Logo
Cybersecurity

Teaching People to Use AI Without Security Is Half a Lesson

AI skills are spreading far beyond technology teams. The ability to use AI safely needs to travel with them.

ITSEC AsiaITSEC Asia
|
Sep 08, 2026
Teaching People to Use AI Without Security Is Half a Lesson

Seven hundred and fifty government employees across Kalimantan started AI training this week. The program, run by BLSDM Komdigi Banjarmasin with ASEAN Foundation, covers AI fundamentals, ethics, implementation and something that deserves to sit comfortably beside all three: data security.

That combination makes sense.

Organizations are teaching more people how to use AI because AI is becoming part of ordinary work. Employees can summarize documents, analyse information, draft material and automate routine tasks without writing a line of code.

Every new capability also creates a new question: what exactly are we giving the AI?

The AI Skill Gap Has a Security Side

An employee can be perfectly competent at prompting an AI system while making poor security decisions around it.

Imagine someone needs to summarize a lengthy internal report. Uploading the document may produce an excellent summary. Whether the document should have been uploaded in the first place is an entirely different test.

As AI becomes commonplace, workers need enough security literacy to ask questions such as:

  • What information am I putting into this system?
  • Does it contain personal, confidential or customer data?
  • Which AI tools has my organization approved?
  • Can generated output reveal information that shouldn’t be shared?
  • When should an AI-generated answer be verified before someone acts on it?

None of these questions requires everyone to become a cybersecurity specialist. They require people to understand where convenience ends and risk begins.

The ASEAN Foundation’s AI Ready ASEAN program takes a similar approach at regional scale. It aims to equip 5.5 million people across Southeast Asia with AI skills while emphasizing responsible and ethical adoption.

Cyber Teams Are Learning AI Too

The skills exchange works in the other direction.

NIST’s NICE program has been examining how AI is changing cybersecurity work, skills and careers. Its July workforce webinar argued that existing and incoming cyber professionals need to adapt as AI changes both the technology they protect and the work they perform.

So two training needs are beginning to meet in the middle.

General employees need enough security knowledge to use AI responsibly. Cybersecurity professionals need enough AI knowledge to understand how these systems work, where they fail and how they change organizational risk.

The overlap includes practical areas such as data handling, access control, model and application security, AI-enabled threats and governance.

Simply adding “AI” to a course title won’t magically cover all of that. Sadly, curriculum design remains resistant to shortcuts.

Train for the Moment Someone Clicks Upload

Security training around AI works best when it gets concrete.

Give learners a realistic scenario involving a customer document, internal financial information or source code and ask them to decide what can safely enter an AI system. Let cybersecurity learners examine an AI-enabled workflow and identify where data, identity or access could become exposed.

That kind of practice connects AI literacy with the decisions people actually make at work.

It also fits the practical learning approach of ITSEC Cyber & AI Academy, where cybersecurity and AI can be taught as connected capabilities rather than separate technology subjects.

The next generation of workforce training will increasingly need both. Knowing how to ask AI the right question is useful. Knowing what you shouldn’t tell it may save considerably more trouble.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: BLSDM Komdigi Banjarmasin: 750 Aparatur Ikuti Pelatihan AI, 7 September 2026 · NIST NICE: Shaping the Future of the Cyber Workforce in the Age of AI · ASEAN Foundation: AI Ready ASEAN

Share this post

You may also like

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026
Cybersecurity

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

INTRODUCTION What percentage of your last penetration test report was actually proven exploitable, and what percentage was a list of things a scanner flagged and nobody validated? Most CISOs cannot answer that question with confidence, and that is exactly the problem. Buyers guides published this year point to a pattern worth sitting with. If a quoted penetration test comes in at four to five thousand dollars or less, it is very likely an automated vulnerability scan wearing a pen test label, not manual work performed by a skilled tester. That gap between what is sold as a penetration test and what is actually delivered is why the selection conversation matters so much more than most procurement teams treat it. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that have gone through this exact evaluation, and the questions that separate a genuinely useful engagement from an expensive checkbox exercise are more specific than most RFPs ever ask. Source: Six Questions to Ask a

ITSEC AsiaITSEC Asia
|
Jul 17, 2026 5 minutes read
AI Penetration Testing vs Traditional Penetration Testing: What's the Difference?
Cybersecurity

AI Penetration Testing vs Traditional Penetration Testing: What's the Difference?

Organizations today face an increasingly complex threat landscape. New vulnerabilities emerge daily, attack surfaces expand continuously and attackers are leveraging automation to move faster than ever before. For many years, traditional penetration testing has been an essential part of cybersecurity programs. However, as environments become more dynamic, many organizations are exploring how artificial intelligence can enhance security assessments and provide more continuous visibility. This shift has given rise to AI penetration testing. But how does AI powered penetration testing compare to traditional penetration testing? Is AI replacing ethical hackers, or are the two approaches designed to work together? UNDERSTANDING TRADITIONAL PENETRATION TESTING Traditional penetration testing involves security professionals simulating real world attacks to identify vulnerabilities and weaknesses before attackers can exploit them. HOW TRADITIONAL PENETRATION TESTING WORKS A typical penetration testing engagement may include: * Reconnaissance and information gathering. * Vulnerability identification. * Exploitation and attack path analysis. * Privilege escalation testing. * Manual validation of findings. * Reporting and remediation recommendations. Traditional penetration testing provides deep insights into an organization's security posture

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 5 minutes read
Web Application Penetration Testing Explained: Why Applications Remain a Top Target for Attackers
Cybersecurity

Web Application Penetration Testing Explained: Why Applications Remain a Top Target for Attackers

Web applications have become the foundation of digital business. From customer portals and online banking platforms to e-commerce systems and internal business applications, organizations rely on web technologies to deliver services and create seamless user experiences. Unfortunately, attackers rely on them too. Because web applications are often exposed to the internet and handle sensitive information, they remain one of the most attractive targets for cybercriminals. This is why Web Application Penetration Testing has become an essential part of a modern cybersecurity strategy. WHAT IS WEB APPLICATION PENETRATION TESTING? Web Application Penetration Testing is a security assessment designed to identify and validate vulnerabilities within web applications before malicious actors can exploit them. Unlike automated vulnerability scanning, penetration testing simulates real-world attack techniques to understand how weaknesses could affect an organization's confidentiality, integrity and availability. The objective is not simply to discover vulnerabilities but to determine their actual impact. WHY ARE WEB APPLICATIONS FREQUENTLY TARGETED? Attackers are constantly searching for exposed applications because they often provide direct access to valuable assets. SENSITIVE DATA Web applications commonly process: * Customer

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe