AI4INDONESIA
Security

BSSN Urges Data Centres to Form CSIRTs and Adopt Post-Quantum Crypto

September 22, 2026 · 6 min read · Security

BSSN Urges Data Centres to Form CSIRTs and Adopt Post-Quantum Crypto

Indonesia’s National Cyber and Crypto Agency pressed data-centre operators to harden cyber defences and prepare for post-quantum cryptography, BSSN director Nur Achmadi Salmawan said at the Indonesia Energy & Engineering seminar in Jakarta on September 2, 2026. He argued that physical power and cooling are no longer enough: under Presidential Regulation 82/2022, data centres sit at the centre of national risk because public and digital-economy services ride on their networks. Operators were told to form Computer Security Incident Response Teams with clear mandates, 24/7 contact channels, escalation playbooks and regular cyber drills.

Filed under Security and dated September 22, 2026, this AI4Indonesia briefing treats the BSSN agenda as Indonesian AI-infrastructure security news distinct from CAEXPO partnership theatre. SOC figures cited for 2025 included millions of traffic anomalies and ransomware attentions plus tens of millions of darknet-exposed records hitting hundreds of government agencies, while roughly a quarter of BSSN early-warning notices reportedly went unanswered. Salmawan also flagged “harvest now, decrypt later” quantum risk for 2026–2030 and urged crypto-agility away from brittle RSA/ECC dependencies—especially as AI workloads concentrate valuable corpora inside the same halls.

Why it matters: Indonesian AI factories and clouds inherit every unpatched rack. CSIRTs and PQC roadmaps can cut cascading outages—but only if drills and algorithm swaps are funded.

What it means in practice

BSSN Urges Data Centres to Form CSIRTs and Adopt Post-Quantum Crypto — contextual photo

Indonesian DC and AI platform leads should name a CSIRT owner this quarter; inventory cryptographic dependencies; assign a budget line for PQC pilots; run time-boxed incident simulations tied to PDNS lessons; and prefer vendors that accept BSSN coordination channels. Anchor the push to ethics-and-safety Perpres review and Zankore AI factory capacity.

Caveats come first. Speeches are not inspections; PQC standards still evolve; and ignored alerts show culture gaps. AI4Indonesia therefore presents BSSN’s September message as directional security context until published compliance deadlines appear.

What to watch next: mandatory CSIRT rules for critical facilities; PQC pilot RFPs; and AI ethics enforcement that pairs with crypto controls. Readers can continue on the AI4Indonesia homepage, or browse the Newsroom for additional briefings.

Bottom line: treat this update as orientation, not instruction. Indonesian AI growth is colliding with cyber and quantum readiness gaps and remains unfinished. Organizations that benefit most will staff response teams, keep humans on escalation, and refuse to confuse a keynote with finished resilience.

← Back to AI4Indonesia