Editor’s Note:
The Indonesia of Today (2026 Update)
Since this article was first written, Indonesia has changed considerably — and so has the nature of risk for foreign businesses operating there. The election of President Prabowo Subianto in October 2024 ushered in a new political era. While Prabowo ran on a platform broadly continuing his predecessor Joko Widodo’s policies, execution of promised reforms has been uneven. Investors have encountered regulatory reversals, inconsistencies between ministerial directives, and a fiscal environment under growing pressure.
Indonesia’s economy has maintained moderate growth — GDP expanded at roughly 5% in 2025, with projections of approximately 4.9% through 2026 — supported primarily by domestic consumption rather than foreign investment or export performance. However, several structural risk factors have become more pronounced and demand updated attention from any organisation considering a market entry or expansion.
In an increasingly competitive environment, multinational companies continue to expand and move into new and unfamiliar territories, either to take advantage of lower operating costs, a cheaper workforce, access to untapped natural resources or what is perceived as a potentially large market. In their haste to take advantage of these ‘attractions’, companies often fail to carry out the necessary due-diligence and research to identify the potential risks and pitfalls associated with such a venture.
Indonesia, like many other developing countries, aside from presenting attractive opportunities also presents a variety of potential risks to which investors may be exposed and vulnerable. These risks range from a history of political and economic instability, civil unrest, religious conflict and the ongoing — if evolving — threat posed by Islamic extremist groups, to socio-economic challenges and rising unemployment. This is in addition to having to work within an environment which for the unprepared cannot only be costly, but also challenging in terms of:
- A poor regulatory environment and lack of transparency;
- An ineffective and corrupt legal system; and
- An increasingly militant labour force, with manpower laws heavily in favour of the workforce.
Updated Risk Landscape: What’s New and What Remains
Political and Regulatory Environment
The core regulatory risks identified in this article remain very much in play. Regulatory uncertainty — inconsistent licensing rules, abrupt policy changes, and the absence of predictable enforcement across regions — continues to be one of the most cited frustrations among foreign investors. The IMF, in its most recent Article IV consultation with Indonesia, specifically flagged the risk of large policy shifts being implemented without sufficient safeguards, and called for deregulation, infrastructure investment, and a reduction in non-tariff trade barriers as priorities for sustainable growth.
The new Prabowo administration has announced reform intentions, but progress has been described by analysts as piecemeal. Investors should not assume a smoother regulatory landscape without verifying the current state of specific licences, sector rules, and regional regulations applicable to their operations.
Fiscal Pressures and Macroeconomic Risk
Indonesia’s public finances face mounting pressure. The country’s constitutionally mandated deficit ceiling is 3% of GDP; by early 2026, government officials were warning that the deficit could breach 3.53% — driven by ballooning energy subsidy costs linked to rising global oil prices and softening tax revenues. For businesses, this matters: fiscal stress can lead to abrupt regulatory changes, new tax measures, or withdrawal of investment incentives. Companies dependent on government contracts or operating in subsidised sectors should model for this risk explicitly.
The Rupiah has faced depreciation pressure, with Bank Indonesia intervening repeatedly to stabilise the currency — drawing down foreign exchange reserves in the process. Import cover has fallen from ten months at the start of the decade to under six months, a metric worth monitoring for businesses with significant imported input costs.
Cybersecurity: An Entirely New Risk Dimension
When this article was first written, computer security risks were understood primarily in terms of internal data theft, fraud, and limited digital intrusions. The threat environment in 2026 is of an altogether different order of magnitude.
Indonesia is now Southeast Asia’s largest internet market by active users, and its digital economy was valued at USD 130 billion in 2025, with projections to reach USD 360 billion by 2030. This scale has made Indonesia a prime and frequently exploited target for cyber threats. In one recent year alone, Indonesia recorded over 400 million cyberattack attempts. Major breaches have hit government servers, financial institutions, and enterprise systems. Ransomware, double-extortion attacks, deepfake-enabled social engineering, and supply chain compromises are among the most serious and growing threats.
PwC’s 2026 Digital Trust Insights survey found that nearly 68% of business and technology leaders in Indonesia now rank cyber risk investment among their top three strategic priorities — a higher proportion than both the Asia-Pacific average and the global average. That is an indicator of genuine alarm, not merely corporate box-ticking.
For any organisation entering or operating in Indonesia today, cybersecurity must be elevated from a supporting IT function to a board-level strategic risk priority. This means:
- Appointing or contracting a Chief Information Security Officer (CISO) with regional expertise.
- Implementing Zero Trust architecture across company networks.
