Server racks in a data center with blinking indicator lights
Back to blog

Data Breach Response for Indonesian Businesses

A data breach response guide for Indonesian businesses: first 24 hours, UU PDP obligations, customer communication, digital forensics, and recovery costs.

The email arrives at 10:47 p.m., from the cloud service provider: "We detected unauthorized access to your storage bucket on August 12-14. Some data may have been downloaded. Please investigate immediately and contact our security team." The founder of an e-commerce startup in Jakarta reads the email three times, then stares at a blank screen. In that bucket sits customer data: names, phone numbers, addresses, order history, some password hashes. How much leaked? Since when? Who must be told? And — the most crushing question — what does he say to the 40,000 customers who entrusted him with their data?

This moment is called a data breach: a failure of data protection in which personal data is exposed, stolen, or accessed without authorization. It can happen to anyone — large companies, small online stores, clinics, schools, or startups. And since Indonesia's Personal Data Protection Law (UU PDP) took full effect in October 2024, how you respond to a breach is no longer just a reputational matter: it is a legal obligation with real sanctions.

This article is a data breach response guide for Indonesian businesses: what to do in the first 24 hours, your obligations under UU PDP, how to communicate with customers without destroying trust, when digital forensics is needed, and estimated recovery costs in the local market.

What Is a Data Breach, and How Is It Different from Other Incidents

A data breach is an incident in which personal data is accessed, disclosed, or stolen by an unauthorized party. Its forms vary: a hacked database, files downloaded from a misconfigured cloud storage, a laptop with customer data lost or stolen, an employee sending data to the wrong email address, or backups containing sensitive data thrown away without destruction.

It is important to distinguish a data breach from security incidents in general. A malware attack on one office computer that does not touch customer data is a security incident, but not necessarily a data breach. Conversely, a database left open to the public without any hacking at all — just a misconfiguration — is a legitimate data breach: the data was exposed, even if no "hacker" was involved. The measure is not who attacked, but whether personal data was exposed.

This distinction determines your response. Technical incidents are handled by the IT team. A data breach drags in law, communication, and risk management — and often requires action before the technical investigation is complete. This is where many businesses stumble: they treat a data breach as a purely technical problem and only realize the legal dimension when it is too late.

Why Data Breaches Become Expensive: Three Dimensions of Loss

Direct financial loss

Global research from IBM estimates the average cost of a single data breach at millions of US dollars once forensics, recovery, lost business, and fines are counted. For Indonesian businesses, the absolute figures are of course smaller, but the proportions hurt just the same: forensics costs, operational shutdowns, compensation or reimbursement to customers, and crisis communication costs can reach hundreds of millions of rupiah for a mid-size business.

Customer loss

After a breach, some customers will leave — not out of anger, but out of fear. Global studies show that a significant share of consumers stop dealing with a company that has experienced a data breach. Trust built over years of discounts, service, and reputation can disappear faster than the data spreads across online forums.

Legal loss

This is the dimension that has changed drastically in Indonesia. UU PDP requires data controllers to safeguard personal data, and when a data protection failure occurs, to notify it in writing no later than 3 x 24 hours to data subjects and relevant authorities. Administrative sanctions can reach two percent of a legal entity's annual revenue — for a company with billions of rupiah in revenue, that is not a number to ignore. Add civil lawsuits from harmed customers to the picture.

These numbers are not meant to scare, but to put preparation in its proper place: data breach response is not an optional expense, it is an insurance premium that must be paid before the policy is needed.

Preparation: What Must Exist Before the Leak

A good response does not start when that 10:47 p.m. email arrives. It starts long before, with a clear head. Four things should be in place before the first incident:

1. A data map

A document answering: what personal data do you store, where is it located, who accesses it, and how long is it kept. Without a data map, the first question during an incident — "what data might have leaked?" — can only be answered with guesses. With a data map, you can assess scope in hours, not weeks.

2. An incident response procedure

You do not need to write everything from scratch: the full guide is in our incident response plan article. What matters is that the procedure includes a specific path for data breaches: who assesses legal obligations, who drafts the notification, and who has the authority to decide public communication.

3. A team and emergency contacts

Names, job titles, and personal numbers for every role: coordinator, technical, legal, communications. Including forensics vendor and legal counsel contacts that were already known beforehand — contacting a vendor for the first time in the middle of a crisis is the worst negotiating position imaginable.

