BSSN urges system owners to implement Proactive Security and Lesson Learned.
Spokesman for the National Cyber and Crypto Agency (BSSN) Ariandi Putra stated that BSSN was investigating allegations of data leakage from PLN and IndiHome service users of PT Telkom Indonesia.
BSSN conducts data analysis on criminal actors and provides notifications to relevant stakeholders.
"Initial data shows that criminal actors (threat actors) provided data samples containing browsing history, email, username, gender, NIK, and user location," said BSSN spokesman Ariandi Putra quoting Republika.co.id, Monday ( 22/8/2022).
Ariandi added that the results of the analysis needed to be investigated and verified more deeply. Meanwhile, for the alleged leak of PLN customer data, BSSN has coordinated with PT PLN.
BSSN has also sent an incident response team or Computer Security Incident Response Team (CSIRT) to carry out investigation, analysis, and mitigation tasks regarding cyber incidents that occurred.
BSSN reminds electronic system operators to be responsible for their security and reliability in accordance with the mandate of PP No. 71 of 2019 concerning the Implementation of Electronic Systems and Transactions (PP PSTE). This is after the widespread data leakage of users of the electronic provider system service.
He asked that every electronic system operator must implement information security standards in the operation of electronic systems. BSSN also urges system owners to take two preventive steps so that data leakage incidents do not recur.
"In response to the large number of data leaks, BSSN urges system owners to take two preventive steps so that data leakage incidents do not recur, namely the implementation of Proactive Security and Lesson Learned," said Ariandi.
Proactive Security is an early detection system with continuous and automatic monitoring. This system can proactively detect indications of incidents early on and provide warnings to the relevant team as both the system owner and the cyber incident response team.
Lesson Learned, namely the step of sharing knowledge by sharing learning information. He explained, the data leak incident and its management is expected to be a lesson in effective incident management.




