Maritime Cybersecurity in Indonesia: Are Law, Governance, and Business Ready?
Maritime cybersecurity in Indonesia is now a legal and business priority. Indonesia has relevant laws on shipping, electronic systems, personal data and critical infrastructure, but no dedicated, integrated maritime cyber regime. This leaves gaps in reporting duties, lead authority, vendor responsibility and insurance coverage.
Download PDF
Maritime Cybersecurity in Indonesia: Why It Is Now a Legal and Business Priority
Indonesia’s maritime sector is undergoing rapid digital transformation. Ships, ports, terminals, logistics networks, navigation systems, cargo platforms and maritime authorities increasingly depend on connected information technology (IT) and operational technology (OT).
This connectivity creates operational benefits. It also expands exposure to ransomware, unauthorised access, data manipulation, system outages, malware, supply-chain compromise and attacks on safety-critical systems.
A cyber incident affecting a maritime organisation may disrupt:
- Vessel navigation and communications.
- Cargo handling and terminal operations.
- Port access and vessel traffic services.
- Customs and logistics systems.
- Supply-chain continuity.
- Personal and commercial data.
- Safety, environmental protection and emergency response.
The legal question is no longer simply whether a shipping company or port operator has been hacked. The more important questions are: who is responsible for the consequences, which laws apply, and do existing contracts and insurance policies actually respond?
ACTIO® Edition 30 examines these questions through three connected perspectives: law, governance and people capacity.
What Is Maritime Cyber Risk?
The International Maritime Organization (IMO) defines maritime cyber risk as the extent to which a technology asset is threatened by an event or circumstance that could cause shipping-related operational, safety or security failures because information or systems are corrupted, lost or compromised.
This goes beyond the traditional view of cybersecurity as data protection. A maritime cyber incident may have digital, operational, physical, financial, contractual, regulatory, criminal and environmental consequences.
For example, a compromised navigation or positioning system could affect a vessel’s route and collision-avoidance decisions. Ransomware in a port operating system could delay cargo release, berthing, customs processes and inland transportation.
The same incident may trigger several legal issues at once:
- Breach of contract.
- Negligence.
- Personal data protection obligations.
- Shipping safety responsibilities.
- Insurance coverage disputes.
- Regulatory investigation.
- Potential regulatory and, in limited circumstances, criminal exposure.
What Does the IMO Require?
ISM Code and Resolution MSC.428(98)
IMO Resolution MSC.428(98) encourages maritime administrations to ensure that cyber risks are appropriately addressed in Safety Management Systems (SMS) under the ISM Code. Administrations were expected to address this no later than a company’s first Document of Compliance verification after 1 January 2021. The IMO states that cyber risk should be addressed within existing safety and security management practices rather than treated as a separate IT problem.
An SMS should therefore consider whether cyber risk can affect safe ship operation, crew and passenger safety, cargo and property, the marine environment, emergency preparedness, and business continuity and recovery.
In practice, a shipping company should be able to demonstrate a risk-based process for:
- Identifying cyber risks.
- Assessing their potential impact.
- Implementing proportionate safeguards.
- Detecting incidents.
- Responding to disruption.
- Recovering critical operations.
- Reviewing and improving controls.
Evolving guidance and class rules
IMO’s maritime cyber risk management guidance is periodically revised. Companies should check the current version, together with flag-state requirements, classification society expectations (including IACS UR E26 and E27 for newbuildings) and applicable national rules.
Cyber compliance is not a one-time certification exercise, and relying only on older procedures is a risk in itself.
Does Indonesia Have a Maritime Cybersecurity Law?
Indonesia has no single maritime cybersecurity law. Several instruments are relevant, but they do not form one dedicated maritime regime. Confirm the current amending laws before relying on any citation below.
- Law No. 17 of 2008 on Shipping, as amended.
- Law No. 11 of 2008 on Electronic Information and Transactions (ITE Law), as amended.
- Government Regulation No. 71 of 2019 on Electronic Systems and Transactions.
- Law No. 27 of 2022 on Personal Data Protection.
- Presidential Regulation No. 82 of 2022 on Protection of Vital Information Infrastructure.
- BSSN regulations on electronic-system security and cyber crisis management.
- Maritime and port security regulations implementing the ISPS Code.
These instruments may impose important duties, but they do not necessarily answer maritime-specific questions:
- What cyber controls must a vessel operator maintain?
- What minimum requirements apply to port operational technology?
- Which maritime cyber incidents must be reported, and to whom?
- Which agency leads the response?
- What evidence must be preserved?
- How should responsibilities be allocated to vendors?
- How should cyber risk be built into ship and port safety audits?
The result is a regulatory patchwork. Relevant rules exist, but their relationship is not always clear in a maritime operational context.
