Logo
Cybersecurity

Cybersecurity Careers Should Start Before University

If students first discover cybersecurity when they’re applying for jobs, we’ve already lost several useful years.

ITSEC AsiaITSEC Asia
|
Sep 07, 2026
Cybersecurity Careers Should Start Before University

Ask a teenager what jobs exist in technology and you’ll probably hear programmer, software engineer or perhaps data scientist. Ask about cybersecurity and the picture can become considerably fuzzier. Maybe “hacker” makes an appearance, usually wearing an imaginary hoodie.

That perception matters because Indonesia needs a much larger pool of people who see cybersecurity as a realistic career before they have to choose one.

Komdigi has started pushing cybersecurity education further down the talent pipeline. In May, its Digital Human Resources Development Agency provided Basic Cyber Security training to 124 students at SMKN 2 Depok, covering digital security awareness and preparation for a technology-driven workplace.

The direction is also appearing internationally. NIST’s NICE program updated its September webinar on 2 September with a specific focus on preparing students for future cyber careers. One part examines how K–12 education can introduce skills connected to immediate workforce realities such as cloud security and generative AI.

Cybersecurity education is moving earlier because the work itself isn’t waiting.

Exposure Before Specialisation

Starting earlier doesn’t mean asking 15-year-olds to become penetration testers before their next mathematics exam.

The first objective is exposure.

Students can begin with concepts that make cybersecurity tangible and show them what the profession actually involves:

  • How networks and digital identities work
  • Why systems become vulnerable
  • How phishing and social engineering manipulate people
  • What happens during a cyber incident
  • How defenders investigate suspicious activity
  • Why cloud and AI systems create different security questions

Once students understand the problems cybersecurity professionals solve, the career becomes less abstract.

Indonesia already has a natural entry point through vocational education. Komdigi’s Vocational Blended Learning program has also been assessing SMK students against SKKNI-based competencies. During June alone, 99 students from six vocational schools in Bekasi participated in competency certification across several digital disciplines.

The Gap Between Knowing and Doing

Exposure, however, eventually has to become practice.

A student can memorize what phishing is in roughly the time it takes to finish a cup of coffee. Recognising a convincing phishing attempt, investigating where it came from and deciding what to do next requires a different kind of learning.

That’s why practical environments matter as students progress. Labs, simulations, competitions and cyber ranges allow learners to turn concepts into observable skills.

Komdigi made a similar point when supporting the Country-to-Country Capture the Flag competition in Bali in August. The event brought together 81 participants from 13 countries to test technical abilities against cybersecurity scenarios rather than simply discuss them.

The talent pipeline becomes stronger when those experiences connect: early exposure creates interest, structured learning builds foundations and realistic practice develops capability.

That progression is also relevant to ITSEC Cyber & AI Academy. Practical cybersecurity and AI training can provide the next step for learners and professionals who need to turn foundational knowledge into skills they can use in real working environments.

Indonesia needs millions more digital talents by 2030. Waiting until people enter the workforce before introducing cybersecurity makes that challenge unnecessarily harder.

Sometimes the first cybersecurity lesson needs to happen while there’s still a school bell at the end of it.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: Komdigi: Basic Cyber Security Training for SMK Students, 21 May 2026 · NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers, updated 2 September 2026 · BPT Komdigi: Vocational Blended Learning Certification, 3 July 2026 · Komdigi: C2C-CTF 2026

Share this post

You may also like

This is How Information Security Analysis Protects What Prevention Can't
Cybersecurity

This is How Information Security Analysis Protects What Prevention Can't

INTRODUCTION Organizations worldwide are investing more in cybersecurity than at any point in history, yet breaches are growing more frequent, more expensive, and more damaging. The global average cost of a data breach reached USD 4.88 million in 2024, the highest figure ever recorded. Even more alarming, the average time to identify a breach stood at 194 days, nearly half a year of undetected attacker activity inside a network before anyone realized something was wrong. These numbers raise an urgent question every business leader must answer honestly: if an attacker entered your network today, how long would it take your organization to find out? And once discovered, could you identify exactly what was accessed, how the attacker moved, and what vulnerabilities made it possible in the first place? For most organizations, the honest answer is: not fast enough, and not with enough certainty. That gap is precisely what Information Security Analysis (ISA) is designed to close. Prevention, including firewalls, antivirus, and multi-factor authentication, is necessary but not sufficient. When attackers

|
Mei 11, 2026 7 minutes read
The Reason Businesses That Skip Digital Forensics Keep Getting Hit Twice
Cybersecurity

The Reason Businesses That Skip Digital Forensics Keep Getting Hit Twice

INTRODUCTION The cybersecurity conversation has long been dominated by prevention. Organizations invest in perimeter defenses, deploy intrusion detection systems, and train employees to recognize phishing attempts. Yet according to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach reached 194 days, nearly half a year of undetected attacker activity inside a network. This statistic reveals a painful truth: prevention alone is not a complete strategy. When an attacker does get through (and modern threat actors have made it a matter of when, not if), organizations need a structured, methodical way to understand exactly what happened, how far the damage extends, and what must change to prevent history from repeating itself. That capability is digital forensics. And the businesses that overlook it are not just leaving questions unanswered. They are setting themselves up to be compromised again. Source: IBM Cost of a Data Breach Report 2024 [https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs], Ponemon Institute [https://www.ponemon.org] WHAT IS DIGITAL FORENSICS AND WHY DOES IT MATTER? Digital forensics is the process of collecting, preserving, analyzing,

|
Mei 06, 2026 7 minutes read
What Is Continuous Security Validation and Why Does It Matter?
Cybersecurity

What Is Continuous Security Validation and Why Does It Matter?

Cyber threats evolve continuously. New vulnerabilities are discovered every day. Cloud environments change rapidly. Applications are updated frequently. Employees adopt new technologies and attackers constantly search for opportunities to exploit weaknesses. Yet many organizations still rely on periodic security assessments conducted once or twice a year. The challenge is simple: risk does not wait for the next penetration test. This is why more organizations are embracing Continuous Security Validation (CSV) as part of a modern cybersecurity strategy. WHAT IS CONTINUOUS SECURITY VALIDATION? Continuous Security Validation is the practice of continuously evaluating and validating an organization's security posture as environments, threats and attack surfaces evolve. Instead of providing a snapshot at a single point in time, Continuous Security Validation delivers ongoing visibility into security weaknesses and control effectiveness. Its purpose is to answer a critical question: "Are our defenses still working today?" Rather than waiting months between assessments, organizations gain a more dynamic understanding of their exposure. WHY TRADITIONAL ASSESSMENTS ARE NO LONGER ENOUGH Traditional penetration testing remains an important component of cybersecurity. However, most assessments are performed

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe