- 28/03/2023
- Category: Report Breakdown
Author: M. Irfan Dwi Putra
Editor: M Perdana Karim
Cybersecurity and Its Importance
The digital age creates new types of crimes that arise along with the rapid growth of the internet, called cybercrimes. Cybercrimes are criminal activity that either uses information technology as a tool (cyber-enabled crime) or targets technology information (cyber-dependent crime) as its object. Examples of cyber-enabled crimes are fraud, defamation, and sexual harassment, which are committed online, while examples of cyber-dependent crimes are malware, phishing, and hacking (Brunhöber, 2022).
Both cyber-enabled crime and cyber-dependent crime bring harm to internet users, especially when it comes to users’ personal data and digital economy activities. They are as threatening as ordinary crimes in the real world, so they must be prevented and controlled in a serious manner. Cybersecurity is one of the instruments that can be used to ensure the people involved in digital activity’s safety. The stronger cybersecurity a state develops, the more secure it is for people involved in the digital space, and it will create a safe digital environment and vice versa. Then, how about Indonesia’s cybersecurity?
Cybersecurity in Indonesia
On the newest report from National Cyber Security Index (NCSI), Indonesia’s cybersecurity index ranked 84th with 38,96 points. NCSI uses 12 indicators in this report, including cybersecurity policy development, personal data protection, and the fight against cybercrimes. The report shows that Indonesia’s cybersecurity index is relatively low compared to other countries. Among the G20 member countries, Indonesia ranked the third lowest, only higher than Mexico and South Africa. The NCSI report is justifiable if we consider some particular facts in Indonesia. According to the Public Monthly Report on Cybersecurity Monitoring Result of August 2022 issued by the National Cyber and Crypto Agency (NCCA), 44.776.891 traffic anomalies occurred in Indonesia throughout August 2022. A traffic anomaly is a deviation from the normal anomaly that indicates cyber attacks (Huo, et al., 2019). From the number above, traffic anomaly classification and its number are presented in the table below.
| Anomaly Type | Total |
| Malware | 24.448.343 |
| Trojan Activity | 8.362.317 |
| Information Leak | 7.084.332 |
| Exploit | 1.644.543 |
| APT | 387.307 |
| Web Application Attack | 343.510 |
| Information Gathering | 177.510 |
| Denial of Service | 50.115 |
| Others | 2.278.914 |
In addition to the high traffic anomalies, the NCCA report also shows email phishing case amount in Indonesia during August 2022. Email phishing is an act to obtain personal information such as user ID, password, and other sensitive information by impersonating other people or authorized organizations. If the perpetrators successfully obtain it, they will use that information to conduct criminal acts. According to the report, 6.342 email phishing cases happened in August 2022. Most of them were attaching documents with a .pdf extension. They usually used cybersecurity-related information, payment, invoice, and other information as their email subject.
Last but not least, the report also writes about website hacking cases in Indonesia. In August 2022, there were 148 sites hacked by trespassers. The websites they hacked varied from government, law officers, to educational sites. The most frequent website hacking cases are local government sites with 62 cases, followed by educational sites with 54 cases, then law officers sites with 19 cases, and other sites. The high traffic anomalies, email phishing, and website hacking explained above show us that Indonesia’s cybersecurity system is still inadequate to deal with cyber attacks that harm people and national security.
There are several factors behind inadequate Indonesia’s cybersecurity system. First, the existing regulations are still insufficient to regulate cyberspace activities. To date, Indonesia has only two acts that regulate cyber activities, i.e., Law No. 11 of 2008 on Information and Electronic Transactions as amended by Law No. 19 of 2016 (EIT Law) and Law No. 27 of 2022 on Personal Data Protection (PDP Law). Although they already have some technical derivative regulations, the two acts are inadequate to regulate cyber activities in Indonesia. Cybercrimes always evolve along with the rapid growth of the internet, so it is impossible to handle them by EIT Law and PDP Law only. Indonesia needs specific laws to regulate cyber activities and cybercrimes.
Second, Indonesia still lacks supporting information technology infrastructure. The Fourth Industrial Revolution requires society’s readiness to deal with the rapidly growing information technology; it requires an adequate information technology infrastructure. Unfortunately, the government is still focusing on physical infrastructure instead of developing information technology infrastructure (Sembiring, 2022). It is shown by the unequal distribution of information technology infrastructure in cities and rural areas.
Third, Indonesia’s digital literacy index is still relatively low. The newest report from the Directorate General for Telematics Application on Digital Literacy Index 2021 shows Indonesia’s digital literacy index scores of 3.49. However, if we observe closely, Digital Safety–one of its indicators–falls from 3,24 to 3,10. Those three things explained earlier indicate that Indonesia’s cybersecurity is still relatively low.
Recommendation
Several actions need to be taken to deal with Indonesia’s cybersecurity problems. These actions should involve all related stakeholders, such as society, electronic system operators, and the government. As internet users, we shall improve our digital skills. Some actions we can take are to be more cautious in surfing the internet, filter information by checking and re-checking the information before sharing it and protect our passwords and other sensitive information. Then, the electronic system operators, as parties who hold users’ data, shall strengthen their cybersecurity systems. This aims to prevent data hacking by trespassers.
On the other hand, the government as regulator shall guarantee user safety by establishing laws that specifically regulate cybercrimes. This aims to legally punish perpetrators who commit cybercrime, so it will guarantee legal certainty. In order to strengthen cybersecurity, all stakeholders shall work together by carrying out their responsibilities. Thus, cyberspace will be a safe place for all.
Reference
Annur, C.M. (2022) Indeks Keamanan Siber Indonesia Peringkat ke-3 Terendah di Antara Negara G20. Available at: https://databoks.katadata.co.id/datapublish/2022/09/13/indeks-keamanan-siber-indonesia-peringkat-ke-3-terendah-di-antara-negara-g20 (Accessed 30 November 2022).
Badan Siber dan Sandi Nasional (2022) Laporan Bulanan Publik Hasil Monitoring Keamanan Siber Agustus 2022. Available at: https://cloud.bssn.go.id/s/HoFJzyeFASPqawL (Accessed 30 November 2022).
Brunhöber, B. (2022) ‘Criminal Law of Global Digitality: Characteristics and Critique of Cybercrime Law’, in Kettenmann, M.C., Peukert, A. dan gen Dohmann, I.S. (ed.) The Law of Global Digitality. New York: Routledge, 2022.
Direktorat Jenderal Aplikasi Telematika (2021) Status Literasi Digital di Indonesia 2021. Available at: https://cdn1.katadata.co.id/media/microsites/litdik/Status_Literasi_Digital_diIndonesia%20_2021_190122.pdf (Accessed 30 November 2022).
Huo, X., et al. (2019) ‘Research on Network Traffic Anomaly Detection of Source-Network-Load Industrial Control System Based on GRUOCSVM’, IOP Conference Series: Earth and Environmental Science, 300, pp. 1-7.
National Cyber Security Index (2022) Indonesia. Available at: https://ncsi.ega.ee/country/id/ (Accessed 30 November 2022).Sembiring, M.P. (2022) ‘Penurunan Daya Saing Global Indonesia: Pembangunan Infrastruktur Yang Kurang Adaptif Terhadap Perkembangan Isu Cybercrime”, Journal of International Relations, 8(4), pp. 895-909.