- Ensuring compliance with Indonesia’s Personal Data Protection Law (PDP Law, enacted 2022), which imposes strict obligations on data controllers and processors and has triggered significant enforcement activity and compliance investment.
- Conducting regular penetration testing and threat assessments specific to the Indonesian environment.
- Including cyber incident response in the Crisis Management Plan.
Indonesia’s National Cyber and Encryption Agency (BSSN) has expanded its capabilities and there is now a more structured national framework for cyber resilience — but the threat continues to outpace the defensive infrastructure, particularly for smaller and mid-sized companies.
Climate, Environment, and Natural Disaster Risk
This is a risk category that deserves far more prominence than it received when this article was originally written. Indonesia sits on the Pacific Ring of Fire and is one of the world’s most disaster-exposed economies — vulnerable to earthquakes, volcanic eruptions, and flooding. Climate change is intensifying these risks.
In November 2025, Cyclone Senyar struck Indonesia, resulting in over 1,200 deaths and an estimated USD 4.1 billion in economic losses. The event was a stark warning: tropical cyclones, previously rare in Indonesia, are becoming a more credible threat as ocean temperatures rise. Critically, the government’s disaster management budget was cut from USD 118.7 million in 2025 to USD 29.1 million in 2026 — a sign that political priorities are not aligned with physical risk.
For businesses, this translates to:
- The need for business continuity plans that account for natural disasters, not just civil or security incidents.
- Site-selection decisions should incorporate flood mapping, seismic risk data, and cyclone trajectory modelling.
- Supply chain resilience audits should account for the geographic vulnerability of Indonesian suppliers, particularly those in remote manufacturing locations.
- Environmental safeguards in land governance remain weak; companies with land-intensive operations face reputational and legal exposure if concession areas are later found to overlap with ecologically protected zones.
ESG, Sustainability Reporting, and Corporate Governance Compliance
ESG compliance has moved from voluntary best practice to a structured and increasingly mandatory framework for companies operating in Indonesia — particularly those that are publicly listed, in the financial sector, or in natural resource industries.
Indonesia adopted its own Sustainability Disclosure Standards (SPK) in July 2025, aligned with IFRS S1 and IFRS S2, with mandatory implementation from January 2027. Climate-related disclosures will be required; other ESG disclosures will initially remain voluntary but are expected to expand in scope.
Presidential Regulation No. 110 of 2025 strengthens Indonesia’s carbon pricing framework, establishing a national carbon registry and refining mechanisms for emission quotas and trading. While the implementation of a carbon tax on coal-fired power plants has been repeatedly delayed, the direction of policy is clear: carbon costs will increase. Companies in energy-intensive industries, natural resources, or manufacturing should begin incorporating carbon pricing scenarios into their financial planning now.
Critically for multinational companies, the EU-Indonesia Comprehensive Economic Partnership Agreement (IEU CEPA), finalised in September 2025, will remove tariffs on the vast majority of trade — but it also brings European supply chain and sustainability due diligence expectations into the picture for companies selling into the EU market. Social accountability and supply chain transparency, discussed further below, take on added legal weight in this context.
Security and Risk Management Strategy
Organisations seeking to enter and do business in Indonesia need to mitigate these risks by putting in place a well-planned risk management strategy to ensure from the outset that they have carried out not only an assessment of the risks, but are also well positioned to manage any situation that may present a threat to their assets — be it people, proprietary information, property or reputation. Such a strategy needs to have a number of elements in place, including but not limited to the following:
- A clear directive and security policy driven by Executive Management at headquarters level.
- A defined and enhanced security budget than would otherwise be assigned to most new start-ups.
- A dedicated Security Manager to manage and coordinate security needs. If not available in-house, this can be contracted to third parties with the relevant experience, local knowledge, capability and local presence.
- A Crisis Management Team (CMT) comprising key department heads, trained in their respective roles and responsibilities — now including a cybersecurity lead and an ESG compliance officer.
- A Crisis Management Center (CMC) strategically located and suitably equipped from which the CMT can operate.
- Crisis Management and Emergency Response Plans, including scenarios for natural disasters, civil disturbance, and cyber incidents — not just physical security events.
- Standard Security Operating Procedures for managing routine security duties, undertaken by both in-house and/or contracted parties.
Protection of Assets
Personnel
Human Resources are a key asset within most organisations and as such need to be protected. In order to obtain a maximum return from one’s employees, it is necessary to create an environment whereby they can focus on the business issues, without having to concern themselves with security related issues. The organisation needs to implement a programme that provides the necessary reassurance that the company is looking after their interests and well-being, including that of their dependants.
