Indonesia’s National Data Center Hit by Cyberattack: Here’s What Your Business Needs to Prepare

Recently, the National Data Center (NDC) server has experienced disruptions causing several public services such as immigration and others to be inaccessible to the public as usual. The Indonesians Ministry of Communication and Informatics confirmed that the disruption was caused by a ransomware attack. 

According to kompas.com, the type of ransomware targeting PDNS is the latest variant, LockBit 3.0 Brain Chipper. This ransomware is more aggressive because it uses AES and RSA encryption to lock files, making them only accessible to the attackers. 

In addition to encryption, LockBit 3.0 also extracts all sensitive files or data to threaten victims with publication if the ransom is not paid, thus creating dual pressure to force payment. 

So, what exactly is the National Data Center (NDC) and why is NDC vulnerable to ransomware attacks, and what lessons can your business learn to be vigilant against similar attacks? Read more in the following article. 

What is a National Data Center (NDC)? 

The National Data Center (NDC) is a facility used to host, store, process, and recover data. The data stored in NDCs are used by both central and local governments to connect with each other, ensuring that various public services run smoothly and efficiently. 

NDCs store critical information for Indonesian citizens, such as ID numbers, bank account numbers, phone numbers, and more. Given the importance of this data, maintaining its confidentiality and security is crucial. 

What is Happening to the National Data Center Now?

 

Indonesia’s National Data Center (NDC) is currently under public scrutiny due to a cyberattack that caused services to be down for several days. Hackers managed to breach the NDC servers and demanded a ransom of US$8 million (approximately Rp130 billion) from the Indonesian government. 

The National Cyber and Encryption Agency (BSSN) detailed the chronology of this breach. According to a preliminary forensic analysis, the attack started on June 17, 2024, at 11:15 PM, with an attempt to disable the internal security system of the PDN. This allowed malicious activities to go undetected. 

As a result of this attack, the National Data Center’s (NDC) servers were disrupted, affecting more than 200 central and regional agencies in Indonesia. The attack also caused personal data breaches, including citizen ID numbers. 

Why is the National Data Center Vulnerable to Cyberattacks?

The vulnerability of the Temporary National Data Center (PDNS) to cyber-attacks is caused by several factors such as: 

1. Lack of Strong Security Governance

According to the BSSN, security governance is essential for helping businesses conduct thorough risk analysis, including security breach scenarios, potential actors involved, the probability of occurrences, and their impacts. Without comprehensive risk analysis, organizations cannot prepare for various threats. 

2. Absence of an Effective Security Plan

According to the National Cyber Security Centre (NCSC), every organization needs an effective security plan to detect, defend against, and respond to cyber-attacks. Without a good security plan, organizations will struggle to quickly detect attacks and will lack structured emergency response or recovery procedures. This results in slow and ineffective responses to incidents. 

3. Lack of Disaster Recovery and Business Continuity Plans

According to BSSN, many institutions, both governmental and private, do not have clear hacking scenarios and are unprepared with disaster recovery or business continuity plans. When an attack occurs, they often panic and lack structured steps to address the issue. 

4. Insufficient Cyber Risk Assessment 

According to BSSN many organizations in Indonesia, including PDNS, do not conduct adequate cyber risk assessments. As a result, they are unprepared for incoming threats and only react after a breach has occurred. 

What Lessons Can Your Business Learn from This Incident?

Businesses need to be more concerned with Disaster Recovery and Business Continuity Plans. To prevent similar attacks on your company’s personal data, here are some integrated solutions you can use: 

  • Implement Strong Security Governance: Conduct regular risk analysis and update security scenarios 
  • Cyber Risk Assessment: Conduct regular cyber risk assessments to identify and fix vulnerabilities before attacks occur 
  • Security Tools and Procedures: Use tools that can effectively detect, prevent, and respond to attacks 
  • Disaster Recovery Plan: Prepare a clear and structured recovery plan 
  • Business Continuity Plan: Ensure there is a reliable business continuity plan 

Most Recommended Data Center Security Solutions to Prevent Cyberattacks by Virtus’ Security Team

In response to increasingly sophisticated cyber threats, Virtus Technology Indonesia (VTI) offers comprehensive and integrated data center security solutions. Here are some key solutions offered to protect your data: 

Isolated Backup (Huawei, Dell, and Rubrik) 

Isolated Backup solutions offer an effective way to ensure data recovery reliability and security. By isolating backup data from the main network, risks of cyberattacks such as ransomware can be minimized. 

