Skip to main content
Threat level elevated · ASEAN financial sector

We break into your systems before someone else does.

BorneoSec is an Indonesian offensive security firm. We deliver penetration testing, red teaming, and incident response for banks, government agencies, and energy operators that cannot afford to be wrong about their defences.

Organizations trusted
500+ Organizations trusted
CVEs credited
38 CVEs credited
Findings remediated
12.4k Findings remediated
Incident response
24/7 Incident response
engagement · live
edge-vpn-01 dmz-web jump-host ad-replica core-db backup-nfs DC-01
Critical Domain admin obtained via unconstrained delegation
4h 12m
High Exposed API allows account enumeration at scale
6h 48m

Accredited & certified

ISO/IEC 27001 CREST Member PCI DSS QSA OSCP · OSEP · CRTO BSSN Registered

Trusted at scale

Over 500 organizations rely on our findings.

From national banks to regional energy operators, security and risk leaders across ASEAN use our engagements to make defensible decisions.

Organizations trusted
500+ Organizations trusted Across ASEAN since 2019
Vulnerabilities remediated
12,400+ Vulnerabilities remediated Validated & retested
CVEs credited
38 CVEs credited Published by our research lab
Critical finding SLA
< 4h Critical finding SLA Escalated same business day

Selected clients across regulated sectors

Bank Nusantara Kalimantan Energi Telkomsa Garuda Fintech PLN Regional Sawit Global MediCare ID Pertamina Hilir BPJS Digital Astra Logistics
  • ISO/IEC 27001
  • CREST Member
  • PCI DSS QSA
  • OSCP · OSEP · CRTO
  • BSSN Registered

About BorneoSec

An offensive security firm built in Kalimantan, trusted across Indonesia.

PT Borneo Secode Digital was founded in 2019 by practitioners who spent their careers inside Indonesian banks, auditors, and state enterprises. We saw the same problem repeatedly: organisations were buying scan reports and calling them security assessments.

BorneoSec was built to close that gap. Our consultants perform genuinely manual, objective-driven testing and hand back evidence that engineering teams can act on and that auditors will accept without translation.

Today we operate from Banjarbaru with delivery teams in Jakarta and regional partnerships in Singapore, supporting the sectors where a breach carries systemic consequences — financial services, government, energy, and telecommunications.

  • Adversary mindset We measure security the way attackers do — by outcome, not by control checklist.
  • Senior-only delivery No junior resourcing. Every engagement is led by a consultant with a decade of field experience.
  • Data stays in Indonesia Evidence is processed and retained on domestic infrastructure, aligned to UU PDP.

Our trajectory

  1. 19 2019 Founded in Banjarbaru by three practitioners from banking and audit backgrounds.
  2. 21 2021 First regional red team practice established; BSSN registration completed.
  3. 23 2023 Research lab launched; first CVEs credited in enterprise network products.
  4. 26 2026 Serving 500+ organizations across Indonesia and Southeast Asia.
Banjarbaru

Head Office — Kalimantan Selatan

Jakarta

Client Delivery — DKI Jakarta

Singapore

Regional Partnerships

Our Services

Full-spectrum offensive and defensive capability.

Six practice areas, delivered by the same senior team. Engagements can be scoped individually or combined into a continuous security programme.

Discuss your requirements
  • Penetration Testing

    Manual, objective-driven testing across web, mobile, API, cloud, and internal network estates — mapped to OWASP, PTES, and OJK expectations.

    • Web, API & mobile application testing
    • Internal & external network testing
    • Thick client and IoT firmware
    Learn more
  • Red Team & Adversary Simulation

    Full-scope, intelligence-led attack simulation that measures how your detection and response functions perform under real pressure.

    • MITRE ATT&CK aligned TTPs
    • Assumed breach & purple team
    • Physical and social engineering
    Learn more
  • Cloud & Kubernetes Security

    Configuration review and exploitation testing for AWS, Azure, GCP, and container platforms, including identity and privilege escalation paths.

    • IAM & privilege path analysis
    • CIS benchmark configuration review
    • Container escape & supply chain
    Learn more
  • Governance, Risk & Compliance

    Readiness and audit support for ISO/IEC 27001, PCI DSS, OJK POJK 11/2022, and UU PDP with practical, engineering-first remediation.

    • ISO 27001 & PCI DSS readiness
    • UU PDP privacy gap assessment
    • Third-party risk assessment
    Learn more
  • Incident Response & Forensics

    24/7 retainer-backed containment, digital forensics, and root-cause analysis delivered by responders based in-region.

    • Ransomware containment & recovery
    • Host & memory forensics
    • Threat hunting and eradication
    Learn more
  • Security Engineering & Training

    Secure SDLC enablement, code review, and hands-on offensive training that upskills your internal engineering and blue teams.

    • Secure code review
    • Developer secure coding labs
    • Blue team detection engineering
    Learn more

Why Choose Us

Why regulated enterprises keep coming back.

Most security vendors sell coverage. We sell certainty — findings you can reproduce, prioritise, fix, and prove closed.

01

Operators, not scanner jockeys

Every engagement is executed by OSCP, OSEP, and CRTO-certified consultants. Automated tooling supports our work — it never replaces it.

02

Evidence you can act on

Reports include reproducible proof-of-concept steps, business-impact ratings, and remediation code samples your engineers can apply immediately.

03

Regulator-ready deliverables

Documentation is structured for OJK, BSSN, Kominfo, and external auditors, reducing the effort your compliance team spends translating findings.

04

In-region data sovereignty

All engagement data is processed and stored on Indonesian infrastructure, aligned with UU PDP and sector-specific residency requirements.

