Can the Indonesian government keep its growing number of digital systems secure?
Sulistyo, Deputy for Cyber Security and Cryptography for Government and Human Development at BSSN, is calling for security to be built into systems from the outset, maintained throughout their lifecycle, and backed by the readiness to respond to and recover services when attacks occur.

BSSN Deputy for Cybersecurity of Government and Human Development, Sulistyo, says security by design must be built into government digital systems from the outset. Image: Canva
The ransomware attack on Indonesia’s National Data Centre (PDNS) in June 2024 was a reminder that a single cyber disruption can ripple across multiple government services.
The incident – which implicated shared infrastructure for more than 228 ministries, agencies and local governments – disrupted immigration services, scholarship registration, and government correspondence and records management through Srikandi.
According to Sulistyo, Deputy for Cyber Security and Cryptography for Government and Human Development at the National Cyber and Crypto Agency (BSSN), building a system is only the first step.
The next step is ensuring that the system remains secure, properly maintained, and capable of being restored when an attack occurs.
“Security should not be left until the final check but designed from the outset through security by design. Security must be treated as mandatory,” he says.
Security starts before a system goes live
Sulistyo emphasises that a security-by-design approach places security throughout the entire lifecycle of a system, from planning and development through to operations and maintenance, and even after the system is no longer in use.
This direction is pursued through a draft Presidential Regulation on Digital Government, reflecting previous regulations on the Electronic-Based Government System (SPBE).
The government has also issued Presidential Regulation No. 132/2022 on SPBE Architecture, which includes security as one of its domains.
However, Sulistyo says further strengthening is needed to make security a more decisive consideration from the earliest stages of system development.
One way to do this is to establish security criteria from the procurement stage. These requirements should form part of decisions about which technologies are used and how systems are developed.
Technology products used by the government, for example, could be required to have certain certifications or pass specific security tests, he adds.
With this approach, security is no longer treated as a final check after a system has been built.
Maintaining systems, closing security gaps
Sulistyo also highlights how evolving cyber threats make system maintenance increasingly important.
“When government systems have been operating for years without receiving technological or security updates, vulnerabilities will emerge.”
He says the government administration sector was among the three sectors with the highest levels of anomalous traffic over the past three years. Based on BSSN analysis, around 60-80 per cent of this traffic was caused by malware.
BSSN has also identified recurring issues, ranging from the use of pirated software and expired licences to the absence of antivirus protection and failures to carry out patching and updates.
“If software, applications, or hardware containing firmware have expired licences and pirated products are being used, there will be failures in the patching process,” he says.
Software vulnerabilities are recorded through Common Vulnerabilities and Exposures (CVE), allowing developers to provide updates when security flaws are identified.
But those updates are only effective if system operators actually apply them.
System operators therefore need to assess more than whether an older system is still functioning.
They also need to establish whether it continues to receive security updates, whether it has unresolved vulnerabilities, and whether it remains appropriate for current security requirements, he adds.
This is particularly important for systems classified as Critical Information Infrastructure (CII), especially those supporting essential services or human safety.
Sulistyo cites air navigation and air traffic control radar systems as examples. Disruptions to obsolete systems could affect aircraft navigation as well as landing and take-off operations.
Similar risks can emerge in healthcare as medical devices become increasingly connected to digital systems.
“If medical record data is manipulated, it can have an impact on human safety,” he says.
These examples show that not all systems carry the same level of risk or require the same level of protection. The greater the potential impact of a system on society, the more important it is to regularly manage vulnerabilities, conduct testing, and maintain the system.
Systems must be ready to withstand and recover from attacks
Even when systems are securely designed and regularly updated, no system is completely immune to attacks.
The government therefore also needs the ability to detect, respond to, and recover services when incidents occur.
One of BSSN’s efforts is to encourage ministries, agencies and local governments to establish Cyber Security Incident Response Teams (CSIRTs).
These teams are not only needed once an attack has occurred. Before an incident, they need to prepare procedures, build technical capabilities, and conduct exercises so that agencies know what to do when facing attacks such as defacement, data breaches, or ransomware.
“Cyber incident response teams do not only work when an incident occurs. They continue working before an incident happens,” says Sulistyo.
BSSN also provides technical guidance and incident-response simulations covering both technical and non-technical aspects.
The number of such teams increased in 2025. According to Sulistyo, around 97 per cent of ministries, agencies and local governments had established CSIRTs, compared with around 42 per cent the previous year.
In 2026, teams across ministries, agencies, and local governments continue to be consolidated.
However, responding to an incident should not stop once services are restored. Agencies need to assess how the attack occurred and address the weaknesses that were identified.
“Every incident can become a source of learning for the government more broadly,” he notes.
Cybersecurity legislation is critical
The next challenge is ensuring that security recommendations are actually implemented.
While BSSN can conduct tests, identify vulnerabilities, and provide recommendations to system owners,its authority to impose sanctions remains limited when those recommendations are not followed.
“We provide recommendations for them to implement. If they are not implemented, we cannot impose sanctions,” he says.
Sulistyo says a stronger legal basis is therefore needed to ensure that security does not remain merely a recommendation or an option.
Such reinforcement is expected through the Cybersecurity and Cyber Resilience Bill (RUU Kamsiber), which is intended to make security obligations more binding.
“So, recommendations will no longer be merely advisory or optional, but become an obligation,” he concludes.