Logo
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

As AI, cloud and security automation reshape the threat environment, Indonesia faces a growing gap between the technology organizations deploy and the skills needed to secure it.

ITSEC AsiaITSEC Asia
|
Agt 27, 2026
Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace.

That gap is becoming harder to ignore.

The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%.

The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology.

New Technology Creates New Security Skills

A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities.

An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them.

A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive.

The skills organizations increasingly need include:

  • AI and AI security
  • Cloud security
  • Penetration testing
  • Threat detection and incident response
  • Security operations
  • Application and API security

The World Economic Forum's Global Cybersecurity Outlook 2026 found that 87% of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk during 2025.

As AI adoption accelerates, cybersecurity professionals are being asked to understand both sides of the technology: how it can improve defense and how it can create new attack opportunities.

Security Technology Can't Make Every Decision

More security tools can improve visibility, but they don't eliminate the need for expertise.

A vulnerability scanner can identify hundreds of findings. A security professional still needs to determine which vulnerabilities are exploitable, which systems are exposed and which issues require immediate action.

A SIEM can generate thousands of alerts. Someone still needs to investigate them, understand the context and determine whether an organization is actually under attack.

AI can help accelerate these processes, but human judgment remains part of the security equation.

Technology can provide:

  • Security alerts
  • Vulnerability findings
  • Threat intelligence
  • Automated analysis
  • Automated responses

Cybersecurity professionals provide:

  • Investigation
  • Context
  • Risk assessment
  • Prioritization
  • Decision-making

The 2026 Fortinet Cybersecurity Skills Gap Report found that 71% of organizations believe the cybersecurity skills gap creates additional risk.

That makes skills a direct part of an organization's security posture.

The Training Gap Matters Too

Cybersecurity education needs to keep pace with the systems professionals are actually expected to protect.

Learning security concepts is necessary, but professionals also need practical experience. They need to understand what happens when a vulnerability is discovered, how an incident develops and how different security technologies work together.

Practical cybersecurity training should give people experience with:

  • Penetration testing and vulnerability assessment
  • Incident investigation and response
  • Security operations
  • Cloud security
  • AI security
  • Realistic attack and defense scenarios

This matters for both experienced professionals and people entering the cybersecurity industry. As technology changes, continuous skills development becomes part of the job rather than a one-time step at the beginning of a career.

Building the Skills Behind Indonesia's Cybersecurity Technology

Indonesia's cybersecurity investment will continue to grow. But technology alone can't close the security gap.

Organizations need people who understand how to configure, operate and challenge the systems they deploy. They need professionals who can work across cybersecurity and emerging technologies rather than treating them as separate disciplines.

That's the thinking behind the ITSEC Cyber & AI Academy.

The Academy brings cybersecurity and AI education together with a practical focus, helping professionals and aspiring cybersecurity talent develop skills aligned with the technologies and threats shaping the industry.

For Indonesia, the next challenge isn't simply buying better cybersecurity technology.

It's building the people who know how to use it.

Build the skills behind the technology.

Explore the ITSEC Cyber & AI Academy and develop practical cybersecurity and AI capabilities for the next generation of digital threats.

Visit ITSEC Cyber & AI Academy

Share this post

You may also like

Post-Quantum Cryptography Readiness with ITSEC
Cybersecurity

Post-Quantum Cryptography Readiness with ITSEC

For decades, public-key cryptography has been the backbone of protecting sensitive information, such as financial transactions, personal data, corporate communications, and government secrets. Whether logging into a secure banking app, shopping online, or browsing encrypted websites (like HTTPS), public key infrastructure (PKI) protects your data from cybercriminals. However, the rise of quantum computing introduces transformative and potentially disruptive challenge to this foundation of digital trust. THE QUANTUM REVOLUTION Quantum computers can perform complex computations faster than even the most advanced current supercomputers. While this capability promises breakthroughs in drug discovery and healthcare, materials science or Artificial Intelligence (AI), it also poses a significant threat to current cryptographic systems. Quantum computers could break widely used publickey cryptographic systems (e.g., RSA, ECC), compromising critical infrastructure security such as energy grids, financial systems, and sensitive government communication networks. Compromised public-key cryptography could lead to forged digital certificates or signatures, undermining trust in banking, healthcare, and government services. Quantum cryptography attacks could also compromise billions of connected devices, from smart homes to Industrial Control Systems (ICS), by

ITSEC AsiaITSEC Asia
|
Jul 11, 2025 4 minutes read
The Security Gap Indonesian Financial Institutions Can't Afford to Ignore
Cybersecurity

The Security Gap Indonesian Financial Institutions Can't Afford to Ignore

INTRODUCTION Between late 2024 and 2025, Indonesia's Financial Services Authority (OJK) and the Indonesia Anti-Scam Center (IASC) recorded approximately 274,000 fraud cases with total public losses exceeding IDR 6 trillion [https://www.itbeat.id/en/penipuan-berbasis-ai-ancam-sektor-keuangan-indonesia-ojk-catat-kerugian-rp6-triliun/]. That number does not include the operational disruption and reputational fallout from high-profile breaches like the 2024 BI-Fast cyber incident, which prompted OJK to launch emergency inspections of regional banks across the country. Indonesia's financial sector is not fighting a periodic threat. It is fighting one that operates around the clock, and treating security validation as a once-a-year checkbox is one of the most dangerous assumptions a bank or fintech company can make right now. Annual penetration tests are the industry norm, and for a long time they were considered sufficient. The logic was reasonable: test the system before it goes into production, document the findings, remediate the critical ones, and revisit in twelve months. That model made sense when environments were relatively static, when APIs were not the backbone of every product integration, and when attackers were not running automated

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 7 minutes read
How IoT Devices Are Expanding the Cybersecurity Attack Surface
Cybersecurity

How IoT Devices Are Expanding the Cybersecurity Attack Surface

INTRODUCTION When people hear “IoT security, [https://itsec.asia/services/ot-ics-cybersecurity]” they often assume it’s something only IT teams need to worry about. In reality, IoT security affects everyday users, households, and businesses alike.* From smart home devices to office surveillance systems, connected devices are now part of critical daily operations. The more devices we connect, the wider the potential attack surface becomes. Here’s the part no one really talks about: Many IoT environments are deployed quickly for convenience, not necessarily designed with security as the top priority. It’s not negligence. It’s just how fast technology moves. Source: aciano.net [https://aciano.net/blog/iot-security-risks/], cio.com [https://www.cio.com/article/3990581/iot-security-challenges-and-best-practices-for-a-hyperconnected-world.html?] THE IOT LANDSCAPE NOWADAYS Security used to focus on protecting networks with firewalls and perimeter defenses. Today, attackers are shifting their focus to easier targets: user credentials, weak device authentication, misconfigured cloud dashboards, and unpatched firmware.  Today, attackers are more interested in: * User credentials * Weak device authentication * Misconfigured cloud dashboards * Unpatched firmware IoT devices often rely on cloud platforms for monitoring, analytics, and control. That means IoT security is no longer just about the

ITSEC AsiaITSEC Asia
|
Mar 06, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe