Indonesian organizations were moving critical data into M365, Entra ID and Salesforce faster than they were protecting it — and the PDP Law made where that data sits a board-level question. Local availability let them adopt BaaS without trading away sovereignty.
The response has been sharper than expected. Most teams had assumed Microsoft was backing this up. The question we now get most is: if Entra ID is the compromised system, what recovers first?