Logo
Cybersecurity

Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Hiring more people helps. But if they freeze when the alert turns real, the headcount doesn’t mean much.

ITSEC AsiaITSEC Asia
|
Sep 01, 2026
Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

Indonesia needs more cybersecurity professionals. That part is obvious. What is becoming less obvious is whether the real problem is still about numbers.

The 2026 SANS | GIAC Cybersecurity Workforce Research Report found that 60% of surveyed organizations said their teams lacked the right skills to defend against current threats. More concerning, 27% reported breaches directly linked to capability gaps.

That changes the conversation. A company can have a security team, a dashboard full of alerts and a stack of expensive tools. The harder question is whether the people behind them know what to do when something unusual happens.

Cybersecurity Work Is Moving Fast

Artificial intelligence is making that question harder.

AI can already help with alert analysis, vulnerability prioritization and repetitive investigation tasks. Attackers can use the same technology to make attacks faster and easier to scale.

In August 2026, Vice Minister of Communication and Digital Affairs Nezar Patria warned that agentic AI could allow cyberattacks to operate with less direct human involvement. He also highlighted threats such as harvest now, decrypt later, where encrypted information stolen today could potentially be decrypted using more advanced computing in the future.

That means knowing how to operate a security tool is becoming the baseline, not the finish line.

Security teams increasingly need people who can:

  • Investigate unusual activity and decide what actually matters
  • Understand attacker behavior instead of trusting every automated alert
  • Work across cloud, endpoint, identity and network environments
  • Use AI-assisted tools without blindly accepting their output
  • Make decisions when an incident doesn’t follow the textbook

The uncomfortable part is that these skills are difficult to build from slides and theory alone.

AI Is Also Changing How Juniors Learn

Junior cybersecurity professionals have traditionally learned by doing repetitive operational work: reviewing alerts, investigating simpler cases and documenting incidents.

That work may not be glamorous, but it builds judgment.

SANS notes that AI is beginning to automate some of the same entry-level tasks that have historically helped train new cybersecurity professionals. If that trend continues, junior talent may get fewer chances to learn through routine work before they are expected to handle harder problems.

So training has to compensate.

Cyber ranges, simulations and scenario-based exercises can give people something a slide deck cannot: the experience of making a decision when the situation is messy and the answer is not immediately obvious.

Indonesia Needs More Talent. It Also Needs More Ready Talent.

Komdigi estimates that Indonesia will need around nine million digital talents by 2030, while the current supply stands at roughly three million.

Closing that gap matters. But counting course graduates or certifications alone will not tell us whether the workforce is ready.

A stronger measure is capability.

Can someone investigate an alert? Can they recognize suspicious behavior? Can they explain what happened? Can they respond without waiting for someone else to tell them what to do?

This is the gap that ITSEC Cyber & AI Academy is designed to address, combining cybersecurity learning with practical exercises, realistic scenarios and experience drawn from ITSEC Asia’s security operations.

As AI takes over more routine work, human judgment becomes more valuable, not less.

Indonesia needs more cybersecurity talent.

The next challenge is making sure that talent can actually do the job.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy: www.itsec.academy

Share this post

You may also like

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace. That gap is becoming harder to ignore. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%. The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology. NEW TECHNOLOGY CREATES NEW SECURITY SKILLS A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities. An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them. A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive. The

ITSEC AsiaITSEC Asia
|
Agt 27, 2026 4 minutes read
What Is Continuous Security Validation and Why Does It Matter?
Cybersecurity

What Is Continuous Security Validation and Why Does It Matter?

Cyber threats evolve continuously. New vulnerabilities are discovered every day. Cloud environments change rapidly. Applications are updated frequently. Employees adopt new technologies and attackers constantly search for opportunities to exploit weaknesses. Yet many organizations still rely on periodic security assessments conducted once or twice a year. The challenge is simple: risk does not wait for the next penetration test. This is why more organizations are embracing Continuous Security Validation (CSV) as part of a modern cybersecurity strategy. WHAT IS CONTINUOUS SECURITY VALIDATION? Continuous Security Validation is the practice of continuously evaluating and validating an organization's security posture as environments, threats and attack surfaces evolve. Instead of providing a snapshot at a single point in time, Continuous Security Validation delivers ongoing visibility into security weaknesses and control effectiveness. Its purpose is to answer a critical question: "Are our defenses still working today?" Rather than waiting months between assessments, organizations gain a more dynamic understanding of their exposure. WHY TRADITIONAL ASSESSMENTS ARE NO LONGER ENOUGH Traditional penetration testing remains an important component of cybersecurity. However, most assessments are performed

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read
What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026
Cybersecurity

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

INTRODUCTION What percentage of your last penetration test report was actually proven exploitable, and what percentage was a list of things a scanner flagged and nobody validated? Most CISOs cannot answer that question with confidence, and that is exactly the problem. Buyers guides published this year point to a pattern worth sitting with. If a quoted penetration test comes in at four to five thousand dollars or less, it is very likely an automated vulnerability scan wearing a pen test label, not manual work performed by a skilled tester. That gap between what is sold as a penetration test and what is actually delivered is why the selection conversation matters so much more than most procurement teams treat it. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that have gone through this exact evaluation, and the questions that separate a genuinely useful engagement from an expensive checkbox exercise are more specific than most RFPs ever ask. Source: Six Questions to Ask a

ITSEC AsiaITSEC Asia
|
Jul 17, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe