On September 4, 2026, ANTARA reported that the Indonesian Internet Service Providers Association (APJII) had urged the DPR to pass the Cybersecurity and Resilience Bill (RUU KKS). APJII chair Muhammad Arif said providers need "legal certainty to grow, not regulations that hamper" them, and asked for a single incident-reporting portal, clear security standards for ISPs of every size, and a two-year transition for smaller firms. DPR Legislative Body chair Bob Hasan described the bill as an umbrella framework, with technical detail to follow in implementing regulations. The bill remains unpassed.
The ISPs' requests are reasonable. The case for a cybersecurity law is also real. APJII's monitoring, cited by ANTARA, counted roughly 68 million attack events in the final three days of its window ending August 28, 2026. Operators currently report incidents to several agencies, and a statute that names one portal and one set of duties would lower compliance costs. An umbrella law that sets principles and leaves technical thresholds to regulators is a normal drafting choice, because technical standards change faster than statutes do.
Why the umbrella approach fails for shutdown powers
The argument for delegation is strong for audit standards and incident-report formats. It is weak for the power to cut or slow connectivity. Earlier drafts drew objections from Komnas HAM in October 2025, and from civil society, over the authority of BSSN, the national cyber agency, to cut or slow internet connections and filter content. Those objections were about who decides, on what trigger, and under whose review. Those are the questions an "umbrella" law tends to defer.
Indonesia's own record shows what deferral costs. In 2019 the government throttled bandwidth in Papua on August 19 and then blocked access in dozens of districts in Papua and West Papua. On June 3, 2020, the Jakarta State Administrative Court ruled the shutdown unlawful. The ruling covered throttling on August 19, 2019 and blocking across 29 cities and districts in Papua and 13 in West Papua from August 21 to September 4, 2019. Access Now reported the judges' view that any decision limiting the right to information must follow the law and not merely government discretion.
The Constitutional Court then took a different view of the underlying statute. In Decision 81/PUU-XVIII/2020, issued in October 2021, it upheld Article 40(2b) of the ITE Law, which lets the government cut access to content deemed unlawful. The petitioners were journalist Arnoldus Belau and the Alliance of Independent Journalists, who argued the article lacked procedural safeguards. According to the government's legal database, the Court found that the statute itself required implementing regulations and that due-process protections were reflected in Government Regulation 71/2019 and related ministerial rules. Two justices, Saldi Isra and Suhartoyo, dissented on the ground that the norm contains no procedure the government must follow, as noted in coverage of the ruling and the decision record.
The result is that Indonesian law now treats implementing regulation as the place where shutdown safeguards live. The RUU KKS would repeat that pattern at larger scale by giving BSSN a statutory power and deferring the limits. Regulations can be rewritten by the same executive that exercises the power, without a floor debate.
What a proportionate statute would contain
A pro-innovation position does not oppose emergency powers. It asks that they be narrow, temporary and reviewable. The bill can do that in a few provisions, without giving up its framework character:
- A defined trigger. Limit connectivity restrictions to a specific, named category of threat to critical information infrastructure, not to broad notions of content or public order.
- Least-restrictive means. Require targeted measures such as blocking an attack source or a specific service before any regional throttle, and rule out blanket shutdowns.
- Time limits and reporting. Set an automatic expiry and require a written order that is published afterward.
- Independent review. Provide prompt judicial or independent oversight, which addresses the dissenting justices' point that no procedure was specified.
- Compensation and notice for operators. ISPs carry out the cuts and bear the liability, so they have a direct stake in clear orders.
This last point connects APJII's agenda to the civil-society objections. An ISP that asks for legal certainty is also asking to know when it may be ordered to degrade its own network, and on what authority. A vague grant leaves operators to choose between defying a state order and harming customers.
The broader stakes
Shutdowns are becoming more common. Access Now's #KeepItOn campaign recorded 313 shutdowns in 52 countries in 2025, up from 78 in 2016. Ordinary users, small businesses and digital payment systems absorb the economic damage from these disruptions, and shutdowns rarely stop the attacks or unrest that prompt them.
DPR members have already stressed clear inter-agency authority and objective criteria for critical infrastructure designation, according to ANTARA's report. Those same principles apply to shutdown authority. Lawmakers can deliver the legal certainty ISPs want and still keep the emergency power in check by writing the outer limits of that power into the bill itself. Leaving them to a later regulation would repeat the pattern the 2021 dissent criticized.