Logo
Cybersecurity

Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Hiring more people helps. But if they freeze when the alert turns real, the headcount doesn’t mean much.

ITSEC AsiaITSEC Asia
|
Sep 01, 2026
Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

Indonesia needs more cybersecurity professionals. That part is obvious. What is becoming less obvious is whether the real problem is still about numbers.

The 2026 SANS | GIAC Cybersecurity Workforce Research Report found that 60% of surveyed organizations said their teams lacked the right skills to defend against current threats. More concerning, 27% reported breaches directly linked to capability gaps.

That changes the conversation. A company can have a security team, a dashboard full of alerts and a stack of expensive tools. The harder question is whether the people behind them know what to do when something unusual happens.

Cybersecurity Work Is Moving Fast

Artificial intelligence is making that question harder.

AI can already help with alert analysis, vulnerability prioritization and repetitive investigation tasks. Attackers can use the same technology to make attacks faster and easier to scale.

In August 2026, Vice Minister of Communication and Digital Affairs Nezar Patria warned that agentic AI could allow cyberattacks to operate with less direct human involvement. He also highlighted threats such as harvest now, decrypt later, where encrypted information stolen today could potentially be decrypted using more advanced computing in the future.

That means knowing how to operate a security tool is becoming the baseline, not the finish line.

Security teams increasingly need people who can:

  • Investigate unusual activity and decide what actually matters
  • Understand attacker behavior instead of trusting every automated alert
  • Work across cloud, endpoint, identity and network environments
  • Use AI-assisted tools without blindly accepting their output
  • Make decisions when an incident doesn’t follow the textbook

The uncomfortable part is that these skills are difficult to build from slides and theory alone.

AI Is Also Changing How Juniors Learn

Junior cybersecurity professionals have traditionally learned by doing repetitive operational work: reviewing alerts, investigating simpler cases and documenting incidents.

That work may not be glamorous, but it builds judgment.

SANS notes that AI is beginning to automate some of the same entry-level tasks that have historically helped train new cybersecurity professionals. If that trend continues, junior talent may get fewer chances to learn through routine work before they are expected to handle harder problems.

So training has to compensate.

Cyber ranges, simulations and scenario-based exercises can give people something a slide deck cannot: the experience of making a decision when the situation is messy and the answer is not immediately obvious.

Indonesia Needs More Talent. It Also Needs More Ready Talent.

Komdigi estimates that Indonesia will need around nine million digital talents by 2030, while the current supply stands at roughly three million.

Closing that gap matters. But counting course graduates or certifications alone will not tell us whether the workforce is ready.

A stronger measure is capability.

Can someone investigate an alert? Can they recognize suspicious behavior? Can they explain what happened? Can they respond without waiting for someone else to tell them what to do?

This is the gap that ITSEC Cyber & AI Academy is designed to address, combining cybersecurity learning with practical exercises, realistic scenarios and experience drawn from ITSEC Asia’s security operations.

As AI takes over more routine work, human judgment becomes more valuable, not less.

Indonesia needs more cybersecurity talent.

The next challenge is making sure that talent can actually do the job.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy: www.itsec.academy

Share this post

You may also like

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing. Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore. CYBERSECURITY NEEDS ARE CHANGING FASTER THAN SKILLS The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages. For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems. The skills required are also changing rapidly. The World

ITSEC AsiaITSEC Asia
|
Agt 24, 2026 5 minutes read
The Security Gap Indonesian Financial Institutions Can't Afford to Ignore
Cybersecurity

The Security Gap Indonesian Financial Institutions Can't Afford to Ignore

INTRODUCTION Between late 2024 and 2025, Indonesia's Financial Services Authority (OJK) and the Indonesia Anti-Scam Center (IASC) recorded approximately 274,000 fraud cases with total public losses exceeding IDR 6 trillion [https://www.itbeat.id/en/penipuan-berbasis-ai-ancam-sektor-keuangan-indonesia-ojk-catat-kerugian-rp6-triliun/]. That number does not include the operational disruption and reputational fallout from high-profile breaches like the 2024 BI-Fast cyber incident, which prompted OJK to launch emergency inspections of regional banks across the country. Indonesia's financial sector is not fighting a periodic threat. It is fighting one that operates around the clock, and treating security validation as a once-a-year checkbox is one of the most dangerous assumptions a bank or fintech company can make right now. Annual penetration tests are the industry norm, and for a long time they were considered sufficient. The logic was reasonable: test the system before it goes into production, document the findings, remediate the critical ones, and revisit in twelve months. That model made sense when environments were relatively static, when APIs were not the backbone of every product integration, and when attackers were not running automated

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 7 minutes read
What Is Continuous Security Validation and Why Does It Matter?
Cybersecurity

What Is Continuous Security Validation and Why Does It Matter?

Cyber threats evolve continuously. New vulnerabilities are discovered every day. Cloud environments change rapidly. Applications are updated frequently. Employees adopt new technologies and attackers constantly search for opportunities to exploit weaknesses. Yet many organizations still rely on periodic security assessments conducted once or twice a year. The challenge is simple: risk does not wait for the next penetration test. This is why more organizations are embracing Continuous Security Validation (CSV) as part of a modern cybersecurity strategy. WHAT IS CONTINUOUS SECURITY VALIDATION? Continuous Security Validation is the practice of continuously evaluating and validating an organization's security posture as environments, threats and attack surfaces evolve. Instead of providing a snapshot at a single point in time, Continuous Security Validation delivers ongoing visibility into security weaknesses and control effectiveness. Its purpose is to answer a critical question: "Are our defenses still working today?" Rather than waiting months between assessments, organizations gain a more dynamic understanding of their exposure. WHY TRADITIONAL ASSESSMENTS ARE NO LONGER ENOUGH Traditional penetration testing remains an important component of cybersecurity. However, most assessments are performed

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe