PT Terminal Petikemas Surabaya (TPS), one of Indonesia’s leading container terminal operators under Pelindo’s subholding Pelindo Terminal Petikemas (SPTP), has stepped up its cybersecurity efforts as digital threats loom large over Indonesia’s port operations.
In an online seminar held Thursday (June 26), TPS gathered 127 personnel from across the SPTP network, from Belawan in the west to Merauke in the east, to deepen understanding of cyber threats, particularly the elusive and increasingly common fileless malware.
“Cyber attacks today are not just a possibility, they are a reality,” said Arjo Dedali, TPS’s Senior Vice President of Information Technology. “We’re not waiting to be targeted. We’re building awareness and resilience now.”
The webinar, part of an ongoing digital security initiative by SPTP, was opened by TPS Director of Finance, HR, and Risk Management, Sapto Wasono Soebagio. It featured a keynote presentation from M. Riyan Syaifunahar, Lead Coordinator of Cyber Security at PT Integrasi Logistik Cipta Solusi (ILCS).
Syaifunahar warned that fileless malware poses a serious and often overlooked threat. Unlike traditional malware, fileless attacks operate in-memory, leaving little to no trace on hard drives and making them exceptionally difficult to detect.

“These attacks can slip past standard antivirus tools,” he said. “They hijack legitimate system processes to execute malicious code. That makes them stealthy and dangerous.”
He cited several prominent examples, including the notorious FIN7 (Carbanak) and Lazarus Group attacks, both linked to sophisticated, state-backed operations targeting financial institutions and multinational firms. The webinar also examined lesser-known variants like Poweliks and Astaroth (Guildma), which exploit vulnerabilities in Microsoft Office and Windows Management Instrumentation (WMI).
Syaifunahar outlined red flags for identifying potential infections: unexplained PowerShell activity, Office applications triggering command line processes, abnormal network behavior, and surging CPU or memory use without a discernible cause.
The fallout from such attacks, he added, is significant, ranging from data breaches and operational disruption to financial losses and reputational damage.
To mitigate the risks, he urged participants to adopt a multi-layered approach: disabling macro scripts, strengthening system patching, deploying Endpoint Detection and Response (EDR) tools, logging and monitoring system behavior, and enforcing the principle of least privilege in network access.

TPS, which operates both international and domestic container terminals at the busy Port of Tanjung Perak, has increasingly relied on digital systems to streamline logistics and port operations.
The company reported a throughput of 1.58 million TEUs in 2024. As of May 2025, it had already handled 632,567 TEUs. TPS continues to hold a dominant position in international container traffic at Tanjung Perak, capturing an 83% market share.
“As we grow our digital footprint, cybersecurity must grow with it,” said Dedali. “This is about protecting not just our systems, but the trust of the global trade community.”