Why this matters
During an incident, a shipping company may need to restore operations, notify authorities, coordinate with insurers, preserve evidence, protect personal data, deal with charterers and cargo interests, and communicate with customers, all while the technical impact is still developing. Without clear reporting channels and institutional coordination, the response becomes slower, costlier and harder to manage.
Governance Challenge: Who Leads When an Incident Occurs?
Maritime cybersecurity involves many stakeholders:
- The Ministry of Transportation.
- BSSN.
- BAKAMLA and the Indonesian Maritime Information Center.
- Port operators.
- Shipowners and ship managers.
- Classification societies.
- Technology providers.
- Insurers and P&I clubs.
- Cargo owners and logistics providers.
- Law-enforcement agencies.
Each may have a legitimate role, but responsibilities can overlap or remain unclear. An effective incident framework should identify:
- The first point of notification.
- The lead authority for each category of incident.
- The responsibilities of the affected operator.
- Information-sharing procedures.
- Evidence-preservation requirements.
- Communication protocols.
- Coordination with foreign authorities.
- The role of insurers and forensic providers.
- Recovery and post-incident review procedures.
The challenge is not the absence of institutions. It is the absence of an integrated framework connecting maritime safety, cybersecurity governance, incident response and legal accountability.
BIMCO Cyber Security Clause 2019
Where public regulation is incomplete, contracts can allocate cyber responsibilities between commercial parties. The BIMCO Cyber Security Clause 2019 applies only when the parties incorporate it. BIMCO is not a regulator, and the Clause has no independent binding force.
The Clause addresses appropriate cybersecurity measures, incident-response procedures, regular review and record keeping, third-party service providers, prompt notification, mitigation, information sharing and liability limits.
Each party must implement appropriate measures, maintain response procedures, review them regularly and keep records of those reviews. Parties must also use reasonable endeavours to ensure that relevant third-party service providers meet comparable requirements.
A party that becomes aware of an incident affecting, or likely to affect, either party’s cybersecurity must promptly notify the other. If the incident occurs in one party’s digital environment, that party must take reasonable steps to mitigate or resolve it and provide contact details and relevant information within 12 hours of the original notification.
The Clause includes a default liability cap of USD 100,000 if the parties insert no other amount, subject to an exception for loss caused solely by gross negligence or wilful misconduct.
What the Clause does not do
- Replace Indonesian cybersecurity regulation.
- Create a complete incident-response regime.
- Automatically bind vendors or subcontractors.
- Guarantee insurance coverage or mandate cyber insurance.
- Determine governing law or dispute-resolution forum.
- Resolve all force majeure or carriage liability issues.
- Prevent payment fraud through wording alone. BIMCO notes that internal verification and authorisation procedures are the better answer.
Contract review checklist
- Is the USD 100,000 cap commercially appropriate?
- Does the cap apply per incident or to a series of breaches?
- Is the Clause incorporated consistently throughout the charterparty chain?
- Are vendors and subcontractors adequately addressed?
- Is the 12-hour information requirement operationally achievable?
- Does it align with regulatory reporting obligations?
- Can confidential information be shared with authorities and insurers?
- Should specific technical standards be added?
- Are the governing law and arbitration provisions suitable?
A standard clause is a useful starting point, not a substitute for a transaction-specific cyber risk assessment.
Does Marine Insurance Cover Maritime Cyber Risk?
Marine insurance may transfer some financial consequences of a cyber incident, but having insurance does not guarantee coverage. The outcome depends on the insuring agreement, definitions, exclusions, endorsements, causation, policy conditions, other-insurance provisions, and the facts and attribution of the incident.
| Policy | Potentially relevant exposure |
|---|---|
| Hull and Machinery | Physical damage to the vessel or machinery |
| Protection and Indemnity (P&I) | Certain third-party liabilities |
| Cargo insurance | Loss of or damage to cargo |
| Loss of hire | Certain operational interruption losses |
| Charterers’ liability | Liabilities connected with chartering activities |
| War-risk insurance | Certain hostile or war-related events |
| Standalone cyber insurance | Data loss, ransomware, restoration, business interruption and cyber liabilities |
A cyber incident may look like a conventional maritime casualty and still be affected by a cyber exclusion. Relevant market clauses include the Institute Cyber Attack Exclusion Clause CL380, LMA Marine Cyber Exclusion LMA5402 and LMA Marine Cyber Endorsement LMA5403.
The key issue is not whether a computer system was involved. The analysis must consider what happened, how, what loss resulted, and how the policy allocates that risk.
Questions for insurers and insureds
- Are malicious cyberattacks excluded?
- Are accidental system failures treated differently?
- Is operational technology covered?
- Is physical damage caused by cyber interference covered?
- Is business interruption covered?
- Are data restoration and forensic costs covered?
- Are third-party claims covered?
- Are state-backed cyberattacks excluded?
- Does the policy contain a war or hostile-action exclusion?
