Fin.SecurTIndonesia 2026
By Invitation · 100 Seats · Jakarta · October 2026
Fin.SecureT
Indonesia 2026

Indonesia's First Exclusively BFSI Cybersecurity Summit

Cyber defense and resilience for Banks, Fintechs, Digital Payments and Insurance of Indonesia — one room, one mandate, no noise.

Scroll
0
Attacks per week on Indonesia
SEA's most attacked economy
0
Attack events recorded in 2025
BSSN national telemetry
0
Growth in deepfake fraud
Indonesian fintech, 2022–2024
0
Days of attacker dwell time
Before detection · 2026 baseline
0
BFSI share of the security market
Largest vertical in Indonesia
01 · The premise

A summit organised around a mandate, not an industry

Fin.SecurT exists because the person accountable for a bank's cyber resilience has almost nowhere to go where the room shares that accountability.

Indonesia hosts more than a dozen cybersecurity events. Every one of them serves a mixed audience — manufacturing, telecoms, healthcare, government and retail sitting alongside financial services. That format cannot make POJK 11/2022, SEOJK 29, BI SNAP or BSSN Regulation 1/2024 the organising principle of a session, because most of the room has no obligation under any of them.

Fin.SecurT can, because every delegate in the room carries the same regulatory exposure, the same board scrutiny and the same 24-hour notification clock. The agenda is not a set of tracks. It is a single sequence of conversations that only make sense between people who file to the same regulator.

Indonesia is the founding chapter of the Fin.SecurT series. The format travels; the audience definition never changes.

02 · Why BFSI only

A bank cannot learn cyber defence in a room built for everyone

Six exposures that exist in financial services and effectively nowhere else. Each one is a session on this agenda.

Payments

Real-time money, real-time fraud

BI-FAST and QRIS removed the reversal window. Across 14.78 million merchant codes, QR substitution and API replay have produced IDR 890 billion in recorded losses — a control problem no other sector runs.

Identity

e-KYC as a security control

Synthetic identity and deepfake onboarding create accounts that are fraudulent from birth. When identity proofing fails, every downstream control inherits the failure.

Interbank

SWIFT and the CSCF baseline

Lazarus-pattern fraudulent instruction against interbank messaging is a financial-sector-specific attack with a financial-sector-specific attestation regime.

Open finance

The mandate to expose APIs

The P2SK Law requires openness. 47+ ITSK operators and 845 partnerships extend the exploitable perimeter past the institution's own boundary — by regulation, not by choice.

Supervision

Compliance with personal consequences

Mandatory independent CISO, annual adversarial simulation filed within 15 business days, soundness-rating impact, and a Cybersecurity Bill introducing criminal liability. No other sector's CISO carries this.

Systemic risk

One vendor, three hundred banks

The C-Edge pattern — a single Jenkins flaw at one supplier taking ~300 banks offline — is why third-party concentration is a financial-stability question, not a procurement one.

03 · The Room Intelligence™

Every seat is allocated. None is sold.

The room is designed before it is filled. One hundred seats, composed across the four BFSI sub-sectors so that the person next to you is a peer with a comparable mandate — not whoever registered first.

ONE ROOM ONE MANDATE · NO NOISE

100 practitioner seats, composed in advance. A further 12 sponsor delegates attend the day and leave the room before the closed-door roundtable.

Vendors leave the roundtableSponsors physically exit before the closed-door CISO session begins. Enforced, not aspirational.
Composed, not filledSeats are allocated across the four BFSI sub-sectors before invitations go out, so the room stays balanced.
Applications are declinedNo students, no resellers, no junior attendance, no booth traffic. Seniority and sector are verified before a seat is confirmed.
04 · Fin.SecurT Intelligence Series

We publish research first, and run a summit second

Three primary research programmes underpin every session on the agenda. Delegates receive all three; the summaries below are public.

Indonesia BFSI Cyber Threat Landscape

Where attacks concentrate

Share of national cyber-attack focus by sector, %
BFSI25%
Government21%
Telecom & tech17%
Healthcare12%
Mfg & energy11%
Education & other15%

Attackers allocate to value: direct monetisation, KYC data density, regulatory clocks that strengthen extortion, and interconnection that propagates a single breach.

QRIS transaction value

USD billions · the rails moved faster than the guards
122022
312023
682024
982025
1152026F

At USD 115 billion in forecast value across 14.78 million merchants, payment fraud stops being an operational line item and becomes macro-economic.

The extortion kill chain — and where it breaks

Six stages, six interception points. The cost of defence rises steeply left to right.

The regulatory multiplier. Encryption starts three clocks at once: OJK notification, PDP Law breach liability, and soundness-rating review. Extortion pressure is now regulatory as much as operational — which is why the crisis plan is a control, not paperwork.

05 · Indonesia Financial Cyber Index 2026

A maturity benchmark your board can read

The Index scores Indonesian BFSI sub-sectors across security maturity, regulatory readiness, third-party exposure, identity controls and detection capability. Full scoring is released to confirmed delegates.

Delegate edition
The Index is not published publicly

Scores are distributed to confirmed delegates and Advisory Council members only, alongside the methodology and the institution-level self-assessment worksheet.

Request the delegate edition
06 · Securing Golden Indonesia 2045

Cybersecurity is not an IT function on this journey. It is national infrastructure.

Golden Indonesia 2045 targets a USD 73 trillion economy and the world's fourth-largest GDP. That ambition rests on a financial system 278 million citizens trust completely — and trust is not built by economists.