In order to minimise the risk to employees, whether expatriate or local national, a personnel security programme needs to be established and a number of pro-active procedures and measures implemented or made available, including:
- Identification of appropriate and secure accommodations, which may entail a survey of possible apartments and then independent security audits of the specific residence. It is also recommended to have domestic staff trained in security awareness techniques — from information security to how to respond to an incident.
- Security Awareness Briefings for expatriates newly arrived in country, existing employees at all levels, and domestic staff and drivers.
- Access to daily risk reports so that all those in country have an ongoing understanding and awareness of the relevant issues that may have a security implication.
- For traveling executives who may feel threatened or who are not familiar with the local environment, the ability to call upon a reliable resource to provide vehicles with trained security drivers and low-profile security officers.
- In cases where internal disputes arise and key corporate personnel are ‘targeted’, appropriate support and reassurance must be provided promptly.
Information Security and Cybersecurity
Information — whether proprietary or otherwise — has value and is in need of protection. In a competitive market with a limited number of firms competing closely for the same projects, relationships at all levels are developed and as such can lead to information being compromised, usually for financial gain. Typical examples include a clerk passing proprietary information to an external party or, in the digital age, the unauthorised access, deletion, or exfiltration of data from company systems.
What has changed dramatically since this article was first published is both the scale and sophistication of the threat. Indonesia has become one of the most actively targeted digital environments in Asia. Ransomware-as-a-Service operations, Advanced Persistent Threat (APT) groups, and state-affiliated actors have all demonstrated an active interest in Indonesian corporate and government systems. Supply chain compromise — where attackers infiltrate a trusted vendor to gain access to the ultimate target — is now a documented and growing vector.
The field of Computer Forensics remains critical and its role has expanded. Where once the goal was primarily to understand the scope of an internal theft, today forensic capability must encompass the investigation of ransomware incidents, data exfiltration, cloud infrastructure breaches, and regulatory compliance documentation. In light of Indonesia’s PDP Law, organisations now face legal obligations to identify, report, and demonstrate remediation of data breaches — forensic capability is no longer optional.
Key additions to any information security programme in Indonesia today should include:
- A formal cybersecurity framework aligned to international standards (ISO 27001 or NIST).
- Regular penetration testing and red-team exercises.
- Multi-factor authentication across all systems, with particular attention to remote access.
- A tested incident response plan that includes regulatory notification procedures under the PDP Law.
- Employee training on phishing, social engineering, and deepfake-based attacks — a rapidly growing threat in the Indonesian business environment.
- Third-party vendor cyber risk assessments as part of the procurement and vendor management process.
Protection of Property
Indonesia has experienced a history of bombings, civil unrest, and criminal damage targeting both government facilities and commercial operations. While the frequency of large-scale terrorist bombings has diminished compared to the peak of the early-to-mid 2000s, the threat from extremist groups has not been eliminated, and vigilance remains necessary.
Companies involved in the storage, distribution, or manufacturing of products continue to face threats of product theft, pilferage, sabotage, and arson — particularly where there are labour-related disputes. Counterfeiting and parallel operations by disaffected employees or entrepreneurial competitors remain concerns.
Natural disaster risk — now more prominent than ever — should also be incorporated into property protection planning. Site-specific threat assessments should now include seismic and flood risk alongside criminal and civil threat assessments. Appropriate insurance coverage must include terrorist acts and, increasingly, climate-related events.
Reputation, Social Accountability, and Compliance
From a business standpoint, Indonesia presents numerous concerns for organisations that wish to protect their reputation rather than merely their physical assets. These include:
- Lack of transparency and inconsistent corporate governance
- Poor regulatory environment and regulatory reversals
- Widespread corruption
- Overvalued assets
- Organised crime, money laundering, counterfeiting, and trafficking
- Conflicts of interest and fraud
- Theft of proprietary information
- Industrial disputes and militant labour activity
- ESG compliance failures and supply chain reputational exposure(new)
- *Cyber incidents and data breaches(new)
- Climate-related liability and environmental regulatory non-compliance(new)
This is an era where organisations have legal obligations to their employees, stakeholders, and regulators — with potentially serious ramifications for non-compliance. The ESG dimension of this has accelerated sharply. Under Indonesia’s new Sustainability Disclosure Standards and the EU-Indonesia CEPA framework, companies can expect greater external scrutiny of their supply chains, environmental performance, and human rights practices.
Employment Screening
Whether to hire a particular employee is one of the most critical business decisions a company makes. Recruiting new staff members based on personal recommendations and appearance is not enough. In Indonesia, where there remains a history of job placement through nepotism and a persistent market in falsified qualifications, objective and comprehensive screening of candidates prior to employment is essential.
