixes are available at the time of the attack.

9. Cyber Espionage

Cyber espionage is the theft of confidential or sensitive information, such as business data, government information, or trade secrets. It is often carried out by state-sponsored hackers or criminal groups.

25

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

10. Supply Chain Attack

Supply Chain Attack targets third parties to gain access to larger organizational systems or data. This type of attack is especially dangerous because it can affect multiple organizations simultaneously.

11. Credential Stuffing

Credential stuffing is an attack that utilizes illegally obtained credentials (such as consumer names and passwords) to access online accounts. These credentials are usually acquired through phishing, data breaches, or malware.

Cyber threats are not limited to those previously mentioned. With the rapid advancement of technology and the complexity of the digital ecosystem, Providers must proactively monitor and anticipate potential threats that continue to emerge. These include

26

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

software vulnerability exploitation, artificial intelligence-based attacks, digital identity abuse, and increasingly sophisticated social engineering techniques. Therefore, Providers need to implement an adaptive security approach based on threat intelligence and ensure that security policies and infrastructure are regularly updated to maintain sustainable cyber resilience. Providers are attractive targets for hackers due to the high-value assets they manage. They often store consumer funds in hot wallets, making them more vulnerable to large-scale cyberattacks. Hacking remains a serious threat in the cybersecurity aspect of various organizations. Cyber resilience refers to a Provider’s ability to maintain business continuity by taking anticipatory, adaptive, and proactive measures against cyber threats. Providers are not only required to protect their electronic systems from cyberattacks but must also be able to detect and recover from cyber incidents. In addition, Providers should monitor cyber incidents as a means of communicating their cyber resilience and security to stakeholders.

2.3 Vital Information Infrastructure

The identification of Vital Information Infrastructure (IIV) outlined in this guideline is crucial, particularly in relation to regulations. Presidential Regulation No. 82 of 2022 on the Protection of Vital Information Infrastructure (IIV) details the responsibilities and processes required to protect vital information infrastructure, which is essential for maintaining national security, economic stability, and public safety.

27

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Providers handle significant financial transactions and personal data, making them potential targets for cyber threats. Identifying and classifying a Provider’s systems as part of the IIV can contribute to broader efforts to protect infrastructure that is vital to the country’s stability and security. This includes regular assessments, updates, and enhancements of security protocols, thereby strengthening systems against cyberattacks and reducing the likelihood of successful attacks. The regulation also requires entities designated as part of the IIV to conduct self-assessments and comply with the established cybersecurity standards.

28

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Data Protection CHAPTER 3

29

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

30

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

With the growing exposure to various forms of cyberattacks, data protection has become a strategic aspect that must receive serious attention from Providers. The complexity of threats such as system hacking, identity theft, and infiltration of backend infrastructure demands the implementation of comprehensive and multi-layered information security policies. In this regard, Providers are required to possess and enforce data protection policies that cover at least four key components: data encryption, data storage security, access control, and device control.

31

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

The encryption policy must be designed to protect all sensitive data, including consumer identification numbers, personal data, financial information, and data processing results that could lead to the identification of individuals, done using standardized and cryptographic algorithms whose security has been proven. Encryption should apply not only when data is at rest but also when data is in transit. Furthermore, servers storing data must be protected by advanced firewall systems, network segmentation, and intrusion detection mechanisms to prevent both external and internal attacks. Data protection cannot be effective without strict access control management, where only authorized parties with appropriate risk profiles are granted access to specific data. This must be reinforced by the implementation of the least privilege principle, the use of multi-factor authentication (MFA), and the documentation of access logs for audit and investigation purposes. Finally, data storage system security testing and audits must be conducted regularly by both internal teams and independent third parties to ensure that the systems in use comply with AKD/AK industry standards and applicable regulations, including personal data protection policies.

3.1 Data Protection Policy

In today’s digital era, personal data protection is becoming increasingly crucial, considering that the collection and storage of data are generally conducted online. Therefore, compliance with the provisions on personal data protection and privacy, as stipulated in Law Number 27 of 2022 on Personal Data Protection, is imperative. This compliance includes, but is not limited to, determination of the location of personal data storage and the mechanisms for data transfer, both domestically and across borders.

32

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

OJK Regulation Number 27 of 2024 further elaborates on the implementation of personal data protection that must be carried out by Providers. Article 3 paragraph 2 letter (g) states that Providers must implement personal data protection when conducting trade. Article 119 of Chapter 12 on Personal Data Protection further stipulates that Providers are obligated to maintain the integrity and availability of personal data, transaction data, and financial data under their management from the point of collection until the data is destroyed. Providers also have the obligation to keep consumer data and/or information confidential. Furthermore, crypto assets traded in the Digital Financial Asset Market, as mentioned in Article 8 paragraph 2 letter (k), must consider consumer protection methods and personal data protection. These provisions strengthen the cause for Providers to give greater attention to the implementation of data protection policies within their business operations.