4. Regular practice

One tabletop exercise per year with a breach scenario (for example: "a cloud bucket was open to the public for three weeks, affecting thousands of customers — what do you do?") will expose holes in the plan far faster than waiting for a real incident.

The First 24 Hours: The Right Order of Actions

When a breach is confirmed, or even just suspected, follow this sequence. The order matters: every step protects the next.

Hours 0-2: Stop, secure, record

  • Stop the bleeding. Close the open access, take affected services offline if necessary, disconnect systems from the network — but do not delete or alter data. Evidence is the most valuable asset at this stage.
  • Secure evidence. Screenshots, logs, file metadata, notification emails — everything recorded with timestamps. Do not investigate "on the fly" on the same system; work from copies or records, not by modifying the original system.
  • Appoint a coordinator. One person holds the timeline and decisions. Without a coordinator, everyone pulls in different directions.
  • Do not discuss on social media. No communication decision has been made yet; one uncoordinated employee comment can become a headline.

Hours 2-8: Assess the scope

  • Identify the data involved: data types (names, contacts, financial, health?), number of data subjects, and sensitivity. Financial data and children's data are the most sensitive categories legally and in terms of impact.
  • Estimate the cause: hacked, misconfigured, lost device, or insider? The initial cause determines the next technical steps, but do not wait for full certainty to start the legal process.
  • Set the severity level per your procedure, and activate the full team if it touches customer data in significant volume.

Hours 8-24: Legal and communication decisions

  • Involve legal counsel. This is where the decision "is this a reportable data protection failure" should be answered together with legal experts. UU PDP's 3 x 24 hour notification rule applies to personal data protection failures; assessing whether your incident falls into that category requires combined legal and technical judgment.
  • Draft the notification. Prepare notification drafts for customers and relevant authorities, with the information UU PDP requires: what personal data was exposed, when and how it was exposed, and the handling and recovery efforts undertaken.
  • Prepare internal communication. Employees must know what may and may not be said — the one-voice rule applies fully here.

Hours 24-72: Notification and recovery

  • Send the official notification within the 3 x 24 hour deadline if your incident qualifies as a personal data protection failure. Delaying in hopes of "finding the gap first, then reporting" is a common mistake — the deadline does not wait for the investigation to finish.
  • Start technical recovery in priority order: close the gap, restore from clean backups, verify integrity, and add extra monitoring.
  • Set up customer support: a question channel, steps customers can take (change passwords, watch for phishing), and — if relevant — assistance with document replacement.

What a Customer Notification Must Contain

The breach notification is the document that most determines your reputation's fate. Customers who read an honest, clear, helpful notification will keep trusting you; customers who read a convoluted one will leave — or worse, sue.

The structure of a good notification:

  • What happened, in human language, not jargon: "your name, phone number, and address were exposed due to unauthorized access to our server on date X".
  • What data was involved, as honestly as possible. Do not soften it: customers have the right to know whether passwords or financial data were affected, because that determines the actions they must take.
  • When and how, based on what you know at the time. If details are incomplete, say what is not yet known and when you will provide updates.
  • What you have done: closed the gap, rotated credentials, added monitoring.
  • What customers should do: change passwords, enable 2FA, watch for phishing emails exploiting their data, contact their bank if financial data was affected.
  • A help channel: a dedicated number or email address for questions, not a general address that goes unanswered.

Three fatal mistakes in notifications: delaying because "the details are incomplete" (the 3 x 24 hour deadline does not wait), denying before evidence (a denial that proves false destroys trust twice over), and prematurely blaming others (unproven accusations against a vendor can turn into lawsuits against you).

Public Communication: One Voice, Facts First

Once the customer notification is sent, questions from journalists, communities, and social media will come. The rules are the same as the notification, plus one: one voice.

  • Appoint one spokesperson and one official information channel (for example, a status page on your website).
  • Share known facts, a timeframe, and the steps being taken. Analysis of the cause is shared only when supported by evidence.
  • Update regularly, even when there is no news — "we have found no additional evidence, the investigation continues" is far better than silence.
  • Never make promises you cannot keep: "everything is definitely safe" is the most dangerous sentence in a crisis.