05

Free remediation retest

Every engagement includes a complete retest cycle within 90 days so you can prove closure to your board and your auditors.

06

Research-led capability

Our lab publishes original vulnerability research and detection tooling, so our tradecraft reflects the current threat landscape.

The typical vendor report

  • Automated scanner output with minimal triage
  • Generic remediation advice copied from a knowledge base
  • Findings ranked by CVSS alone, with no business context
  • Retest billed as a separate engagement
  • Offshore delivery team you never speak to

The BorneoSec engagement

  • Manual exploitation by certified senior consultants
  • Remediation guidance with working code samples
  • Risk rated on CVSS v4 plus real business impact
  • Full retest and attestation letter included
  • Direct access to the consultants who did the work

Methodology

A six-phase process, documented end to end.

Every engagement follows the same disciplined lifecycle, aligned to internationally recognised frameworks so results are repeatable and defensible.

PTES OWASP ASVS MITRE ATT&CK NIST SP 800-115 OSSTMM
  1. 01

    Scoping & Rules of Engagement

    We define objectives, critical assets, threat scenarios, and escalation paths with your stakeholders before a single packet is sent.

  2. 02

    Reconnaissance & Threat Modelling

    OSINT, attack-surface mapping, and sector-specific threat intelligence establish how a real adversary would approach your organisation.

  3. 03

    Exploitation & Post-Exploitation

    Manual exploitation, privilege escalation, and lateral movement — safely executed and continuously logged for full auditability.

  4. 04

    Analysis & Business Impact Rating

    Findings are triaged with CVSS v4 plus a business-impact layer so leadership can prioritise on risk, not raw severity counts.

  5. 05

    Reporting & Executive Debrief

    You receive a technical report, an executive summary, and a live walkthrough with the consultants who performed the work.

  6. 06

    Remediation Support & Retest

    We advise your engineers throughout remediation, then formally retest and issue an attestation letter for auditors.

What you receive

Every engagement concludes with a documentation set designed for three different audiences: your engineers, your executives, and your auditors.

  • Technical findings report Reproducible PoC per finding
  • Executive summary Risk posture in business language
  • Retest attestation letter Auditor-ready evidence of closure
  • Live debrief session Q&A with the delivery consultants

Industries

Sector expertise where the stakes are highest.

Regulatory context matters as much as technical depth. Our consultants understand the supervisory expectations that apply to your sector.

Banking & Financial Services

POJK-aligned testing for core banking, mobile banking, and payment switching environments.

Government & Public Sector

BSSN-aligned assessments for national and regional digital services and citizen data platforms.

Energy, Mining & Utilities

OT/ICS and IT-OT boundary testing for Kalimantan's resource and power operators.

Telecommunications

Core network, BSS/OSS, and subscriber platform security for carriers and ISPs.

Healthcare

Clinical system, EMR, and medical device assessments protecting patient data.

Technology & Fintech

Continuous testing that keeps pace with high-velocity product and platform teams.

Leadership

Founded by practitioners who still test.

Our leadership team came from the red teams, audit floors, and research labs of Indonesia's most regulated organisations.

Portrait of Rizky Ardhana Nugraha, Co-Founder & Chief Executive Officer at BorneoSec RN

Rizky Ardhana Nugraha

Co-Founder & Chief Executive Officer

Fifteen years leading offensive security programmes for Indonesian tier-one banks and state enterprises. Former head of red team at a national payment provider.

  • OSCP
  • CISSP
  • ISO 27001 LA
Request an introduction
Portrait of Aditya Pratama Wibowo, Co-Founder & Chief Technology Officer at BorneoSec AW

Aditya Pratama Wibowo

Co-Founder & Chief Technology Officer

Vulnerability researcher with 20+ credited CVEs across enterprise network and virtualisation products. Builds the tooling behind our red team practice.

  • OSEP
  • OSWE
  • CRTO
Request an introduction
Portrait of Siti Nurhaliza Rahmawati, Co-Founder & Chief Operating Officer at BorneoSec SR

Siti Nurhaliza Rahmawati

Co-Founder & Chief Operating Officer

Leads delivery governance, regulatory alignment, and client assurance. Previously led IT audit for a multinational mining group in Kalimantan.

  • CISA
  • CRISC
  • PCI QSA
Request an introduction

Insights

Field notes from our consultants.

Practical guidance on Indonesian regulatory expectations, offensive tradecraft, and defensive engineering.

All insights

Common questions

What clients ask before we start.

If your question isn't covered here, our engagement leads will answer it directly on an introductory call.

How quickly can an engagement start?

Standard penetration tests are typically scheduled within 10 business days of a signed statement of work. Incident response retainer clients receive same-day mobilisation.

Where is our engagement data stored?

All evidence, findings, and reports are processed and retained on Indonesian infrastructure with encryption at rest, aligned to UU PDP requirements.

Do you provide a retest after remediation?

Yes. Every fixed-scope engagement includes one full remediation retest within 90 days and a formal attestation letter suitable for auditors.

Can you support OJK or BSSN audit requirements?

Our deliverables are structured for regulator submission, and our consultants routinely join audit interviews to explain findings and remediation evidence.

Start an engagement

Let's find out what an attacker would find first.

Tell us about your environment and objectives. An engagement lead — not a sales representative — will respond within one business day with a scoped proposal.

Email
hello@borneosec.co.id

General & new engagement enquiries

Incident hotline
soc@borneosec.co.id

Active incident — monitored 24/7

Telephone
+62 811 5800 100

Mon–Fri, 08:00–18:00 WITA

Head office

Jl. Ahmad Yani Km 5, Sungai Besar

Banjarbaru, Kalimantan Selatan 70714

Enquiries are encrypted in transit and stored on Indonesian infrastructure.