Rajah & Tann Regional Round-Up
your snapshot of key legal developments in Asia
Issue 2 - Apr/May/Jun 2023
 

OJK Sets New Cyber Security Best Practices for Banking Industry

The Financial Services Authority ("OJK") of Indonesia has taken significant steps to boost the digital banking transformation in the country. In line with this goal, OJK Regulation No. 11/POJK.03/2022 on the Implementation of Information Technology by Commercial Banks was issued last year, addressing various aspects such as data, technology, risk management, collaboration, and institutional setting. As a follow-up to this regulation, Circular Letter No. 29/SEOJK.03/2022 on Cyber Security and Resilience for Commercial Banks ("Circular") has been introduced. The Circular emphasises the importance of cyber security and places the responsibility on banks to assess their cyber security risk annually, report their self-assessed ratings, and establish dedicated cyber security units.


Under the Circular, banks are required to conduct assessments of inherent risk and cyber security maturity to determine their cyber security risk level. The results of these assessments must be reported to OJK, along with regular cyber security testing. Additionally, banks must establish independent cyber security units to manage cyber security and coordinate cyber incident response teams. While some market players view the requirements under the Circular as reasonable for effective risk management, challenges may arise in implementing certain aspects, particularly those related to human resources for the cyber security units. The success of these regulations will depend on customer awareness and participation in preventing cyber security threats, and it remains to be seen if similar standards will be adopted by non-bank financial services and other industries in the future.


For more information, click here to read our Legal Update.



Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice.

 

Assegaf Hamzah & Partners
Jakarta Office
Level 36 & 37, Capital Place
Jalan Jenderal Gatot Subroto Kav 18
Jakarta 12710, Indonesia

Surabaya Office
Pakuwon Center, Superblok Tunjungan City
Lantai 11, Unit 08
Jalan Embong Malang No. 1, 3, 5,
Surabaya 60261, Indonesia
http://id.rajahtannasia.com


Contacts:

Bono Daru Adji
Senior Partner
D +62 21 2555 7800
F +62 21 2555 7899
bono.adji@ahp.co.id

Ahmad Fikri Assegaf
Senior Partner/Co-Founder
D +62 21 2555 7800
F +62 21 2555 7899
ahmad.assegaf@ahp.co.id

Chandra M Hamzah
Partner
D +62 21 2555 7800
F +62 21 2555 7899
chandra.hamzah@ahp.co.id

Eri Hertiawan
Partner
D +62 21 2555 7800
F +62 21 2555 7899
eri.hertiawan@ahp.co.id

Ibrahim Sjarief Assegaf
Managing Partner
D +62 21 2555 7800
F +62 21 2555 7899
ibrahim.assegaf@ahp.co.id


Rajah & Tann Singapore LLP


Contacts:

Hamidul Haq
Partner
D +65 62320398
hamidul.haq@rajahtann.com

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This update is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this update.