3.2 Principles of Data and Information Security

The systems built and/or used by Providers must adopt the Zero Trust Architecture (ZTA) principle. Under the zero-trust approach, every application user, device, and system must go through a verification process each time they request access. In other words, access is not granted automatically, even if the user or device is already within the internal network 5 . The Zero Trust principle emphasizes Secure by Design , ensuring that security considerations are integrated from the earliest stages of system design rather than being added as a complement, including default system configurations that are inherently set to the most secure state to minimize the risk of negligence or configuration errors.

5  National Institute of Standards and Technology, NIST Special Publication 800‑207 - Zero Trust Architecture

33

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

The Zero Trust approach reinforces the implementation of basic information security principles, i.e., Confidentiality, Integrity, and Availability, commonly known as the CIA model, as well as other principles as described below.

All sensitive data must be encrypted using reliable cryptographic standards to ensure that the data remains secure even if accessed by unauthorized entities. Providers must implement reliable encryption standards such as AES- 256, while also considering the trade-off between security level and processing speed. In addition to encryption, multi-layered data storage protection must be prioritized, which includes software and security updates as well as the implementation of appropriate controls and access policies. This strategy is carried out to protect data and help prevent sensitive data from being vulnerable to cyberattacks. 3.2.1 Confidentiality

34

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

3.2.2 Integrity

Integrity refers to the assurance that data remains whole and accurate throughout its lifecycle. Therefore, in order to prevent data from being altered illegally, whether intentionally or unintentionally, practices that can be implemented by Providers to maintain their integrity are needed. Stakeholders can be involved in promoting a system architecture that follows privacy by design principles to reinforce integrity across all operational processes.

3.2.3 Availability

Availability focuses on ensuring that data and information systems can be accessed consistently by authorized parties when needed. Ensuring that data backups are well-maintained and have an automatic failover system is an example of measures to uphold availability effectively.

35

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

3.2.4 Accountability

Accountability means that every activity and access to the system can be traced back to a specific entity or individual. To that end, it must be ensured that all operational and administrative activities are recorded and stored (in accordance with best practices) systematically through secure and immutable logging mechanisms. Measures such as the implementation of SIEM for system activity logging, as well as external audits by third parties, can serve as forms of accountability to ensure compliance with applicable regulations and policies.

3.2.5 Authentication

Authentication is the process of verifying the identity of an entity before granting access to a system. An example of a strong and adaptive authentication method is Multi-Factor Authentication (MFA) applied to all accounts with access to sensitive systems or digital assets.

36

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

3.2.6 Authorization

Authorization governs user access rights after the authentication process is successfully completed. Implementing Role-Based Access Control (RBAC) so that only authorized parties can access or modify certain data and systems is a measure that can be used as a reference for effective authorization mechanisms.

3.2.7. Non-repudiation

The principle of non-repudiation is critical in implementing authentication and authorization for consumer transactions in digital asset trading to ensure that any actions or transactions carried out by a consumer cannot be denied or replicated by any party. Thus, in the event of a dispute or suspicious activity, the Authorities and Providers can prove who was responsible for the transaction.

37

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

In the Financial Services Authority Regulation (POJK) Number 27 of 2024, it has been discussed in more detail regarding the implementation of personal data protection that must be established by the Provider.

*This regulation is dynamic; please refer to the most recent laws and regulations.

38

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Cybersecurity Strategy for Providers CHAPTER 4

39

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

40

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

4.1 Cybersecurity Implementation

Cybersecurity implementation is crucial in today’s digital era due to the increasing reliance on information technology and the internet. Without reliable protection, systems and sensitive data are vulnerable to cyberattacks such as hacking, data theft, ransomware, and operational disruptions that can lead to financial losses or reputational damage to the Providers. Cybersecurity is not solely the responsibility of the IT team; it requires awareness and active participation from all employees to build a resilient and sustainable digital defense system that protects the integrity, confidentiality, and availability of information. Cybersecurity implementation includes but is not limited to the following:

41

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

4.1.1 Zero Trust Implementation

The implementation of a Zero Trust architecture is a strategic step in enhancing the resilience of information systems against various complex and evolving cyber threats. Zero Trust no longer relies on the network perimeter as the main security barrier as it focuses on continuous verification, risk-based access control, and strict separation of access privileges. The implementation of Zero Trust in an operational environment can be carried out through the following key criteria:

Device Posture Checking 1 Device Posture Checking is the process of evaluating the condition and security status of a device before granting it access to an organization’s network or resources. The goal of this step is to ensure that only devices meeting minimum security standards are allowed to communicate within the system. The parameters to be checked should at least include: a. Operating system update status: to ensure the device does not contain known vulnerabilities. b. Active and updated antivirus: to detect and prevent potential malware that could threaten the system. This step directly supports the Zero Trust principle that access should not be granted merely based on network location, but based on the trustworthiness of the device.

