Earlier, phishing drills and incident simulations were just a box to tick on the IT checklist. For Indonesia’s Financial Services Authority (OJK), they are now closer to a test of financial sector stability. In practice, this means licensed institutions can no longer get by with one training a year and a folder of certificates kept safely somewhere. OJK wants institutions to demonstrate their ability to safeguard the digital products and consumer information they handle, and training is the means.
When you talk about OJK cybersecurity training, you’re not talking about a few slides and an annual webinar. The bar also covers how companies plan new services, how they react when something goes wrong, and how ready their staff and front-line employees are.
Table of Contents
ToggleWhy Cybersecurity Training Matters Under OJK
The Financial Services Authority has made it clear that cybersecurity is now an integral part of financial stability and consumer protection. OJK emphasizes the role of training and awareness in its guidelines for Financial Sector Technology Innovation (FSTI) and digital financial asset trading businesses, as one of the strategic pillars of cyber resilience, alongside data protection, risk management, and incident response.
These guidelines sit alongside OJK’s broader regulatory framework for the sector: POJK No. 3/2024 on the Implementation of Financial Sector Technology Innovation (FSTI) and POJK No. 27/2024 on the Implementation of Digital Financial Asset Trading, Including Crypto Assets, as amended by POJK No. 23/2025.
In reality, this means OJK cybersecurity training is not just another internal policy. It’s an important aspect of how institutions demonstrate they’re aware of their risks, manage them, and safeguard customers’ data and assets in a rapidly changing technology landscape.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
What OJK Cybersecurity Training Actually Covers
“OJK cybersecurity training” isn’t one fixed rulebook. It’s a set of expectations that differ across provider types but share common themes. Across both guidelines, OJK highlights at least four key dimensions of training and awareness:
1. Continuous Training, Not One‑Off Sessions
Training and awareness are expected to be ongoing, rather than an annual seminar or workshop that everyone attends once and forgets by the next quarter. In the digital asset trading guideline, for instance, the development of technical expertise is described as an ongoing process that includes intensive training and incident simulations.
2. Role‑Based and Competency‑Focused Content
OJK does not establish one curriculum but expects competencies to be built around roles. The digital asset trading guideline advises obtaining professional certifications to improve operational readiness.
In practice:
- More technical training should be provided to staff who are involved in designing and managing systems.
- Risk and compliance teams should know about cyber risk management frameworks such as ISO or national references.
- Awareness training should be provided for frontline staff, the people actually facing phishing, fraud, and operational abuse attempts day to day.
3. Integration With Cyber Risk Management and Incident Response
OJK repeatedly associates training and awareness with cyber risk management and incident response capabilities. It is part of a process of how institutions
- Know how to identify and evaluate cyber risks, following accepted frameworks.
- Ensure all employees are trained to identify and respond to incidents promptly.
- Ensure information sharing and coordination for significant events.
For example, the digital asset trading guideline has incident response plans, including coordination of reporting to OJK and relevant stakeholders, supported by technical competence and training. For example, the digital asset trading guideline has incident response plans, including coordination of reporting to OJK and relevant stakeholders, supported by technical competence and training. FSTI providers are also expected to adopt proactive and reactive approaches, with staff knowing their roles. FSTI providers are also expected to use proactive and reactive approaches, depending on staff knowing their roles.
4. Collaboration and Information Sharing
OJK also wants institutions to collaborate across the financial ecosystem, and training feeds directly into that. It’s the employees who know what to look for that report suspicious activity, participate in exercises, and help create a safer digital environment for everyone.
OJK cybersecurity training is not only about technical aspects but also about building a culture where employees are responsible for reporting suspicious activities, participating in exercises, and learning from incidents.
What This Means for FSTI and Digital Asset Providers
These guidelines apply specifically to entities licensed as FSTI providers or DFA/crypto trading organizers. Banks, insurers, and other traditional financial institutions are subject to separate, existing OJK IT risk management regulations. The direction is the same everywhere, but for these providers it comes down to four things:
- Documented cyber training programs: Institutions should have a documented training plan that outlines goals and training topics, not something that lives in someone’s head**.
- Evidence of implementation: Training assessments and outcomes should be recorded, traceable, and demonstrable to OJK.
- Linking training to risks and controls: Training programs should be directly connected to risks and incident response controls.
- Emphasis on certifications: For technical roles, professional development through courses and recognition through certification to international standards are encouraged.
How Organizations Can Align With OJK Cybersecurity Training
- Identify teams based on OJK references and internal risk assessment that need technical training and risk and governance training.
- Coordinate a comprehensive schedule of employee awareness sessions, technical training, and incident simulations, and repeat regularly.
- Keep track of all employees’ participation and activities. Also, track the handling of incident capabilities, which align with OJK’s focus on maturity and resilience.
How Threatcop Can Support OJK‑Aligned Training
OJK provides direction, but doing this manually across a few hundred or a few thousand employees is usually where programs fall apart. Institutions need platforms that can run continuous, incident-oriented awareness at scale, and this is where Threatcop fits into existing cybersecurity programs.
- TSAT (Threatcop Security Awareness Training) enables consistent security awareness and phishing campaigns through email, SMS, messaging apps, QR codes, and voice calls. This aligns with OJK’s expectations for continuous, realistic learning rather than one-off awareness campaigns.
- Threatcop’s Learning Management System (TLMS) enables institutions to organize cybersecurity content, assign courses to roles, and track completion, providing the documentation and evidence that OJK will expect for training activities.
- TPIR (Threatcop Phishing Incident Response) provides a simple method for employees to report suspicious emails. Reports are quickly analyzed and resolved, reinforcing the link between training and incident response.
- TDMARC is an additional layer of protection that increases email authentication and domain protection against spoofed messages and brand impersonation aimed at employees and customers.
The Bottom Line
OJK’s guidelines on cybersecurity training are very clear: human competence is not an optional component of financial resilience; it is central to it. OJK cybersecurity training needs to be ongoing and completely aligned with the way institutions address cyber risk.
Occasional training sessions are no longer enough. Regulators expect cybersecurity awareness to be part of everyday operations. Platforms like Threatcop make it easier for organizations to align their cybersecurity awareness efforts with OJK’s expectations.
FAQs
Does OJK require specific cybersecurity courses or certifications?
OJK does not specify the requirements for technical positions, but continuous training and professional development are encouraged, especially for positions in FSTI and digital asset trading operations.
Is cybersecurity training compulsory for all employees in the OJK guidelines?
OJK expects that all staff complete training and awareness, with the depth based on staff function. Technical staff need more sophisticated training, and frontline and support staff need more specific awareness training regarding their cyber and fraud risk exposure.
How does OJK link cybersecurity training to incident response?
The OJK guidelines explicitly link training, awareness, and incident simulations to incident response plans and cyber maturity assessments. The response of staff members in the event of an incident and their participation in coordinated reporting to OJK.

Purva is a Technical Content Strategist at Threatcop with an MBA in Business Analytics, specializing in SEO-driven content and technical editing across IT and digital domains, and is the author of the book From a Daughter’s Eye.
