Aditia Nugroho, Hari Ginardi
Jurnal Indonesia Sosial Teknologi, Vol. 5, No. 8, August 2024 3722
Introduction
In the era of Volatility, Uncertainty, Complexity, and Ambiguity (VUCA) which
describes the business environment is affected by rapid changes, external uncertainty, the
complexity of problems and often unpredictable unclarity (Nugroho, 2024). Digital
transformation (DT) is one of the strategies for answering various challenges and business
sustainability. Digital transformation is the fundamental process of how organizations
utilize information technology (IT) to improve performance, efficiency and innovation.
The level of adaptation of a company in the era of disruption is greatly influenced by the
level of digital transformation and innovation (Škare & Soriano, 2021).
In the implementation of digital transformation, PT Krakatau Steel Tbk as one of
the State-Owned Enterprises (SOEs) companies engaged as the largest and integrated
steel producer in Indonesia continues to strive for the development of information
technology consistently and sustainably to realize the vision of becoming a competitive,
profitable and reliable corporation and realize the company's mission in realizing
productive and efficient operational performance in producing products and services
quality (Tan, Ambouw, & Kustiwi, 2024). The digitalization that has been carried out
brings a lot of business operational benefits, especially added value to customers, but it
also raises several new challenges to the technological dimension, namely the increasing
dependence on information technology in the operational aspect of services, making
organizations vulnerable to cyberattacks and the risk of information security breaches
such as viruses and data leaks that cause financial impacts (Shiau, Wang, & Zheng, 2023)
The results of a survey conducted on chief audit executives from shared countries and
industries in Europe (Aqil & Khalid, 2024) showed that as many as 82% of respondents
said that data security risks and cyber vulnerabilities are still the number one threat and
will still occur in the next three years. Inequality in the application of information
technology and increasing vulnerability to information security threats in the government
sector and the business world are some of the world's main risks in the next two to five
years, along with many other cyber threats such as ransomware. Information security and
IT governance are two important aspects of information management in an organization.
The two are closely related and influence each other. Effective governance plays an
important role in ensuring information protection and security in an organization or
country, information security failures can affect the organization's finances and image
(Petroye, Liulov, Lytvynchuk, Paida, & Pakhomov, 2020).
IT governance is the process of managing information effectively to achieve
organizational goals (Noorhasanah, Winarno, & Adhipta, 2015). This involves setting
policies, procedures, and practices related to information management (Alayida, Aisyah,
Deliana, & Diva, 2023). Good IT governance will include policies and procedures related
to aspects of information security. On the other hand, effective information security
requires good governance to manage risk and ensure compliance with established policies
and procedures (Oktarina, 2022). Based on the new regulation of the Ministry of SOEs
number PER-2/MBU/03/2023 CHAPTER VII article 208 of the implementation of
information technology, it is stated that SOEs are obliged to maintain cyber security by