42

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2

Dynamic Policy Enforcement

Zero Trust requires systems to adjust access policies in a contextual and adaptive manner. This dynamic policy enforcement mechanism ensures that every access request is evaluated in real time based on relevant context, such as user identity, geographic location, device type, and network traffic patterns. Some key criteria in the enforcement of these policies include: a. Geolocation: The system only allows access from approved geographic regions to prevent access attempts from high-risk locations. b. T raffic analysis and anomaly detection: The system should integrate both rule-based detection methods and behavioral analytics to identify activities that deviate from normal patterns.

3

Support from Technology and Additional Security Architecture

The implementation of Zero Trust depends on the integration of supporting technology that strengthens control and visibility of all system activities. Several technical components recommended by the Cybersecurity and Infrastructure Security Agency (CISA) as part of Zero Trust implementation include:

43

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

a. Security Information and Event Management (SIEM): for centralized log consolidation, correlation, and analysis. b. Intrusion Detection System (IDS): for passively detecting malicious activities or intrusions. c. Intrusion Prevention System (IPS): for actively preventing and automatically blocking identified attacks.

With this approach, Providers do not rely solely on initial authentication, but continuously monitor, verify, and evaluate all activities within the system, in accordance with the basic principle of Zero Trust: “Never trust, always verify.”

4.1.2 Access Control

In the effort to strengthen information security systems, the implementation of strict and structured access control policies is crucial. One effective approach that can be applied is adopting various principles and best practices in user access management. Several key components to consider in access control implementation include user role management, the principle of least privilege, session settings and access request mechanisms, and session management. Below are important points that need to be applied to ensure the system remains secure, controlled, and aligned with information security governance standards:

44

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2. Least Privilege Principle: a. Grant users only the minimum level of access required to perform their duties. b. Conduct periodic audits of access levels to ensure compliance with the least privilege principle. 1. Role-Based Access Control (RBAC): a. Apply RBAC to grant access rights based on the user’s role within the organization. b. Regularly review access rights, roles, and permissions to ensure they align with policy function changes.

3. Access Requests and Approvals: a. Establish policies that cover the steps of access request, review, and approval based on the principle of least privilege and valid operational needs. b. Formulation of policies should include verification of the identity of the requester, assessment of the request’s relevance based on job function, validation by the data or system owner, and thorough logging of all approval histories as part of accountability and audit trails.

45

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Create periodic access rights review mechanism to identify and revoke no longer relevant or excessive privileges. d. Employ proactive alerting systems that automatically monitor and notify any changes to high-privilege access or roles. e. Centralized and integrated implementation of Identity and Access Management (IAM) enables organizations to manage user identities and access rights consistently across information technology environments, including local systems, cloud, and third-party applications. f. Implementation of Privileged Access Management (PAM) to manage, monitor, and control access to privileged accounts, such as system administrator accounts, database root accounts, or service accounts with access to critical infrastructure and data. g. PAM ensures that access is only granted to authorized parties, for a limited duration, and with full monitoring and logging of every activity performed.

4. Session Management Session Management is a crucial aspect of controlling the security of user access to information systems, particularly in the context of web-based applications, cloud, or digital financial service platforms. Improper session management can create gaps for various types of misuse, such as session hijacking, session fixation, and unauthorized access due to improperly terminated sessions. To mitigate these risks, the comprehensive implementation of user session policies and

46

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

technical controls is necessary, by considering the following aspects: a. Auto-Session Timeout Organizations must implement an auto-session timeout mechanism that automatically disconnects or ends a user session after a specific period of inactivity (e.g., 15–30 minutes for critical systems). The goal is to prevent unauthorized parties from accessing the system via unattended devices left in a logged- in state. Timeout durations should also be adjusted based on the sensitivity of the accessed data and the associated operational risk. b. Session Token Security and Management Session tokens (e.g., Java Web Token (JWT), OAuth tokens) used to authenticate user sessions must be: 1 Securely stored (e.g., in HTTP-only secure cookies for web applications). 2 Configured with token expiration times that are reasonable and proportionate to their risk level. 3 Automatically revoked when users log out of the system, or when credential changes occur, such as password updates, token rotation, or anomaly detection in the session. To prevent the misuse of stolen tokens, the system must also be capable of detecting and forcibly terminating active sessions if suspicious activity is identified or if there are reports of a compromised account.