Phase 1Stabilisation2019–2025
Complete

Legal and institutional foundation: BSSN CIRT establishment, the OJK enforcement framework, the PDP Law enacted. The infrastructure exists — now it has to perform.

Phase 2Integration2026–2035
Active — you are here

Advanced threat detection across critical sectors, cross-sector intelligence sharing, AI-powered defence and enforcement with real consequences. Not planned. Not piloted. Operational. This is the BFSI CISO's mandate, and it is the reason this summit exists in 2026.

Phase 3Autonomy2036–2045
The prize

Full cyber sovereignty: homegrown cryptography, world-class national capability, Indonesia as a regional cybersecurity leader. Decisions taken in 2026 either enable that or foreclose it.

07 · Advisory Council

Eight seats. The event's guarantee of independence.

Senior Indonesian BFSI security leaders who co-design the agenda, chair the closed-door session, serve as editorial board for the Intelligence Series, and set the award categories and judging framework.

Council seat 01
Photography 4:5
Announcement pendingCommercial banking
Council seat 02
Photography 4:5
Announcement pendingDigital banking
Council seat 03
Photography 4:5
Announcement pendingFintech & payments
Council seat 04
Photography 4:5
Announcement pendingInsurance

Council conversations are being held now, ahead of public delegate invitations. Seats are confirmed in order of conversation, not in order of seniority. Register interest →

08 · Speaker faculty

Curated for institutional balance

Speaker · Photography 4:5
Announcement pendingCISO · Commercial bank
Speaker · Photography 4:5
Announcement pendingHead of Security · Digital bank
Speaker · Photography 4:5
Announcement pendingCISO · Payments
Speaker · Photography 4:5
Announcement pendingHead of InfoSec · Insurance
Speaker · Photography 4:5
Announcement pendingSupervisory perspective
Speaker · Photography 4:5
Announcement pendingRegional threat intelligence
09 · Indonesia BFSI Cyber Excellence Awards

Recognition that cannot be purchased

Ten categories. An independent panel chaired by the Advisory Council. Submissions are judged on evidence of outcome — measured dwell time, tested recovery, programmes that survived supervisory examination.

Submit a nomination Judging criteria

CISO of the Year

Individual leadership across a measurable posture change.

Cyber Resilience Programme

Tested recovery under realistic conditions.

Fraud Defence Innovation

Measured reduction in loss, not deployment of a tool.

Identity Security Excellence

Phishing-resistant MFA and privilege elimination at scale.

Third-Party Risk Leadership

Continuous assessment across a real supplier estate.

Detection & Response Team

Dwell time evidenced against the national baseline.

Four further categories announced with the Advisory Council.

10 · Sponsorship

One hundred qualified buyers, in a room composed in advance.

Fin.SecurT is not a booth. There is no exhibition hall, no badge scanning and no lead list of students. There is a curated room of BFSI decision-makers, and a limited number of ways to be in it.

Tier 01 · One available

Founding Partner

Named alongside the chapter. Category exclusivity guaranteed in writing.

  • Speaking slot on the main stage
  • Category exclusivity across the chapter
  • Logo lockup on the Intelligence Series
  • Curated delegate introductions before the day
  • Awards evening association
  • First refusal on the next Fin.SecurT chapter
Request the prospectus
Tier 02 · Limited

Strategic Partner

A speaking position on the main stage.

  • 20-minute speaking slot
  • Delegate list access under NDA
  • Branded presence across the day
  • Pre-arranged executive meetings
Request the prospectus
Tier 03

Specialist Partner

Presence and access without a stage position.

  • Full-day delegate access for two
  • Branded presence and collateral
  • Pre-arranged executive meetings
  • Post-event delegate insight report
Request the prospectus

Investment levels are shared in the commercial prospectus. The Founding Partner position carries category exclusivity and is allocated in order of conversation.

11 · Participate

Seats are allocated, not registered

Applications are reviewed against seniority, institution type and room composition. Some are declined — that is what makes the room worth sitting in.

Delegate application
Enter your full name.
Enter your job title.
Enter your institution.
Select your institution type.
Enter a valid work email address.
Enter a contact number.
A sentence is enough — it informs table composition.

Reviewed within five business days. Applications from vendors, resellers and consultancies are directed to sponsorship.

Sponsorship enquiry
Enter your company name.
Enter your country.
Select a category.
Enter a contact name.
Enter a valid work email address.
Tell us what success looks like.

Category exclusivity is allocated in order of conversation. Once a category is locked it is not reopened.

12 · Questions

Before you apply

Is there a delegate fee?

No. Qualified BFSI delegate seats are complimentary and allocated by application. The summit is funded by a small number of category sponsors.

I work for a technology vendor. Can I attend as a delegate?

No. Vendor, reseller and consultancy attendance is available only through sponsorship, and sponsors leave the room before the closed-door roundtable. This rule is what the delegates are there for.

Why only 100 seats?

Above roughly one hundred people, a room stops being a conversation and becomes an audience. The Chatham House session does not work at conference scale.

Is the roundtable recorded?

No recording, no attribution, no write-up. Nothing said in that session leaves it attributed to a person or an institution.

Who decides the agenda?

The Advisory Council — eight serving Indonesian BFSI security leaders. ACCELETECH produces the event; the Council determines what is discussed.

Will Fin.SecurT run outside Indonesia?

Indonesia is the founding chapter. Further chapters are planned across Singapore, Malaysia, Thailand, Vietnam, the Philippines, India and the UAE, with the same format and the same audience definition.