Skip to main content
Threat level elevated · ASEAN financial sector

We Find the Weaknesses Before Attackers Do.

BorneoSec is an Indonesian cybersecurity initiative focused on offensive security, vulnerability research, and practical security assessment. We help organizations identify, understand, and reduce security risks before they become real-world incidents.

Organizations trusted
500+ Organizations trusted
Findings remediated
1000+ Findings remediated
Incident response
24/7 Incident response
engagement · live
edge-vpn-01 dmz-web jump-host ad-replica core-db backup-nfs DC-01
Critical Domain admin obtained via unconstrained delegation
4h 12m
High Exposed API allows account enumeration at scale
6h 48m

Trusted at scale

Over 500 organizations rely on our findings.

From national banks to regional energy operators, security and risk leaders across ASEAN use our engagements to make defensible decisions.

Organizations trusted
500+ Organizations trusted Across Wordwide since 2019
Vulnerabilities remediated
1,000+ Vulnerabilities remediated Validated & retested
Critical finding SLA
< 4h Critical finding SLA Escalated same business day

Selected clients across regulated sectors

Bank Nusantara Kalimantan Energi Telkomsa Garuda Fintech PLN Regional Sawit Global MediCare ID Pertamina Hilir BPJS Digital Astra Logistics
  • BSSN Registered

About BorneoSec

An offensive security firm built in Kalimantan, trusted across Indonesia.

PT Borneo Secode Digital is an Indonesian cybersecurity company founded by Rahmadhani NovianJaya and Muhammad Zaid Ghiffari, with a focus on offensive security, vulnerability research, and practical security assessment.

We believe that effective security assessment goes beyond automated scanning and checklist-based reviews. BorneoSec takes an adversary-focused approach to security, combining technical testing and vulnerability research to identify weaknesses that may expose organizations to real-world attacks.

Our assessments are designed to provide clear technical evidence, practical risk analysis, and actionable recommendations that help organizations understand and improve their security posture. BorneoSec provides cybersecurity services across application security, infrastructure security, vulnerability assessment, penetration testing, security research, and security consulting.

  • Adversary mindset We approach security from an attacker's perspective — focusing on how vulnerabilities can be discovered, chained, and exploited in real-world scenarios.
  • Senior-only delivery No junior resourcing. Every engagement is led by a consultant with a decade of field experience.
  • Responsible Research We conduct vulnerability research and responsible disclosure with a focus on improving the security of applications, systems, and digital services.

Our trajectory

  1. 19 2019 BorneoSec was established by Rahmadhani NovianJaya and Muhammad Zaid Ghiffari with a focus on cybersecurity and offensive security.
  2. 21 2021 BorneoSec continued developing its capabilities in penetration testing, vulnerability assessment, and security research.
  3. 25 2025 BorneoSec gained wider public recognition through coverage across various media outlets for its cybersecurity research and security findings.
  4. 26 2026 Continuing to expand its cybersecurity services, research capabilities, and security expertise to support organizations across Indonesia.
Sampit

Head Office

Our Services

Full-spectrum offensive and defensive capability.

Six practice areas, delivered by the same senior team. Engagements can be scoped individually or combined into a continuous security programme.

Discuss your requirements
  • Penetration Testing

    Manual, objective-driven testing across web, mobile, API, cloud, and internal network estates — mapped to OWASP, PTES, and OJK expectations.

    • Web, API & mobile application testing
    • Internal & external network testing
    • Thick client and IoT firmware
    Learn more
  • Red Team & Adversary Simulation

    Full-scope, intelligence-led attack simulation that measures how your detection and response functions perform under real pressure.

    • MITRE ATT&CK aligned TTPs
    • Assumed breach & purple team
    • Physical and social engineering
    Learn more
  • Cloud & Kubernetes Security

    Configuration review and exploitation testing for AWS, Azure, GCP, and container platforms, including identity and privilege escalation paths.

    • IAM & privilege path analysis
    • CIS benchmark configuration review
    • Container escape & supply chain
    Learn more
  • Governance, Risk & Compliance

    Readiness and audit support for ISO/IEC 27001, PCI DSS, OJK POJK 11/2022, and UU PDP with practical, engineering-first remediation.

    • ISO 27001 & PCI DSS readiness
    • UU PDP privacy gap assessment
    • Third-party risk assessment
    Learn more
  • Incident Response & Forensics

    24/7 retainer-backed containment, digital forensics, and root-cause analysis delivered by responders based in-region.

    • Ransomware containment & recovery
    • Host & memory forensics
    • Threat hunting and eradication
    Learn more
  • Security Engineering & Training

    Secure SDLC enablement, code review, and hands-on offensive training that upskills your internal engineering and blue teams.

    • Secure code review
    • Developer secure coding labs
    • Blue team detection engineering
    Learn more

Why Choose Us

Why regulated enterprises keep coming back.

Most security vendors sell coverage. We sell certainty — findings you can reproduce, prioritise, fix, and prove closed.

01

Operators, not scanner jockeys

Every engagement is executed by OSCP, OSEP, and CRTO-certified consultants. Automated tooling supports our work — it never replaces it.

02

Evidence you can act on

Reports include reproducible proof-of-concept steps, business-impact ratings, and remediation code samples your engineers can apply immediately.

03

Regulator-ready deliverables

Documentation is structured for OJK, BSSN, Kominfo, and external auditors, reducing the effort your compliance team spends translating findings.

