Logo
Cybersecurity

Cybersecurity Careers Should Start Before University

If students first discover cybersecurity when they’re applying for jobs, we’ve already lost several useful years.

ITSEC AsiaITSEC Asia
|
Sep 07, 2026
Cybersecurity Careers Should Start Before University

Ask a teenager what jobs exist in technology and you’ll probably hear programmer, software engineer or perhaps data scientist. Ask about cybersecurity and the picture can become considerably fuzzier. Maybe “hacker” makes an appearance, usually wearing an imaginary hoodie.

That perception matters because Indonesia needs a much larger pool of people who see cybersecurity as a realistic career before they have to choose one.

Komdigi has started pushing cybersecurity education further down the talent pipeline. In May, its Digital Human Resources Development Agency provided Basic Cyber Security training to 124 students at SMKN 2 Depok, covering digital security awareness and preparation for a technology-driven workplace.

The direction is also appearing internationally. NIST’s NICE program updated its September webinar on 2 September with a specific focus on preparing students for future cyber careers. One part examines how K–12 education can introduce skills connected to immediate workforce realities such as cloud security and generative AI.

Cybersecurity education is moving earlier because the work itself isn’t waiting.

Exposure Before Specialisation

Starting earlier doesn’t mean asking 15-year-olds to become penetration testers before their next mathematics exam.

The first objective is exposure.

Students can begin with concepts that make cybersecurity tangible and show them what the profession actually involves:

  • How networks and digital identities work
  • Why systems become vulnerable
  • How phishing and social engineering manipulate people
  • What happens during a cyber incident
  • How defenders investigate suspicious activity
  • Why cloud and AI systems create different security questions

Once students understand the problems cybersecurity professionals solve, the career becomes less abstract.

Indonesia already has a natural entry point through vocational education. Komdigi’s Vocational Blended Learning program has also been assessing SMK students against SKKNI-based competencies. During June alone, 99 students from six vocational schools in Bekasi participated in competency certification across several digital disciplines.

The Gap Between Knowing and Doing

Exposure, however, eventually has to become practice.

A student can memorize what phishing is in roughly the time it takes to finish a cup of coffee. Recognising a convincing phishing attempt, investigating where it came from and deciding what to do next requires a different kind of learning.

That’s why practical environments matter as students progress. Labs, simulations, competitions and cyber ranges allow learners to turn concepts into observable skills.

Komdigi made a similar point when supporting the Country-to-Country Capture the Flag competition in Bali in August. The event brought together 81 participants from 13 countries to test technical abilities against cybersecurity scenarios rather than simply discuss them.

The talent pipeline becomes stronger when those experiences connect: early exposure creates interest, structured learning builds foundations and realistic practice develops capability.

That progression is also relevant to ITSEC Cyber & AI Academy. Practical cybersecurity and AI training can provide the next step for learners and professionals who need to turn foundational knowledge into skills they can use in real working environments.

Indonesia needs millions more digital talents by 2030. Waiting until people enter the workforce before introducing cybersecurity makes that challenge unnecessarily harder.

Sometimes the first cybersecurity lesson needs to happen while there’s still a school bell at the end of it.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: Komdigi: Basic Cyber Security Training for SMK Students, 21 May 2026 · NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers, updated 2 September 2026 · BPT Komdigi: Vocational Blended Learning Certification, 3 July 2026 · Komdigi: C2C-CTF 2026

Share this post

You may also like

Cybersecurity Indonesia: Rising Cyber Threats and the Importance of a Strong Digital Security Strate
Cybersecurity

Cybersecurity Indonesia: Rising Cyber Threats and the Importance of a Strong Digital Security Strate

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Indonesia is facing a growing risk of ransomware attacks, phishing campaigns, data breaches and digital infrastructure exploitation that can impact business operations, public services and customer trust. In recent years, sectors including government, financial services, manufacturing, education and digital platforms have become major targets of cyber attacks. As one of the leading cybersecurity companies in Indonesia, ITSEC Asia provides cybersecurity services designed to help organizations strengthen cyber resilience and protect against evolving digital threats. -------------------------------------------------------------------------------- WHY CYBERSECURITY INDONESIA HAS BECOME A NATIONAL PRIORITY Cybersecurity Indonesia is no longer just a technical concern. Cybersecurity has become a critical component of business resilience and national digital security. Indonesia’s fast-growing digital economy is driving organizations to adopt new technologies at a rapid pace. At the same time, cyber threats continue to evolve through: * Ransomware attacks targeting organizations * Customer and sensitive data breaches * AI-powered phishing and social engineering * Cloud infrastructure attacks * Web and mobile application exploitation * Threats against critical infrastructure Organizations across Indonesia are increasingly recognizing that cyber attacks are

ITSEC AsiaITSEC Asia
|
Mei 07, 2026 4 minutes read
Vulnerability Assessment vs Penetration Testing: What's the Difference and Why Does It Matter?
Cybersecurity

Vulnerability Assessment vs Penetration Testing: What's the Difference and Why Does It Matter?

When discussing cybersecurity assessments, two terms are often used interchangeably: Vulnerability Assessment and Penetration Testing. While both approaches aim to improve an organization's security posture, they serve different purposes and provide different types of insights. Understanding the distinction between the two is important for organizations looking to prioritize risks, strengthen defenses and make better security decisions. Rather than asking which one is better, the more relevant question is: When should you use each approach, and how can they work together? WHAT IS A VULNERABILITY ASSESSMENT? A Vulnerability Assessment is the process of identifying and evaluating security weaknesses across systems, networks, applications and other digital assets. The primary objective is to discover vulnerabilities before attackers do. WHAT HAPPENS DURING A VULNERABILITY ASSESSMENT? A typical Vulnerability Assessment may include: * Asset discovery. * Automated vulnerability scanning. * Risk classification and prioritization. * Identification of outdated software and misconfigurations. * Reporting and remediation recommendations. The result is a broad view of potential weaknesses that require attention. STRENGTHS OF VULNERABILITY ASSESSMENTS Organizations often conduct Vulnerability Assessments

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read
Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside
Cybersecurity

Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

INTRODUCTION Here is a question every security leader should sit with: if an attacker entered your network six months ago, would you know? According to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach now stands at 194 days, nearly half a year of undetected attacker activity operating freely within enterprise infrastructure. Prevention tools, no matter how sophisticated, have already demonstrated they cannot close that window on their own. Firewalls, antivirus software, and multi-factor authentication are necessary. They are not sufficient. The organizations that understand this distinction are the ones investing in threat hunting: the proactive, intelligence-driven practice of searching for adversaries who have already bypassed the perimeter and are operating in silence. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works with organizations across these regions to build this exact capability before the next breach makes it urgent. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] THE GAP THAT REACTIVE SECURITY CANNOT CLOSE The fundamental flaw in

|
Mei 12, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe