- 19/07/2024
- Category: Press Release
Yogyakarta (12/7/24) – Cyberattacks have become an increasingly concerning phenomenon with increasing victims around the world, from organizations to government agencies. The recent cyberattack on Indonesia’s Temporary National Data Center (PDNS) has also attracted public attention regarding the condition of national data security and countermeasures. Participating in the discourse, the Center for Digital Society (CfDS) at UGM conducted the 114th series of Digital Future Discussion (Difussion) entitled “Global Cyber Threat Landscape: What are the Trends and Solutions?”. This activity was held on Friday (12/7) with Tane Andrea Hadiyantono and Ayom Mratita Purbandani, Research Assistants of CfDS. This event was broadcast live through the official YouTube account of CfDS UGM at the link https://www.youtube.com/watch?v=44f7zNrtQUw.
Tane Hadiyantono discusses how, although digital transformation creates opportunities for the Global South to leapfrog legacy digital infrastructure, it is being outpaced by the Global North, which has a more mature technology industry. This has led to a tendency for the Global South to become renters rather than creators of technology. The rapid development of data in the era of digital transformation creates vulnerabilities to attacks such as malware, Denial-of-Services (DOS) attacks, phishing, impersonation, supply chain attacks, and social engineering attacks. Many countries are mobilizing their capabilities and budgets to strengthen their cybersecurity, such as the United States budgeting 0.7 percent of their state budget in 2022 and the United Kingdom budgeting 2.6 billion GBP in 2021 for civilian cybersecurity. Indonesia itself, through BSSN, has budgeted 0.02 percent of the state budget for cybersecurity in 2023.
Tane argued that the existence of LockBit, a Ransomware-as-a-Service (RaaS) business since 2019, exacerbated data security vulnerabilities, with 2500 victims and up to a USD 500 million ransom. She outlined some of the challenges faced by the Global South, such as being a new target of cyberattacks due to the security tightening of the Global North, budget issues related to security expenditure, the tendency to become ‘renters’ of digital technologies and services, and weak frameworks and regulations in responding to cybercrime. Tane outlined her recommendations to the Indonesian government in responding to this issue. “First of all, the government should actively invest in its cybersecurity. Maybe the government and the House of Representatives should rethink about increasing the cybersecurity budget and should also invest not only in the technology, but in the capacity and skill building of our cybersecurity teams and data analysts,” Tane said. She also recommended the government to implement technological and organizational modernization, as well as work with other countries to formulate a cooperative framework related to cybersecurity.
Ayom Mratita discussed the state of data after a hacking incident. She elaborated on how, after a ransomware attack, attackers not only steal and hold data hostage but also steal the data itself, causing the data to no longer be in the control of the data custodian. Data belonging to victims who had paid the ransom was also found to still exist in LockBit’s systems in some cases, or became scattered due to data sales on some data leak sites (DLS). Ayom described the situation of other Global South countries after hacking incidents, such as Thailand, Brazil, Costa Rica, India, and South Africa. She also expressed her opinion on the positionality of data custodians. Data custodians have the responsibility for the classification, protection, use, and quality of one or many sets of organizational data, as well as being responsible for the accuracy, availability, and security of data, and ensuring compliance with the law.
Ayom explained the measures that can be taken in resolving a cyberattack. These include investigating the source of the cyberattack, reporting the incident, providing a timely and transparent public statement, informing the affected data subjects of the incident, preserving evidence of the incident, and working towards a long-term recovery. Existing digital infrastructure is expected to have backup mechanisms, disaster recovery procedures, and comply with relevant digital laws and regulations, in order to be able to perform in the event of a system failure. She discussed that, referring to regulations related to data and privacy laws, people as data subjects have the right to obtain information, complain, and receive compensation in these cases. “In a cyberattack, ensuring operational recovery is not enough. Data custodians need to ensure and take responsibility for the protection of personal data that was exposed to attack,” Ayom said.
Author : Carmelia Gaby Talia