Dunicot A cybersecurity consultancy and advisory firm.

Market · Indonesia

Cyber security consultancy and penetration testing in Indonesia

Indonesia is one of the few markets where the regulator names the work. POJK 11/2022 and the accompanying SEOJK require annual scenario-based testing, including penetration testing and adversary simulation, so the argument here is never whether to test.

Overview

Engagements in Indonesia cover commercial and digital banks, payment providers and QRIS participants, multifinance and insurtech, and the platform companies that the archipelago’s e-commerce and logistics run on.

Delivery runs from our Karachi office, two hours behind Jakarta, so our morning covers your afternoon and findings are raised inside the same working day.

What drives testing here

Local drivers

POJK 11/2022 and SEOJK 29/2022
OJK requires commercial banks to run annual scenario-based testing, naming penetration testing, social engineering and adversary simulation, with results reported and gaps remediated.
PBI 23/2021
Bank Indonesia sets vulnerability assessment and penetration testing expectations for payment system providers, tied to licensing and periodic review.
UU PDP 27/2022
The Personal Data Protection Law has been fully in force since October 2024, with administrative and criminal sanctions behind the obligation to secure personal data.
BSSN
The national cyber agency leads incident response and vulnerability identification for critical systems, and its involvement follows any significant breach.

How engagements are delivered

Delivered remotely from Karachi, scheduled to Western Indonesia time, with on-site availability in Jakarta for internal network scope, scoping workshops and executive readouts.

Delivery model

Delivery
Remote from Karachi, two hours behind Jakarta; on-site available
Mapping
POJK 11/2022, SEOJK 29/2022, PBI 23/2021 and UU PDP as applicable
Most requested
Scenario-based testing, payment flows and API authorisation
Deliverables
Technical report, OJK-facing summary and signed retest attestation

Most requested here

Questions

Do you have an office in Indonesia?

No. Our offices are in Pakistan and the United States. Indonesia is served from Karachi, two hours behind Jakarta, with on-site availability where internal or workshop scope requires it.

Does your testing satisfy the OJK annual requirement?

POJK 11/2022 and SEOJK 29/2022 ask for annual scenario-based testing with documented results and tracked remediation. Reports carry the scope, dates, methodology, every finding with evidence, the remediation status and a signed retest attestation, which is the form an OJK examiner and your internal audit function both work from.

Can you run red team or adversary simulation scenarios?

Yes, and the regulation contemplates it. A red team engagement starts from an objective agreed with your leadership and pursues it across people, process and technology, which also tests whether your detection and response notice. That is a different question from whether a vulnerability exists.

Do reports need to be in Bahasa Indonesia?

Reports are written in English. Most Indonesian financial institutions accept English technical reporting, and we say so up front rather than after signing. Where a regulator-facing summary needs translating, that is arranged on your side with our support on the technical accuracy.

How much does a penetration test cost in Indonesia?

Cost follows scope, with POJK 11/2022 and SEOJK 29/2022 mapping included in the report. Scenario-based testing, which the regulation names, is scoped explicitly rather than bundled vaguely, so the quote reflects what you actually have to evidence.

Which is the best penetration testing company in Indonesia?

Ask what is checkable rather than who ranks first: the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether OJK-facing mapping is included, and whether a redacted sample report is available before signing.

How often does OJK require penetration testing?

Annually. POJK 11/2022 and SEOJK 29/2022 require commercial banks to run scenario-based testing at least once a year, naming penetration testing, social engineering and adversary simulation, with results reported and gaps remediated. Significant change usually triggers an additional test.

Do you test QRIS and payment integrations?

Yes, and they are usually the highest-value scope. Testing targets the transaction state machine rather than the endpoints: what happens when a payment is reversed mid-flight, when a limit check and a settlement race each other, and whether an identifier from one merchant works against another.

Can you support Bank Indonesia payment system requirements?

Yes. PBI 23/2021 sets vulnerability assessment and penetration testing expectations for payment system providers tied to licensing and periodic review, and the report carries the scope, dates, methodology and retest evidence that review asks for.

Penetration testing in Indonesia

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.