JICT Tests Cyber Recovery Within 21-Hour Limit

The Indonesia’s leading container terminal tested cyber incident recovery, operational continuity and crisis communication, with exercises designed to restore services within a 21-hour target

PT Jakarta International Container Terminal (JICT) conducted a cyber incident response exercise on Friday to test its ability to recover systems and maintain terminal operations following a disruption.

The 2026 Cyber Incident Response & CBDR Drill, held under the theme “21 Hours to Recover – From Incident to Recovery,” covered system recovery, operational continuity and crisis communication, the company said.

JICT President Director Ade Hartono said cyber resilience should be treated as part of the terminal’s broader operational resilience rather than solely as an information technology function.

“The exercise tests not only how quickly systems are restored, but also how quickly the organization makes decisions, keeps operations under control, manages communication and ensures end-to-end service functionality,” Ade said in Jakarta on Friday, September 18.

He said system restoration would be followed by a validation process before operations could be considered fully restored.

The validation covers users and business processes, including applications, databases, connectivity, system integration and operational transactions, to ensure they are functioning properly, the company said.

“An active system does not automatically mean services have been restored. All elements within JICT must validate services and ensure that all ‘return to normal’ criteria are met,” Ade said.

The exercise also involved coordination between JICT and TPK Koja to test connectivity and integration between their systems.

Recovery performance during the drill was measured against a Recovery Time Objective (RTO) of no more than 21 hours.

Ade said the exercise was intended to ensure employees understood their roles during a disruption and that decisions could be made quickly while terminal operations remained under control.

“Cyber resilience is not something built only after an incident occurs. It must be prepared, tested and continuously improved,” he said.