  • Key Features: 
    • Simple Setup Process: Quick and easy implementation, allowing integration without disrupting daily operations 
    • Easy Daily Operations: Intuitive and automated backup management, reducing IT team workload 
    • Immutable Snapshot Capability: Taken snapshots cannot be altered or deleted, ensuring backup data is always safe from unauthorized changes 
  • Recommended Tools: 
    • Huawei: Offers backup solutions with isolated storage technology and stringent data protection, ensuring data availability whenever needed 
    • Dell Technologies: Provides the Isolated Backup feature in the Dell Cyber Recovery Solution (CRS), designed to protect backup data from threats such as cyberattacks or malware by isolating those backups from the production network 
    • Rubrik: Backup solution with data immutability features and fast recovery, ensuring your data is always protected and accessible
       

SOC Visibility Triad: XDR, NDR, SIEM (Palo Alto Networks, Sophos, Trend Micro, Arista, Elastic, ExtraHop, OpenText) 

The SOC Visibility Triad is a security framework that combines three key technologies to provide comprehensive visibility and rapid response to threats across networks and information systems. The main components of the SOC Visibility Triad are: 

1. XDR (Extended Detection and Response) </h4> 

XDR integrates data from various sources including endpoints, servers, email, networks, and cloud services to provide full visibility and deep threat analysis. With XDR, security teams can detect, analyze, and respond to threats more efficiently. 

  • Key Features: 
    • Multi-layer security integration 
    • Automatic correlation of data from various sources 
    • Faster and more accurate threat detection capabilities 
  • Recommended Tools: 
    • Palo Alto Networks: Using data from firewalls, endpoints, and cloud services for centralized analysis 
    • Sophos: Providing AI-based automatic detection and response based on correlated data that has been collected 
    • Trend Micro: Integrating data from endpoints, networks, and cloud services for unified response 
    • CrowdStrike: Offering advanced security systems that integrate detection and response from various data sources into a single console, enabling more effective threat monitoring and handling 

2. NDR (Network Detection and Response)

NDR monitors network activities to detect suspicious behavior and provides real-time forensic analysis and network traffic insights, enabling quick identification of hidden threats. 

  • Key Features: 
    • Real-time network monitoring. 
    • Detection of anomalies and suspicious behaviors. 
    • Deep network forensics for incident investigations. 
  • Recommended Tools: 
    • Arista: Utilizes advanced network monitoring technology for deep visibility. 
    • ExtraHop: Uses real-time analytics for faster threat detection. 

 

3. SIEM (Security Information and Event Management) 

SIEM collects, analyzes, and correlates log data from various sources across the network to detect and respond to threats quickly. SIEM also assists in regulatory compliance by providing reports and audit trails. 

  • Key Features: 
    • Centralized log collection and analysis 
    • Incident correlation for better threat detection 
    • Support for security compliance and auditing 
  • Recommended Tools: 
    • Elastic: Enables powerful log searching and analysis 
    • OpenText: Provides comprehensive SIEM solutions for analysis and compliance 

By leveraging tools like Elastic and OpenText for SIEM, Arista and ExtraHop for NDR, and Palo Alto Networks, Sophos, and Trend Micro for XDR, organizations can ensure their data and systems are protected from cyberattacks and security threats. 

SASE (Zero Trust) (Palo Alto Networks, Forcepoint)

Secure Access Service Edge (SASE) applies the Zero Trust principle to secure access to resources in widely distributed environments. The Zero Trust concept rejects the assumption that users or devices within the internal network can be inherently trusted. 

  • Key Features: 
    • Strict Verification: Every access request is verified regardless of user/device origin or status 
    • Specific Access Rights: Access is granted only after identity verification, with access rights determined based on security needs and policies 
    • Security and Network Integration: Integrates security and networking functions into a cloud service 
    • Consistent Management: Ensures consistent application of security policies across distributed environments 
    • Performance Enhancement: Improves network access performance and speed
       
  • Recommended Tools: 
    • Palo Alto Networks: Cloud-based SASE platform integrating security and networking, ensuring consistent protection for all users, whether at headquarters, branches, or remote locations 
    • Forcepoint: A SASE platform that provides secure access to applications and data anywhere, anytime, combining Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA). It also includes Remote Browser Isolation (RBI), Content Disarm and Reconstruct (CDR), and Data Security (DLP) 

IAM/PAM (Ivanti, OpenText) 

Identity and Access Management (IAM) is a system managing digital identities and user access, ensuring only authorized individuals have specific resource access. 