- Are notification obligations compatible with the incident-response plan?
Insurance is one part of cyber risk management, not a replacement for governance, technical controls, training and response planning.
Can a Cyber Victim Face Liability?
A maritime company may be both a victim and a subject of scrutiny. The external attacker may be responsible for the initial unlawful access, but authorities, counterparties, insurers and courts may also ask whether the organisation:
- Maintained reasonable security measures.
- Conducted adequate risk assessments.
- Protected critical systems.
- Trained employees and crew.
- Supervised vendors.
- Implemented incident-response procedures.
- Complied with data-protection duties.
- Preserved evidence.
- Took reasonable steps to mitigate harm.
- Maintained safe operations after the incident.
This does not mean every successful cyberattack creates liability for the victim. Liability depends on the applicable provisions and the facts.
Risk rises where cyber weaknesses contribute to collision or grounding, navigation failure, cargo loss, pollution, injury or death, port disruption, significant economic damage, unlawful disclosure of personal data, or failure to meet mandatory reporting or safety requirements.
The more accurate question is not “victim or suspect?” but whether the operator showed the care, governance, preparedness and control expected of an entity responsible for digitally dependent maritime operations.
A Practical Maritime Cybersecurity Action Plan
- Map critical systems. Inventory shipboard, port, logistics and corporate systems, and identify those affecting navigation, propulsion, communications, cargo, access control, port operations, safety, personal data and financial transactions.
- Integrate cyber risk into the SMS. Treat cyber risk as part of the Safety Management System, not only an IT policy. Document risk assessments, roles, response procedures, backup and recovery, training, and audit and review.
- Review contractual allocation. Assess charterparties, bills of lading, terminal, technology, service and vendor agreements. Confirm who maintains cybersecurity, who notifies whom, what is shared, who pays response costs, whether caps are realistic, whether obligations flow down to vendors, and which law and forum apply.
- Review insurance wording. Map cyber exposures against H&M, P&I, cargo, war-risk, loss-of-hire and standalone cyber policies. Identify exclusions before an incident.
- Test incident response. A written plan is not enough. Run tabletop exercises with legal, IT and cybersecurity, vessel and port operations, senior management, communications, insurers, external counsel, forensic specialists and relevant authorities.
- Build people capacity. Train on phishing and social engineering, remote access, portable devices, passwords and authentication, reporting suspicious activity, payment verification, evidence preservation and emergency communications.
What Should Indonesian Maritime Businesses Do Now?
Treat cyber resilience as a board-level business-continuity and safety issue. The immediate priorities are:
- Identify critical IT and OT systems.
- Integrate cyber risk into the SMS.
- Establish clear internal and external reporting procedures.
- Review BIMCO and other cyber clauses before signing.
- Reassess liability caps and vendor obligations.
- Check marine insurance exclusions and affirmative coverage.
- Conduct incident-response exercises.
- Keep records showing controls are implemented and reviewed.
- Monitor IMO guidance, Indonesian regulations, flag-state requirements and class standards.
Frequently Asked Questions
Does Indonesia have a dedicated maritime cybersecurity law?
No. Relevant rules exist across shipping, electronic systems, personal data, critical infrastructure and port security, but they do not form one integrated maritime cyber regime.
Is the BIMCO Cyber Security Clause mandatory?
No. It applies only if the contracting parties incorporate it. BIMCO is not a regulator.
Does marine insurance automatically cover a cyberattack?
No. Coverage depends on policy wording, exclusions such as CL380 or LMA5402, endorsements, causation and the facts of the incident.
Can a company be liable after being hacked?
Possibly. Authorities, counterparties and courts may examine whether the company maintained reasonable security, supervised vendors, complied with data-protection duties and responded appropriately. Liability depends on the law and facts.
Conclusion
Maritime cybersecurity in Indonesia is no longer only a technology issue. It combines maritime safety, corporate governance, contractual risk allocation, insurance, regulatory compliance and legal responsibility. The IMO framework gives the international direction: govern, identify, protect, detect, respond to and recover from cyber risks as part of safe maritime operations.
Indonesia has relevant laws and institutions, but the lack of an integrated maritime framework creates practical uncertainty. BIMCO clauses can allocate responsibility and insurance can transfer some financial risk, but neither replaces effective governance and operational resilience. The best prepared organisations connect cyber controls, safety management, contract drafting, insurance review, vendor governance, incident response and crew training. Maritime cyber resilience begins before the incident.
Download ACTIO® Edition 30
For deeper analysis across Indonesian law, IMO standards, BIMCO protections, marine insurance, corporate liability, governance and people capacity, download ACTIO® Edition 30: Maritime Cyber Risk Across Law, Governance, and People Capacity.
This article is for general informational purposes only and does not constitute legal advice. The application of Indonesian law depends on the facts, contractual documents, applicable regulations and circumstances of each incident.
