Indonesian Political, Business & Finance News

Discussion of Cybersecurity Bill Urged to Be More Participatory

| | Source: REPUBLIKA Translated from Indonesian | Regulation
Discussion of Cybersecurity Bill Urged to Be More Participatory
Image: REPUBLIKA

The Cyber Agency of the Central Board of the Ansor Youth Movement (GP Ansor) is urging that the discussion of the Cybersecurity and Resilience Bill be conducted in a more open and participatory manner. The organisation, under the auspices of Nahdlatul Ulama, hopes that the House of Representatives (DPR RI) and the government will provide access to the draft bill so that the public can offer input before the regulation is enacted.

Head of the GP Ansor Central Board Cyber Agency, Ahmad Luthfi, stated that the Cybersecurity and Resilience Bill is a strategic regulation that will serve as the foundation for national cybersecurity governance. He believes the drafting process will be stronger if it involves various stakeholders.

“The Cybersecurity and Resilience Bill will become the legal foundation for Indonesia’s digital ecosystem in the long term. Transparency is a primary requirement to produce a regulation that is high-quality, legitimate, and capable of addressing national cybersecurity challenges,” Ahmad Luthfi said in a written statement in Jakarta on Tuesday (30/6/2026).

According to Ahmad, cybersecurity is no longer solely related to state defence but also touches the daily lives of citizens. Therefore, drafting regulations in this field needs to involve academics, cybersecurity practitioners, digital industry players, civil society organisations, technology communities, and professional associations.

GP Ansor believes that public involvement can enrich the substance of the bill, especially amid the rise of various cyber threats such as personal data leaks, ransomware attacks on public services and the financial sector, digital fraud, phishing, identity theft, account takeovers, and the misuse of artificial intelligence technologies like deepfakes and voice cloning.

Ahmad stated that the regulation being drafted is expected not only to strengthen the national security system but also to provide optimal protection for the public as users of the digital space.

Beyond highlighting the drafting process, GP Ansor also submitted several inputs on the substance of the bill. These include strengthening national cybersecurity governance through inter-agency coordination and the implementation of more effective security standards.

The organisation also proposed regulating digital supply chain security standards, considering that cyberattacks often exploit gaps in vendors or service providers to penetrate larger systems.

Additionally, GP Ansor proposed a mandatory incident reporting obligation with a clear deadline so that the public can promptly receive information in the event of a data breach or system disruption affecting public interests.

GP Ansor is also pushing for the bill to provide more comprehensive protection for victims of cybercrime, including mechanisms for digital identity recovery as well as legal and technical assistance.

In terms of strengthening the security system, the organisation proposed the implementation of a risk-based national cybersecurity framework, allowing security standards to be tailored to the characteristics of each sector, from MSMEs and technology companies to financial institutions, hospitals, and operators of vital information infrastructure.

Furthermore, cybersecurity literacy is deemed necessary as part of the national strategy because most cyberattacks still exploit human weaknesses through social engineering techniques, phishing, online fraud, and the misuse of OTP codes.

GP Ansor also holds the view that the regulation needs to anticipate technological developments, including threats arising from the use of artificial intelligence such as deepfakes, voice cloning, synthetic identities, and various forms of AI-based attacks.

As a reference, GP Ansor encourages the drafting of the bill to adopt best practices from several countries, such as Singapore, the European Union through the NIS2 regulation, Australia, and the United States in strengthening collaboration between the government and the private sector.

“Indonesia must not only pursue the existence of a law but also ensure that the law is capable of protecting the public, strengthening national resilience, and being adaptive to the development of global cyber threats. Good regulation is born from a process that is open, participatory, and based on public interest,” said Ahmad.

On that basis, GP Ansor hopes that the DPR RI and the government can open public access to the draft Cybersecurity and Resilience Bill, expand the space for public consultation, and ensure that the enacted regulation is capable of strengthening public protection as well as national cyber resilience.

View JSON | Print