Privileged Access Management (PAM), a part of IAM, manages specific access for sensitive tasks to ensure security and prevent misuse of authority. 

For businesses aiming to ensure optimal data security, IAM and PAM solutions from well-known and proven vendors like Ivanti and OpenText can be the best choice. 

  • Recommended Tools: 

Ivanti

  • Ivanti IAM: Manages identity lifecycle, Multi-Factor Authentication (MFA), and Single Sign-On (SSO) 
  • Ivanti PAM: Granular access control, activity monitoring, and privileged session management 

OpenText

  • OpenText IAM: Automates identity, security, compliance, and auditing, including cloud application integration 
  • OpenText PAM: Providing centralized and privileged user access management across the entire IT ecosystem to enhance security and simplify compliance processes 

Vulnerability Management (Tenable) 

Managed in the cloud and powered by Tenable Nessus, this solution provides comprehensive and real-time vulnerability assessment. It includes built-in prioritization and threat intelligence, enabling quick and efficient understanding and mitigation of risks. 

Awareness Training (ThriveDX)

Before discussing Awareness Training from ThriveDX, let’s review the “Three Pillars of Cyber Security” principle: People, Process, and Technology. This fundamental concept states that effective cyber security requires a holistic approach that includes: 

  • People: Emphasizing the importance of training and security awareness for all system users 
  • Process: Establishing clear procedures and policies to manage and protect data 
  • Technology: Implementing appropriate technologies to detect, prevent, and respond to security threats 

Currently, Awareness Training is crucial in strengthening the “People” pillar in cyber security. ThriveDX offers customizable training and phishing simulation solutions to test employees’ knowledge. With real-time dashboard and automated monthly reports, you can measure progress and enhance security awareness throughout the organization. 

Awareness Training from ThriveDX is highly recommended for building a strong data security culture within your organization, helping employees identify and avoid potential cyber threats more effectively. 

Read more: 10 Must-Have Cybersecurity Skills to Outsmart Cyber Crime 

Patch Management (Ivanti, Quest)

Patch Management can help simplify your IT processes by securing and managing devices from a single console. This solution enhances security by automating patching policies, detecting and remedying vulnerabilities, and ensuring uninterrupted business operations. 

Ivanti and Quest offer some of the best and most recognized Patch Management solutions in the field, providing advanced technology to protect systems from the latest vulnerabilities and cyber threats. 

  • Recommended Tools: 

Ivanti 

Automated Patching: Manages and applies patches automatically 

Vulnerability Detection: Quickly identifies and fixes system vulnerabilities 

Centralized Management: Controls all devices from a single console 

Quest

  • Comprehensive Patching: Patching solutions for various platforms and applications 
  • Audit and Compliance: Ensures system compliance with security policies and regulations 
  • Flexible Scheduling: Schedules patching according to business needs 

With these solutions, Virtus ensures your data center is protected from various cyber threats, maintaining the security and operational continuity of your business. 

Protect Your Business Data Center from Cyberattacks with Virtus’ Comprehensive Solutions

Supported by a competent and certified IT team, Virtus Technology Indonesia (VTI) will assist you through every process of implementing all data center security solutions for your business, from consultation, deployment, and management to after-sales support. 

Consult your needs with Virtus now! For more information, contact our team by clicking here 

Author: Ary Adianto 

Content Writer CTI Group 

 

Share to:

VIRTUS PARTNER ACADEMY

Virtus newest benefit program for Business Partners. Virtus Partner Academy is an online IT training course with a comprehensive curriculum that can be accessed at any time and from any location.

SPEND MORE GET MORE

VIRTUS INCENTIVE PROGRAM

for Business Partner

Privacy Policy

  1. Privacy Policy – PT Virtus Technology Indonesia 

At PT Virtus Technology Indonesia, ensuring the privacy and security of your information is of utmost importance to us. As you navigate through our website, Virtus Technology Indonesia, collectively referred to as this “Website”, we strive to create a safe and trustworthy environment for all users. 

