Logo
Cybersecurity

Teaching People to Use AI Without Security Is Half a Lesson

AI skills are spreading far beyond technology teams. The ability to use AI safely needs to travel with them.

ITSEC AsiaITSEC Asia
|
Sep 08, 2026
Teaching People to Use AI Without Security Is Half a Lesson

Seven hundred and fifty government employees across Kalimantan started AI training this week. The program, run by BLSDM Komdigi Banjarmasin with ASEAN Foundation, covers AI fundamentals, ethics, implementation and something that deserves to sit comfortably beside all three: data security.

That combination makes sense.

Organizations are teaching more people how to use AI because AI is becoming part of ordinary work. Employees can summarize documents, analyse information, draft material and automate routine tasks without writing a line of code.

Every new capability also creates a new question: what exactly are we giving the AI?

The AI Skill Gap Has a Security Side

An employee can be perfectly competent at prompting an AI system while making poor security decisions around it.

Imagine someone needs to summarize a lengthy internal report. Uploading the document may produce an excellent summary. Whether the document should have been uploaded in the first place is an entirely different test.

As AI becomes commonplace, workers need enough security literacy to ask questions such as:

  • What information am I putting into this system?
  • Does it contain personal, confidential or customer data?
  • Which AI tools has my organization approved?
  • Can generated output reveal information that shouldn’t be shared?
  • When should an AI-generated answer be verified before someone acts on it?

None of these questions requires everyone to become a cybersecurity specialist. They require people to understand where convenience ends and risk begins.

The ASEAN Foundation’s AI Ready ASEAN program takes a similar approach at regional scale. It aims to equip 5.5 million people across Southeast Asia with AI skills while emphasizing responsible and ethical adoption.

Cyber Teams Are Learning AI Too

The skills exchange works in the other direction.

NIST’s NICE program has been examining how AI is changing cybersecurity work, skills and careers. Its July workforce webinar argued that existing and incoming cyber professionals need to adapt as AI changes both the technology they protect and the work they perform.

So two training needs are beginning to meet in the middle.

General employees need enough security knowledge to use AI responsibly. Cybersecurity professionals need enough AI knowledge to understand how these systems work, where they fail and how they change organizational risk.

The overlap includes practical areas such as data handling, access control, model and application security, AI-enabled threats and governance.

Simply adding “AI” to a course title won’t magically cover all of that. Sadly, curriculum design remains resistant to shortcuts.

Train for the Moment Someone Clicks Upload

Security training around AI works best when it gets concrete.

Give learners a realistic scenario involving a customer document, internal financial information or source code and ask them to decide what can safely enter an AI system. Let cybersecurity learners examine an AI-enabled workflow and identify where data, identity or access could become exposed.

That kind of practice connects AI literacy with the decisions people actually make at work.

It also fits the practical learning approach of ITSEC Cyber & AI Academy, where cybersecurity and AI can be taught as connected capabilities rather than separate technology subjects.

The next generation of workforce training will increasingly need both. Knowing how to ask AI the right question is useful. Knowing what you shouldn’t tell it may save considerably more trouble.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: BLSDM Komdigi Banjarmasin: 750 Aparatur Ikuti Pelatihan AI, 7 September 2026 · NIST NICE: Shaping the Future of the Cyber Workforce in the Age of AI · ASEAN Foundation: AI Ready ASEAN

Share this post

You may also like

Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 6 minutes read
Four Strong Reasons to Use an MSSP
Cybersecurity

Four Strong Reasons to Use an MSSP

Test

The multitude of challenges to be faced is the main reason why most organizations today are turning to managed security service providers (MSSPs) to help them address these issues. The challenges of strengthening human resources, processes, and technologies as efforts to secure their intellectual property and data appropriately, while still complying with cybersecurity regulations, can be a daunting task even for well-managed IT departments. With these considerations in mind, here are four main reasons why I prefer MSSPs over in-house security. USING MSSP SAVES YOU MONEY Building, running, and maintaining a cybersecurity ecosystem comes with significant costs. One of the reasons is that many software solutions require specialized hardware and equipment to run, and they often come with recurring licensing costs. Additionally, the salaries of cybersecurity employees and the training they need to effectively utilize new tools and technologies add to the expenses. One of the CFO's favorite aspects of using MSSP is that it can replace the capital expenditures often needed to add new tools with a large

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 5 minutes read
Cybersecurity Indonesia: Rising Cyber Threats and the Importance of a Strong Digital Security Strate
Cybersecurity

Cybersecurity Indonesia: Rising Cyber Threats and the Importance of a Strong Digital Security Strate

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Indonesia is facing a growing risk of ransomware attacks, phishing campaigns, data breaches and digital infrastructure exploitation that can impact business operations, public services and customer trust. In recent years, sectors including government, financial services, manufacturing, education and digital platforms have become major targets of cyber attacks. As one of the leading cybersecurity companies in Indonesia, ITSEC Asia provides cybersecurity services designed to help organizations strengthen cyber resilience and protect against evolving digital threats. -------------------------------------------------------------------------------- WHY CYBERSECURITY INDONESIA HAS BECOME A NATIONAL PRIORITY Cybersecurity Indonesia is no longer just a technical concern. Cybersecurity has become a critical component of business resilience and national digital security. Indonesia’s fast-growing digital economy is driving organizations to adopt new technologies at a rapid pace. At the same time, cyber threats continue to evolve through: * Ransomware attacks targeting organizations * Customer and sensitive data breaches * AI-powered phishing and social engineering * Cloud infrastructure attacks * Web and mobile application exploitation * Threats against critical infrastructure Organizations across Indonesia are increasingly recognizing that cyber attacks are

ITSEC AsiaITSEC Asia
|
Mei 07, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe