- 15/08/2024
- Category: Commentaries
The cyberattack on the Temporary National Data Center in June revealed at least two critical lessons for cybersecurity in Indonesia. First, despite the rapid development and widespread use of technology in all aspects of life, the government still lacks a robust digital system to ensure data security and the continuity of public services.
As a result, the ransomware attack by the Brain Chiper hacking group impacted 239 government agencies, including ministries and municipal governments, which lacked backup data. This attack even paralyzed nearly all airport immigration services in Indonesia for almost 100 hours and disrupted school enrollments in several cities.
Second, Indonesia’s government lacks responsiveness and effectiveness in addressing swift and sudden cyberattacks. This is evident in the Ministry of Communications and the National Cyber and Encryption Agency (BSSN) passing the blame regarding the lack of backup data at the National Data Center.
This issue arises because these two institutions have overlapping duties and responsibilities with unclear boundaries. Consequently, when a crisis occurs, the standard operations of these institutions fail to answer fundamental questions: Who should respond? And what response should be given?
Uncovering the Dual Responsibilities of the Cyber Agency and Ministry of Communications
The National Cyber and Encryption Agency was established in 2017 under President Joko Widodo’s leadership, based on Presidential Regulation No. 53 of 2017. It is a merger of the State Encryption Agency, the Directorate of Information Security, and the Directorate General of Informatics Applications under the ministry. Meanwhile, the Ministry of Communications and Informatics was established under Presidential Regulation No. 54 of 2015, later replaced by Presidential Regulation No. 22 of 2023.
Three fundamental points—status, duties, and functions—are key to understanding the differences in responsibilities between these two agencies, as shown in Table 1 below.
Table 1. Differences in Responsibilities Between the Ministry and the National Cyber Agency

Based on the table above, the main difference between the Ministry and the Cyber Agency lies in the scale and scope of their responsibilities. The Ministry is responsible for government affairs in the broader field of communication and informatics, including public communication, while the Cyber Agency focuses on cybersecurity and state encryption. The Cyber Agency also has a specific duty to formulate norms, standards, procedures, and criteria in the field of cybersecurity.
Another important point is that both institutions report directly to the President. This means the Cyber Agency is not required to report to or be accountable to the Ministry, even though it was formed from the merger of two directorates previously under the Ministry.
Regarding the management of data centers, Presidential Regulation No. 95 of 2018, Article 27 Paragraph (5), states that data center management is under the Ministry of Communications and Informatics. This means that the Ministry should have been responsible and played a more strategic role in responding to the cybersecurity failure at the data center a few months ago, rather than the Cyber Agency.
However, beyond merely assigning blame, this case serves as a lesson for both institutions to build stronger coordination and cooperation to prevent similar incidents in the future.
Considering their status, duties, functions, and responsibilities in data management, this analysis outlines four main implications when the country faces a cyberattack. First, the Ministry must lead the response to an attack, including identifying the source of the attack, addressing the damage, and restoring affected systems, as the data center management is legally under the Ministry. Second, the Cyber Agency can provide resources to the Ministry to contain the spread of the attack. Third, the Ministry must ensure communication and coordination between the government and the public, even during communication infrastructure disruptions. Lastly, collaboration between the two institutions is crucial because security and communication are inseparable.
Examining the Budget and Performance of the Ministry and the Cyber Agency
The ransomware attack on the National Data Center also raises the issue of budget adequacy for digital infrastructure and cybersecurity in Indonesia. This issue was highlighted by Minister Budi Arie, who attributed the lack of backup data to budget constraints. However, this claim was refuted by Minister Sri Mulyani, who noted that the Ministry of Communications and Informatics had a significant budget, with Rp700 billion allocated for Data Center maintenance. This amount is more than three times the budget allocated by Malaysia to develop its Cybersecurity Testing Framework for 2024, which is around Rp215 billion.
Diagram 1. Budget Comparison Between the Ministry and Cyber Agency
Source: Ministry of Finance (Financial Notes)
Although the Ministry of Communications and Informatics’ budget over the past seven years has fluctuated, as seen in Diagram 1, the Ministry’s spending has generally increased. In contrast, the Cyber Agency’s budget has decreased in recent years.
Nevertheless, increasing the budget for a ministry or agency cannot automatically be linked to improved communication, informatics services, and national cybersecurity quality. This is evident in 2022 and 2023, when the combined budget of the two institutions reached over Rp20 trillion. Yet, the Cyber Agency reported more than 1 million ransomware activities in 2023. Moreover, throughout 2022, there were at least seven major data breaches, such as the Bjorka case, data breaches from Bank Indonesia, PT Pertamina Training and Consulting, and the State Electricity Company. These incidents strongly indicate that a substantial budget alone will not directly resolve the ongoing crisis.
Therefore, ministries and agencies may consider the following holistic and integrated approaches. First, the Ministry should invest in training and capacity development for workers in the cybersecurity field. This is necessary to ensure that organizations are staffed by experienced and knowledgeable individuals.
Second, the government should consider establishing a risk management framework, as data centers integrate many government services into a single system. Given that data centers are vulnerable to various threats, such as power supply disruptions, natural disasters, and hacker attacks, the existence of a Data Recovery Center (DRC) is crucial. Third, the government must ensure the availability of a disaster recovery plan policy as a rapid response protocol to cyberattacks, while also implementing strict cybersecurity policies through regular audits, monitoring, and compliance by relevant agencies.
Last but not least, the government should strengthen and maintain interagency cooperation between the public and private sectors. This collaboration aims to enhance the detection and mitigation capabilities of cyberattacks more comprehensively. These strategies can serve as alternatives for ministries and agencies to strengthen cybersecurity and digital resilience in Indonesia, rather than merely focusing on demands for increased organizational budgets.
Author: Achmad Hanif Imaduddin
Editor: Iradat Wirid