Cyber defense and resilience for Banks, Fintechs, Digital Payments and Insurance of Indonesia — one room, one mandate, no noise.
Fin.SecurT exists because the person accountable for a bank's cyber resilience has almost nowhere to go where the room shares that accountability.
Indonesia hosts more than a dozen cybersecurity events. Every one of them serves a mixed audience — manufacturing, telecoms, healthcare, government and retail sitting alongside financial services. That format cannot make POJK 11/2022, SEOJK 29, BI SNAP or BSSN Regulation 1/2024 the organising principle of a session, because most of the room has no obligation under any of them.
Fin.SecurT can, because every delegate in the room carries the same regulatory exposure, the same board scrutiny and the same 24-hour notification clock. The agenda is not a set of tracks. It is a single sequence of conversations that only make sense between people who file to the same regulator.
Indonesia is the founding chapter of the Fin.SecurT series. The format travels; the audience definition never changes.
Six exposures that exist in financial services and effectively nowhere else. Each one is a session on this agenda.
BI-FAST and QRIS removed the reversal window. Across 14.78 million merchant codes, QR substitution and API replay have produced IDR 890 billion in recorded losses — a control problem no other sector runs.
Synthetic identity and deepfake onboarding create accounts that are fraudulent from birth. When identity proofing fails, every downstream control inherits the failure.
Lazarus-pattern fraudulent instruction against interbank messaging is a financial-sector-specific attack with a financial-sector-specific attestation regime.
The P2SK Law requires openness. 47+ ITSK operators and 845 partnerships extend the exploitable perimeter past the institution's own boundary — by regulation, not by choice.
Mandatory independent CISO, annual adversarial simulation filed within 15 business days, soundness-rating impact, and a Cybersecurity Bill introducing criminal liability. No other sector's CISO carries this.
The C-Edge pattern — a single Jenkins flaw at one supplier taking ~300 banks offline — is why third-party concentration is a financial-stability question, not a procurement one.
The room is designed before it is filled. One hundred seats, composed across the four BFSI sub-sectors so that the person next to you is a peer with a comparable mandate — not whoever registered first.
100 practitioner seats, composed in advance. A further 12 sponsor delegates attend the day and leave the room before the closed-door roundtable.
Three primary research programmes underpin every session on the agenda. Delegates receive all three; the summaries below are public.
Attackers allocate to value: direct monetisation, KYC data density, regulatory clocks that strengthen extortion, and interconnection that propagates a single breach.
At USD 115 billion in forecast value across 14.78 million merchants, payment fraud stops being an operational line item and becomes macro-economic.
Six stages, six interception points. The cost of defence rises steeply left to right.
The regulatory multiplier. Encryption starts three clocks at once: OJK notification, PDP Law breach liability, and soundness-rating review. Extortion pressure is now regulatory as much as operational — which is why the crisis plan is a control, not paperwork.
The Index scores Indonesian BFSI sub-sectors across security maturity, regulatory readiness, third-party exposure, identity controls and detection capability. Full scoring is released to confirmed delegates.
Scores are distributed to confirmed delegates and Advisory Council members only, alongside the methodology and the institution-level self-assessment worksheet.
Request the delegate editionGolden Indonesia 2045 targets a USD 73 trillion economy and the world's fourth-largest GDP. That ambition rests on a financial system 278 million citizens trust completely — and trust is not built by economists.
Legal and institutional foundation: BSSN CIRT establishment, the OJK enforcement framework, the PDP Law enacted. The infrastructure exists — now it has to perform.
Advanced threat detection across critical sectors, cross-sector intelligence sharing, AI-powered defence and enforcement with real consequences. Not planned. Not piloted. Operational. This is the BFSI CISO's mandate, and it is the reason this summit exists in 2026.
Full cyber sovereignty: homegrown cryptography, world-class national capability, Indonesia as a regional cybersecurity leader. Decisions taken in 2026 either enable that or foreclose it.
Senior Indonesian BFSI security leaders who co-design the agenda, chair the closed-door session, serve as editorial board for the Intelligence Series, and set the award categories and judging framework.
Council conversations are being held now, ahead of public delegate invitations. Seats are confirmed in order of conversation, not in order of seniority. Register interest →
Ten categories. An independent panel chaired by the Advisory Council. Submissions are judged on evidence of outcome — measured dwell time, tested recovery, programmes that survived supervisory examination.
Individual leadership across a measurable posture change.
Tested recovery under realistic conditions.
Measured reduction in loss, not deployment of a tool.
Phishing-resistant MFA and privilege elimination at scale.
Continuous assessment across a real supplier estate.
Dwell time evidenced against the national baseline.
Four further categories announced with the Advisory Council.
Fin.SecurT is not a booth. There is no exhibition hall, no badge scanning and no lead list of students. There is a curated room of BFSI decision-makers, and a limited number of ways to be in it.
Named alongside the chapter. Category exclusivity guaranteed in writing.
A speaking position on the main stage.
Presence and access without a stage position.
Investment levels are shared in the commercial prospectus. The Founding Partner position carries category exclusivity and is allocated in order of conversation.
Applications are reviewed against seniority, institution type and room composition. Some are declined — that is what makes the room worth sitting in.
No. Qualified BFSI delegate seats are complimentary and allocated by application. The summit is funded by a small number of category sponsors.
No. Vendor, reseller and consultancy attendance is available only through sponsorship, and sponsors leave the room before the closed-door roundtable. This rule is what the delegates are there for.
Above roughly one hundred people, a room stops being a conversation and becomes an audience. The Chatham House session does not work at conference scale.
No recording, no attribution, no write-up. Nothing said in that session leaves it attributed to a person or an institution.
The Advisory Council — eight serving Indonesian BFSI security leaders. ACCELETECH produces the event; the Council determines what is discussed.
Indonesia is the founding chapter. Further chapters are planned across Singapore, Malaysia, Thailand, Vietnam, the Philippines, India and the UAE, with the same format and the same audience definition.