For years, cybersecurity has largely operated within a reactive paradigm: install firewalls, update antivirus, wait for incidents to occur, then respond. This paradigm was already inadequate before generative AI became mainstream, and by 2025, when AI can be used to create phishing that is indistinguishable from genuine communication, automate vulnerability scanning, and generate adaptive malware, the gap between conventional defensive approaches and actual threats will widen even further.
At the same time, organizations in Indonesia are facing a new dimension of compliance: the Personal Data Protection Law No. 27 of 2022, which is now fully in effect. This means that cybersecurity incidents involving personal data are no longer just a technical issue; they are a legal issue with real financial and reputational consequences.
CIA Triad: An Unchanging Foundation Amid Evolving Threats
Amid the complexity of the cybersecurity threat landscape, the CIA Triad remains the most fundamental framework: Confidentiality (data can only be accessed by authorized individuals), Integrity (data is not modified without authorization), and Availability (systems and data are available to those who need them when needed). Every cybersecurity incident is essentially a violation of one or more of these three principles, and every security control implemented must be traceable back to all three.
- AI-powered threats include deepfake audio and video for social engineering, personalized spear phishing using data from LinkedIn and social media, automated vulnerability scanning; these threats operate at speeds and scales that human security teams cannot respond to without the aid of AI-based detection tools as well.
- Zero Trust Architecture is the “never trust, always verify” approach that does not assume security from the network position; every access is verified, every session is monitored—a model that is increasingly relevant as network perimeters can no longer be clearly defined in the era of remote work and cloud.
- Incident Response Plan is a written procedure that defines who does what, in what order, when a security incident is detected; it includes escalation, internal and external communication, and notifications to regulators in accordance with the provisions of the UU PDP.
UU PDP as a Catalyst for Security Improvement
The UU PDP not only regulates privacy but also effectively mandates certain data security standards. Organizations processing personal data are required to implement adequate technical and organizational measures to protect it. “Adequate” here is not a self-defined term; it will be measured against industry standards, and in many cases, ISO 27001 serves as the reference. In other words, the UU PDP acts as a catalyst that compels many organizations to systematically improve their information security posture.
The provisions in question have measurable figures. Article 46 of Law 27/2022 requires Data Controllers to provide written notification no later than 3 x 24 hours to the data subjects and to the authorities, and the notification must contain at least three things: what personal data was disclosed, when and how it was disclosed, and the handling and recovery efforts that have been undertaken. The two-year adjustment period provided by Article 74 has also expired since October 17, 2024, so the transition window has indeed closed.
There is one change that is rarely mentioned. Through Decision Number 151/PUU-XXII/2024, the Constitutional Court stated that the word and in Article 53 paragraph (1) letter b is conditionally contrary to the 1945 Constitution as long as it is not interpreted as and/or. This article regulates when organizations are required to appoint an officer or official to carry out the function of personal data protection, and with this new interpretation, the obligation is triggered when one of the conditions is met, rather than requiring all three to be met simultaneously. For many medium-sized organizations, this shifts the appointment of data protection officers from the “later” column to the “now” column.
You should also note the authority to which the aforementioned notification is directed. Article 58 delegates its establishment to the President through Presidential Regulation, and until September 2026, that regulation has not been issued, so compliance oversight is still carried out by the Ministry of Communication and Digital. On the other hand, the implementing regulation is already in place, namely Government Regulation Number 33 of 2026, which will take effect on January 15, 2027, and tightens the basis for processing and the way consent is obtained. This means that the incident response plan you are currently drafting should already assume this regulation, rather than waiting for the deadline to pass.
Sources
- Law No. 27 of 2022 on Personal Data Protection, JDIH BPK (status Effective, contains notes on material testing)
- Full text of Law No. 27 of 2022, Article 46, Article 53, Article 58, and Article 74
- Decision of the Constitutional Court Number 151/PUU-XXII/2024
- Bisnis.com, August 29, 2026: Implementing Regulations of the PDP Law, Stricter Consumer Data Consent