Information Technology Risk Management For Malware And Ransomware Attacks In Banking Using Cobit 5 Framework

Authors

  • Nur Akhmad Van Jouvi Perbanas Institute
  • Fathur Rahman Perbanas Institute
  • Mercurius Broto Legowo Perbanas Institute

Keywords:

malware, It risk management, COBIT 5, Indonesian Banking, cybersecurity governance

Abstract

The rise of malware and ransomware attacks targeting the banking sector has emerged as a critical threat to financial data integrity and service continuity. Indonesian banking institutions, including Bank Rakyat Indonesia (BRI) and Bank Syariah Indonesia (BSI), have experienced significant cyber incidents in recent years, highlighting the urgent need for a structured IT risk management approach. This study aims to analyze malware and ransomware risks in the Indonesian banking sector using the COBIT 5 framework as the primary governance reference. A qualitative case study method was employed, examining real-world incidents and mapping identified risks against relevant COBIT 5 domains, including EDM03, APO12, APO13, BAI06, DSS05, and DSS04. The analysis identifies four key risk categories: malware infection, ransomware attacks, malware-induced data breaches, and insider threats. Each risk is assessed based on probability and impact levels, followed by mitigation strategies and Key Risk Indicators (KRIs) with measurable thresholds. The findings demonstrate that COBIT 5 provides a comprehensive and structured governance approach to address escalating cyber threats in the banking sector. This study contributes practical risk management guidance aligned with Indonesian financial regulatory requirements under OJK supervision.

Downloads

Published

2026-06-26