47

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Re-Authentication and Step-Up Authentication For access to data or privileged functions, the system must enforce re-authentication or step-up authentication. This mechanism requires users to re-authenticate (e.g., re-enter a password, OTP, or use biometric factors) before accessing sensitive resources such as:

• Management of other user accounts. • High-value or critical transactions. • System configuration changes. • Access to logs or encrypted data.

T he purpose of this step is to reverify the user’s identity, especially in long-running sessions, and strengthen access control so that it does not rely solely on initial authentication.

4.1.3 Secure Storage Media

In modern information systems, secure data storage is a vital component in maintaining the confidentiality, integrity, and availability of information. The implementation of secure storage does not rely solely on encryption technology but also includes access management, operational oversight, and robust policies and procedures. Data storage security strategies must be designed comprehensively by considering the following key aspects:

48

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

1. Security Management a. The data storage environment must be protected with multiple layers of security. This includes the use of servers equipped with firewalls to prevent unauthorized external access and up-to-date antivirus. In addition, data centers must have strict physical security systems to prevent unauthorized physical access. b. Ensure that password hashes are stored separately from other sensitive data to reduce the risk of leakage in the event of a data breach. c. Use dedicated and secure storage mechanisms for sensitive data, while continuing to implement the principle of least privilege. 2. Data Center and Disaster Recovery Center The Data Center and Disaster Recovery Center must be located in Indonesia, with the Disaster Recovery Center situated at least 20 (twenty) kilometers from the location of the Data Center. The use of servers or cloud servers must be with international standard certifications related to information security management systems. If the server or cloud server is provided by a third party, the provider must have an official representative office in Indonesia.

49

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

3. Access Audit and Logging Activities related to storage media must be auditable and comprehensively monitored, including: a. Implementing a logging system that records user or system identity, access time, type of operation (read, write, delete, modify), as well as IP address or location of each activity. b. Storing logs in a tamper-evident system and integrating them with SIEM for correlation, anomaly detection, and real-time incident reportin.. c. Conducting regular log reviews by an independent team or internal security team to detect potential breaches or suspicious activities. 4. Redundancy and Backup a. The implementation of regular and reliable data backups needs to utilize automated backup systems for critical data. b. Ensuring that the infrastructure of data centers and backup data centers has equivalent configurations, capacity, and security levels (1:1 ratio) to guarantee operational continuity and seamless service recovery in the event of disruptions. c. Conducting regular testing of backup data to ensure that data can be fully recovered. d. Backup data needs to be encrypted to protect against unauthorized access. e. Developing and maintaining data, including procedures to restore data after loss or damage. f. Performing regular recovery simulations to ensure that the staff understand and can efficiently execute recovery procedures.

Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20 Page 21 Page 22 Page 23 Page 24 Page 25 Page 26 Page 27 Page 28 Page 29 Page 30 Page 31 Page 32 Page 33 Page 34 Page 35 Page 36 Page 37 Page 38 Page 39 Page 40 Page 41 Page 42 Page 43 Page 44 Page 45 Page 46 Page 47 Page 48 Page 49 Page 50 Page 51 Page 52 Page 53 Page 54 Page 55 Page 56 Page 57 Page 58 Page 59 Page 60 Page 61 Page 62 Page 63 Page 64 Page 65 Page 66 Page 67 Page 68 Page 69 Page 70 Page 71 Page 72 Page 73 Page 74 Page 75 Page 76 Page 77 Page 78 Page 79 Page 80 Page 81 Page 82 Page 83 Page 84 Page 85 Page 86 Page 87 Page 88 Page 89 Page 90 Page 91 Page 92 Page 93 Page 94 Page 95 Page 96 Page 97 Page 98 Page 99 Page 100 Page 101 Page 102 Page 103 Page 104 Page 105 Page 106 Page 107 Page 108 Page 109 Page 110 Page 111 Page 112 Page 113 Page 114 Page 115 Page 116 Page 117 Page 118 Page 119 Page 120 Page 121 Page 122 Page 123 Page 124 Page 125 Page 126 Page 127 Page 128 Page 129 Page 130 Page 131 Page 132 Page 133 Page 134 Page 135 Page 136 Page 137 Page 138 Page 139 Page 140 Page 141 Page 142 Page 143 Page 144 Page 145 Page 146 Page 147 Page 148

Made with FlippingBook Ebook Creator