This Privacy Policy establishes the terms governing your use of our website between you (“you” or “your”) and PT Virtus Technology Indonesia. By accessing our website, you acknowledge that you have reviewed, understood, and consent to be bound by this Privacy Policy. 

  1. Information We Collect 

When utilizing or engaging with our Website, we may gather or receive various types of information, collectively referred to as “Information”, including but not limited to: 

  • “Personal Information,” such as your name, email, contact details, or any other personal content provided to us via forms on our website or other means of communication (e.g., email, phone, mail, etc.). 
  • “Technical Information,” such as browser type, operating system, device type, IP address, and similar technical data typically obtained automatically from browsers or devices when interacting with our Website. This may also encompass the referring URL that directed you to our website. 
  • “Usage Information,” such as the pages visited on our website, click activity, searches conducted, and other related data on how you have utilized our website. This category may also encompass details regarding your interaction with emails, including whether you opened, clicked on links, or received them. 

      We acknowledge that certain Technical Information or Usage Information may be considered personal data, either independently or when combined with other data, under various laws and jurisdictions. We are committed in handling such data in accordance with applicable laws and regulations. 

      1. The Methods We Use to Collect and Receive Information 

      Depending on the type of Information, we collect or receive it through various channels, including but not limited to the following conditions: 

      • When you voluntarily share Information with us. For instance, when you subscribe to our newsletter or fill out our online form to request contact.  
      • By using cookies and similar technologies. These technologies help us analyze how our Website is utilized and tailor content that is pertinent to you. They also assist in delivering more relevant advertisements on our own or third-party sites. 
      • Information obtained from third-party sources. This encompasses Information acquired through various business support tools and services we utilize, such as Website, analytics services, etc., as well as public sources like social media sites. We may merge the Information from these sources with other data we possess to maintain updated records and provide you with pertinent content. 
          1. The Purposes 

          We utilize Information for the following purposes: 

          • Processing your inquiries and responding to your requests, such as when you reach out to learn more about our products or services. 
          • Sending you information related to our services and products that we believe may be of interest to you, such as an invitation to our upcoming events, follow-up by WhatsApp blast and/or call, newsletters, or updates on products and services. These communications are sent to you either based on your explicit consent or when we have a legitimate interest in marketing our products and services. You always have the option to opt out of receiving invitation, newsletters, and/or updates on products and services. 
          • Understanding how you interact with our Website and tailoring it to align with your interests, past actions, and preferences. We do this to enhance our Website, diagnose any issues, and improve your experience while navigating through them. 
          • Preventing fraud or harm to us or any third party, and ensuring the security of our network and services, which is in our legitimate interest. 
          • Complying with our legal obligations and exercising and enforcing our legal rights as necessary for PT Virtus Technology Indonesia. 
          • Utilizing certain third-party marketing and advertising networks to assist in marketing our products on our website and third-party Website. 
            1. Who We Share Information With 

            To facilitate our business operations and the functioning of our Website, we may disclose Information to various third parties, including: 

            • Our global branches and subsidiary companies. 
            • Third-party service providers aiding in the operation of our Website, such as hosting companies, recruitment platforms and agencies, payment processors, business management, and email distribution service providers, and similar service providers. These entities are authorized to use your personal information solely to provide these services to us. 
            • When compelled by law, such as to comply with court orders, search warrants, regulatory orders, subpoenas, and other lawful requests from public authorities, including those for national security or law enforcement purposes. 
            • Legal authorities, consultants, advisors, or service providers required to investigate, respond to, or prevent fraud, or to ensure the security of our network and services and safeguard the well-being of PT Virtus Technology Indonesia
            • In the event of a merger and/or acquisition involving PT Virtus Technology Indonesia, Information may be transferred to the merging or acquiring entity, as well as to any advisors representing parties involved in discussions related to such merger or acquisition. 
            • Principal, resellers, partners, sponsors, or service providers acting on our behalf in conjunction with the offering of PT Virtus Technology Indonesia’s products or services. 
            • Third-party marketing and advertising networks assisting in the promotion of our products on our Website and on third-party websites, such as Google for remarketing ads across the Internet. 
            • PT Virtus Technology Indonesia may also disclose general aggregate and anonymized information (e.g., statistical data) pertaining to the use of its Website. 
                1. Cross Border Data Transfers 