Employment screening services safeguard a corporation from hiring persons who are either unqualified or of questionable integrity. It is recommended to screen both existing and new employees at all levels. The extent and level of screening is determined by the nature of the position to be filled.
A note for 2026: As companies in Indonesia expand their digital and technology functions, screening should be extended explicitly to cover candidates with access to IT infrastructure, data systems, and financial platforms — roles that carry heightened risk of insider threat in the current cybersecurity environment.
The overall objective of employment screening is to:
- Identify inconsistencies, fabrications, omissions or exaggerations in a candidate’s résumé.
- Confirm previous working experience and highlight any character weaknesses.
- Reveal any previously recorded occasions of misconduct which could embarrass the employer or damage its credibility.
Due Diligence
The future problems that will result from the choice of an unsuitable business partner should not be underestimated. Profiling the background, standing, ownership and reputation of prospective business partners is an essential first stage in the due diligence process.
Due diligence is recommended at two consecutive levels:
- A basic check on the company or individual through publicly available information and database resources — a preliminary review to focus subsequent enquiries.
- A thorough check that expands enquiries to provide tangible proof of existence and an accurate appraisal of reputation, business standing, and financial status.
Indonesia presents specific challenges in this regard. Records in Indonesia are poor. Few records are required to be kept, and those that are maintained are often incomplete or unreliable. In most instances records are not centrally held and are rarely fully digitised. Local expertise and a significant amount of direct enquiry are required to conduct effective due diligence.
A 2026 addition: Due diligence on potential partners and vendors should now include an assessment of their cybersecurity posture and data protection practices, particularly if they will handle sensitive company or customer data. Cyber risk in the supply chain is a documented and growing exposure in Indonesia.
Vendor Auditing
As in many Asian countries, irregularities in purchasing and other fraudulent insider schemes are common in Indonesia. The overall aim of a vendor auditing programme is to ensure complete transparency in the supply chain — to ensure suppliers are legitimate and ethical, remove the possibility of bogus companies and conflicts of interest, prevent collusion between company employees and vendors, and demonstrate commitment to eliminating fraud within the procurement function.
The difficulty in implementing an effective vendor-auditing programme is that the people who may be defrauding a company can be the very same people entrusted with the checking. The use of an outside service provider removes this risk.
Social Accountability Auditing
From sweatshops and child labour to environmental damage and unsafe working conditions, subcontractors of large multinational corporations have the ability to do immense damage to the reputations — and bottom lines — of the companies who contract them. This risk has, if anything, intensified. The EU-Indonesia CEPA, combined with growing international ESG reporting requirements, means that supply chain conduct is now subject to more structured external scrutiny than at any previous point.
A Social Accountability Programme should go beyond initial certification. Regular compliance monitoring is essential and should cover:
- Adherence to local laws and international standards
- Company labour policy standards (compensation, working hours)
- Environmental standards and climate-related commitments
- Health and safety standards
- Cybersecurity and data handling standards for vendors with access to systems or sensitive data(new)
Indonesia has a large manufacturing base with factories often located in remote places. Those that feel least under scrutiny are the ones that often need the closest monitoring by local, knowledgeable, and independent risk management professionals.
Summary and Conclusion
Indonesia remains an attractive country in which to do business for many investors. Its population of over 280 million, a growing middle class, a young digital-native workforce, and abundant natural resources continue to present genuine opportunities. The IEU CEPA and Indonesia’s ambition to reach high-income status by 2045 signal continued openness to foreign investment.
However, the risk landscape has evolved considerably since this article was first published. The foundational risks — regulatory opacity, corruption, a challenging legal system, militant labour dynamics, and property security — remain. To these have been added a new generation of threats: sophisticated cybersecurity attacks on a scale unprecedented in Indonesian history; fiscal and macroeconomic pressures under the Prabowo administration; the physical and financial consequences of climate-related disasters; and a rapidly expanding ESG and sustainability compliance environment with real legal teeth.
In order to reduce vulnerability to this broadened set of risks, companies must take a pro-active approach to security and risk management. Doing so naturally reduces the chances of becoming a victim, and minimises the likely fallout in the event an incident does occur. An effective risk prevention and mitigation plan — one that now spans physical security, cybersecurity, ESG compliance, and climate resilience — will enable a company to effectively respond, recover and resume normal business operations within the shortest possible time frame, minimising business impact whether financial or reputational.
Original article written by Nick Duder of PT Hill Konsultan Indonesia (Hill and Associates). Updated and expanded in June 2026 to reflect current political, economic, regulatory, cybersecurity, ESG, and climate conditions.















