Indonesia connected devices IoT security regulation

Indonesia Is Building Cyber Incident Response Teams Before It Has Set a Security Baseline for Connected Devices

BSSN's 59 new incident response teams add response capacity, but Indonesia still has no binding IoT security standard, so teams will keep cleaning up preventable failures.

BSSN's New Incident Response Teams People of Internet Research · Indonesia 59 Teams inaugurated Cyber incident response teams inau… 37 Regional government teams The largest group among the 59 tea… 29 Apr 2024 UK IoT regime start Date the UK consumer connectable p… peopleofinternet.com
BSSN's New Incident Response Teams People of Internet Research · Indonesia 59 Teams inaugurated 37 Regional government teams 29 Apr 2024 UK IoT regime start peopleofinternet.com

Key Takeaways

On 6 October 2026, Indonesia's National Cyber and Crypto Agency (BSSN) inaugurated 59 cyber incident response teams (Tim Tanggap Insiden Siber, TTIS) at its office in Depok. According to Sindonews' report carried by RCTI+, the teams are 13 for ministries and agencies, 37 for regional governments, 7 for the health sector and 2 for education. BSSN head Nugroho Sulistyo Budi called the inauguration "an beginning, not an end" and stressed how fast teams respond once an incident occurs. The report does not mention connected devices.

That omission is the useful part. Indonesia is building the machinery that responds to incidents before it has written the rules that would make many of them less likely.

The case for building response capacity first

The strongest argument for BSSN's order of operations deserves a fair hearing. Indonesia has hundreds of ministries, agencies and regional governments, and many have had no one whose job is to receive an incident report, triage it and coordinate recovery. A hospital that discovers ransomware on a Friday night needs a named team and an escalation path more urgently than it needs a procurement standard. Response capacity helps no matter where the attack came from, while a device standard only covers products made after it takes effect. Regulators who wait for perfect rules before building any capability often end up with neither.

The rollout also reaches sectors where failure is costly. Seven of the 59 teams sit in health, and a hospital's network increasingly contains connected infusion pumps, imaging equipment, cameras and building controls. The 37 regional teams cover the governments that run local services, CCTV networks and smart-city pilots.

What the device rules actually cover

This is where the gap shows. As far as we could establish, Indonesia has no binding baseline security standard for connected devices. The main device rule is the Communications and Informatics Minister's Regulation No. 3 of 2024 on certification of telecommunications equipment and devices, which took effect in May 2024 and replaced the 2018 rule. It applies to anyone who makes, assembles or imports telecommunications equipment for use in Indonesia. It tests each brand, model and country of origin against applicable technical standards, and equipment that passes receives a certificate. That is radio and telecom conformity: it checks that a device behaves properly on the spectrum and the network. We found no evidence that it requires unique default credentials, a vulnerability disclosure channel or a minimum period of security updates. Our search did not turn up an IoT-specific obligation in it, so we describe this as an absence of evidence rather than a confirmed exclusion.

A certified device can therefore pass every Indonesian check while shipping with a shared factory password and no update path. The certificate tells a buyer the product is legal to sell, not that it is hard to compromise.

What a baseline looks like elsewhere

Other jurisdictions have made a small set of requirements binding. The United Kingdom's consumer connectable product regime came into effect on 29 April 2024. It requires manufacturers to meet baseline security requirements drawn from the UK Code of Practice for Consumer IoT security and the ETSI EN 303 645 standard. The core ideas, as law firms described them while the rules were being drafted, were three: ban universal default passwords, publish a vulnerability disclosure policy, and tell consumers how long security updates will last.

The European Union went further with Regulation (EU) 2024/2847, the Cyber Resilience Act, adopted on 23 October 2024 and covering horizontal cybersecurity requirements for products with digital elements. It is broader and heavier than the UK approach, with compliance duties that reach software and a wide range of products.

Neither model should be copied wholesale. The Cyber Resilience Act's breadth carries real compliance cost, which falls hardest on small manufacturers and open-source maintainers, and a developing market with many importers does not need that weight on day one. The UK's three-rule floor is the better template, because each rule is cheap to implement, easy to verify at the border and aimed at the failures attackers exploit at scale.

Why the sequencing matters

Incident response and device baselines do different jobs, and the first cannot substitute for the second. Response teams act after compromise, at the cost of an investigation, downtime and recovery. A baseline acts at the factory, at close to zero marginal cost per unit. If every hospital, school and city office keeps buying devices with shared default credentials, the new teams will spend their time on a stream of preventable incidents, and their capacity will be consumed by problems that should never have reached them.

The pro-innovation position is not that Indonesia should regulate IoT heavily. It is the opposite: a short, outcome-focused floor reduces the need for heavier intervention later. Without one, the likely response to a high-profile device-driven breach is a hurried, broad mandate written under political pressure, which is the kind of rule that hurts local manufacturers and importers most.

A proportionate path

Indonesia does not need new institutions to start. Three steps would be enough:

BSSN's inauguration is a sound investment, and Nugroho is right that it is a beginning. The next step is to make sure the devices those 59 teams defend are not shipped insecure by default.

Sources & Citations

  1. Sindonews via RCTI+: BSSN inaugurates 59 TTIS
  2. UK Government: Secure by design (consumer connectable product regime)
  3. EU Cyber Resilience Act, Regulation (EU) 2024/2847
  4. Hogan Lovells: Security by design, UK and EU IoT legislation