                • We may need to transfer Information to countries where we and/or our service providers operate. These countries may have different data protection laws compared to the country where the data originated, potentially offering different levels of protection. By using our Website, you consent to such transfers. In cases where applicable to the services provided, we will establish agreements with our service providers to ensure a level of privacy consistent with the terms of this policy. 
                • Regarding the collection, use, and retention of personal information transferred from Indonesia, please note that PT Virtus Technology Indonesia remains compliant with all relevant laws concerning such transfers.
                1. Protecting Your Information 

                We aim to uphold top-tier security standards throughout our business operations. We have adopted suitable technical and organizational safeguards aligned with industry best practices. These safeguards are devised to prevent unauthorized access or unlawful handling of Personal Information and to mitigate the risk of accidental loss, destruction, or damage of such information. As part of these efforts, we have instituted several policies and procedures to guide us, covering aspects such as asset management, access control, physical security, personnel security, product security, cloud and network infrastructure security, third-party security, vulnerability management, security monitoring, and incident response. 

                1. Information Storage and Retention 

                We may store Information on both our own servers and those managed by third-party data hosting providers. As explained in Section 5 above (Cross Border Transfers), these servers may be situated globally. We will retain your Personal Information only for as long as necessary to fulfil the collection’s intended purpose. Additionally, we may retain your Personal Information for the duration required to pursue our legitimate business interests, address any legal claims, and ensure compliance with legal obligations. In instances where we utilize your information for direct marketing, we will retain your data until you choose to opt-out of receiving marketing materials; however, certain information may need to be retained to maintain a record of your request.  

                1. Modifications to This Policy 

                PT Virtus Technology Indonesia reserves the right to amend this Privacy Policy at any time. In the event of a significant change, we will provide notice on this page and/or adjacent to the link leading to this page. These updates will become effective immediately for new Information collected or provided from the date of the update, and within thirty (30) days for any Information collected or provided to PT Virtus Technology Indonesia prior to the update. If you do not agree to the terms of the revised policy, please contact our Legal Department using the contact details provided in Section 11 below. We encourage you to periodically review this page for any updates.  

                1. Your Choices 

                We offer you various options regarding the use of Information in relation to: (i) our marketing activities; and (ii) our utilization of cookies and similar technologies for interest-based advertising and website usage analysis 

                1. a. You can choose to discontinue receiving our newsletter or marketing emails by following the unsubscribe instructions included in these emails, adjusting email preferences in your account settings page, or contacting us through PT Virtus Technology Indonesia.

                1. b. Moreover, the laws in some jurisdictions may grant you various rights concerning our processing of certain Information. These rights may include:

                  i. The right to withdraw previously provided consent; 

                  ii. The right to access specific information about you that we process; 

                  iii. The right to rectify or update any Personal Information; 

                  iv. The right to request the erasure of certain Information; 

                  v. The right to temporarily suspend our processing of certain Information; 

                  vi. The right to receive Information in a common machine-readable format; 

                  vii. The right to object to our processing of Information for direct marketing purposes or when we rely on legitimate interests as the lawful basis for processing your information; and 

                  viii. The right to file a complaint with the relevant data protection authority. 


                  We will address your requests promptly. Please note that these rights may be subject to limitations under applicable law. For further information on these rights or to exercise them, please contact PT Virtus Technology Indonesia at: legal@computradetech.com

                1. Social Media and Third-Party Services 

                Our Website may include a blog with a ‘comments’ section and several social media features, such as a ‘share’ button or links to third-party websites and services like Facebook, X, YouTube, LinkedIn, and Instagram. When utilizing these features, certain information may be gathered by these third parties, such as your IP address or the specific page you are visiting on our website. Additionally, these third parties may set cookies to ensure the proper functioning of the features. Any data collected by these third parties is subject to their respective privacy policies. We encourage you to thoroughly review the privacy policies of these third parties. 

                1. Contacting Us 

                If you have any questions or concerns regarding this Website Privacy Policy, the information we collect, PT Virtus Technology Indonesia‘s practices, or your interactions with the Website, please feel free to contact us. You can reach us via email at legal@computradetech.com or by physical mail addressed to: PT Virtus Technology Indonesia (Centennial Tower 12th Floor, Jl. Jend. Gatot Subroto Kav. 24-25, Jakarta – 12930, (021-80622288).