One important note for Indonesian businesses: do not assume a data breach can be "hidden". Leaked data often circulates in online forums and becomes news; trying to hide it only delays the disclosure and adds reputational damage when it finally comes out. Fast honesty is the best reputational strategy that exists.

Digital Forensics: When It Is Needed and What It Costs

Digital forensics is a systematic investigation to determine what happened, how, and how far it reached. It answers questions that guesses cannot: what data was actually downloaded, who did it, and whether there is other access not yet discovered.

When is forensics needed? A practical guide: if the breach involves customer data in significant volume, financial data, or suspected involvement of an outside party. Internal IT investigation is often enough for small incidents; for cases with legal potential, independent forensics provides evidence that can be accounted for — before customers, authorities, and courts.

Digital forensics costs in Indonesia vary by complexity: for a focused investigation (one system, limited scope), it typically starts around Rp 25-75 million; for a comprehensive investigation with timeline reconstruction and network analysis, it can reach hundreds of millions. Some vendors offer retainer pricing — paying in advance for response capacity — which can reduce costs and speed up the start time.

A decision that is often wrong: using the internal team to investigate a breach with legal potential. The internal team can be technically excellent, but an investigation that will be examined by others — lawyers, regulators, courts — must meet evidence standards that operational teams do not always master. The conflict of interest is real too: a team that may have contributed to the incident cannot credibly audit itself.

Recovery Costs: Estimates for Indonesian Businesses

There is no fixed price, but here are the components that typically appear and their market ranges:

ComponentCost rangeNotes
Digital forensicsRp 25-100+ millionDepends on scope and complexity
Legal counsel & notificationRp 15-75 millionObligation assessment, notification drafting, representation
Technical recovery & gap closureRp 10-100 millionBackups, patching, extra monitoring
Crisis communicationRp 5-50 millionPR consultants, status page, support channel
Customer compensation/incentivesvaries widelyDepends on policy and impact scale
Potential administrative sanctionsup to 2% of annual revenueUnder UU PDP for serious violations

Add it up for a mid-size case: a customer data breach handled seriously typically costs tens to hundreds of millions of rupiah on top of lost business. Compare that with prevention investments — tested backups, monitoring, regular security assessments, incident response procedures — which can be far cheaper. This ratio is the most honest argument for investing before an incident, not after.

After Recovery: Learning and Rebuilding

Recovery is not complete when systems run normally again. Three jobs follow:

Thorough evaluation. Hold a review meeting two weeks after the incident: what happened, what went well and badly, what gap was exploited, and what changes prevent recurrence. The output must be actions with deadlines, not meeting notes.

Continuous improvement. A data breach almost always reveals deeper weaknesses: undocumented processes, overly broad access, backups never tested. Fix the roots, not the symptoms.

Rebuilding trust. Customer trust recovers through actions, not promises: honest regular updates, visible security improvements, and service that keeps working well. Businesses that get through a breach with transparency often come out with a stronger reputation than businesses that covered things up — because customers know they can believe what the company says, even when the news is bad.

Preparation Is Half the Response

Back to the 10:47 p.m. email at the start of this article. That startup eventually handled its breach well: the internal team locked down access within two hours, legal counsel assessed obligations within a day, the customer notification went out within the 3 x 24 hour deadline, forensics found that what leaked was contact data without passwords or financial details, and regular updates kept communication honest. Some customers left; most stayed. And from that day on, the company ran regular security assessments and incident response drills — a lesson that cost less than the second breach that would certainly have come if they had not learned.

Data breaches cannot be completely eliminated; they can only be prevented, contained, and responded to. What determines your business's fate is not whether a breach happens, but how ready you are when it does. A good security foundation — the website security guide, incident response procedures, and proper cloud risk management through the cloud migration guide — is the first investment that must exist. If your team has never faced a data breach, consider guidance from people who have handled them: the Kartech team in Bandar Lampung helps businesses draft breach response procedures, conduct security assessments, and prepare teams for worst-case scenarios. Start from the contact page or explore our services.

Customer trust is an asset that does not appear on the balance sheet, but it determines your business's value more than buildings and machines. Protecting it does not mean promising the impossible; it means preparing for what may happen — and speaking honestly when it does.

Photo: Unsplash

Bring us the hard part.

Tell us what is blocked, what must be built, or where your current technology is falling short. We will start with the problem.

Talk to us