04

In-region data sovereignty

All engagement data is processed and stored on Indonesian infrastructure, aligned with UU PDP and sector-specific residency requirements.

05

Free remediation retest

Every engagement includes a complete retest cycle within 90 days so you can prove closure to your board and your auditors.

06

Research-led capability

Our lab publishes original vulnerability research and detection tooling, so our tradecraft reflects the current threat landscape.

The typical vendor report

  • Automated scanner output with minimal triage
  • Generic remediation advice copied from a knowledge base
  • Findings ranked by CVSS alone, with no business context
  • Retest billed as a separate engagement
  • Offshore delivery team you never speak to

The BorneoSec engagement

  • Manual exploitation by certified senior consultants
  • Remediation guidance with working code samples
  • Risk rated on CVSS v4 plus real business impact
  • Full retest and attestation letter included
  • Direct access to the consultants who did the work

Methodology

A six-phase process, documented end to end.

Every engagement follows the same disciplined lifecycle, aligned to internationally recognised frameworks so results are repeatable and defensible.

PTES OWASP ASVS MITRE ATT&CK NIST SP 800-115 OSSTMM
  1. 01

    Scoping & Rules of Engagement

    We define objectives, critical assets, threat scenarios, and escalation paths with your stakeholders before a single packet is sent.

  2. 02

    Reconnaissance & Threat Modelling

    OSINT, attack-surface mapping, and sector-specific threat intelligence establish how a real adversary would approach your organisation.

  3. 03

    Exploitation & Post-Exploitation

    Manual exploitation, privilege escalation, and lateral movement — safely executed and continuously logged for full auditability.

  4. 04

    Analysis & Business Impact Rating

    Findings are triaged with CVSS v4 plus a business-impact layer so leadership can prioritise on risk, not raw severity counts.

  5. 05

    Reporting & Executive Debrief

    You receive a technical report, an executive summary, and a live walkthrough with the consultants who performed the work.

  6. 06

    Remediation Support & Retest

    We advise your engineers throughout remediation, then formally retest and issue an attestation letter for auditors.

What you receive

Every engagement concludes with a documentation set designed for three different audiences: your engineers, your executives, and your auditors.

  • Technical findings report Reproducible PoC per finding
  • Executive summary Risk posture in business language
  • Retest attestation letter Auditor-ready evidence of closure
  • Live debrief session Q&A with the delivery consultants

Industries

Sector expertise where the stakes are highest.

Regulatory context matters as much as technical depth. Our consultants understand the supervisory expectations that apply to your sector.

Banking & Financial Services

POJK-aligned testing for core banking, mobile banking, and payment switching environments.

Government & Public Sector

BSSN-aligned assessments for national and regional digital services and citizen data platforms.

Energy, Mining & Utilities

OT/ICS and IT-OT boundary testing for Kalimantan's resource and power operators.

Telecommunications

Core network, BSS/OSS, and subscriber platform security for carriers and ISPs.

Healthcare

Clinical system, EMR, and medical device assessments protecting patient data.

Technology & Fintech

Continuous testing that keeps pace with high-velocity product and platform teams.

Leadership

Founded by practitioners who still test.

Our leadership team came from the red teams, audit floors, and research labs of Indonesia's most regulated organisations.

Portrait of Rahmadhani NovianJaya, Co-Founder & Chief Executive Officer at BorneoSec THx17k

Rahmadhani NovianJaya

Co-Founder & Chief Executive Officer

Cybersecurity professional with 7 years of experience across the FMCG and mining industries, specializing in offensive security, penetration testing, vulnerability research, and information security.

Request an introduction
Portrait of Muhammad Zaid Ghifari, Co-Founder & Chief Hacking Officer at BorneoSec Zheev

Muhammad Zaid Ghifari

Co-Founder & Chief Hacking Officer

Security researcher and penetration tester with experience in vulnerability research, bug bounty, and offensive security. Active in cybersecurity since 2019, with multiple CVE credits and recognition from global security platforms.

Request an introduction

Insights

Field notes from our consultants.

Practical guidance on Indonesian regulatory expectations, offensive tradecraft, and defensive engineering.

All insights

Common questions

What clients ask before we start.

If your question isn't covered here, our engagement leads will answer it directly on an introductory call.

How quickly can an engagement start?

Standard penetration tests are typically scheduled within 10 business days of a signed statement of work. Incident response retainer clients receive same-day mobilisation.

Where is our engagement data stored?

All evidence, findings, and reports are processed and retained on Indonesian infrastructure with encryption at rest, aligned to UU PDP requirements.

Do you provide a retest after remediation?

Yes. Every fixed-scope engagement includes one full remediation retest within 90 days and a formal attestation letter suitable for auditors.

Can you support OJK or BSSN audit requirements?

Our deliverables are structured for regulator submission, and our consultants routinely join audit interviews to explain findings and remediation evidence.

Start an engagement

Let's find out what an attacker would find first.

Tell us about your environment and objectives. An engagement lead — not a sales representative — will respond within one business day with a scoped proposal.

Email
hello@borneosec.co.id

General & new engagement enquiries

Incident hotline
soc@borneosec.co.id

Active incident — monitored 24/7

Telephone
+62 8515 7500 418

Mon–Fri, 08:00–18:00 WIB

Head office

Jl. Samekto Barat No 33

Sampit, Kotawaringin Timur, Kalimantan Tengah 74313

Enquiries are encrypted in transit and stored on Indonesian infrastructure.