Logo
Cybersecurity

Teaching People to Use AI Without Security Is Half a Lesson

AI skills are spreading far beyond technology teams. The ability to use AI safely needs to travel with them.

ITSEC AsiaITSEC Asia
|
Sep 08, 2026
Teaching People to Use AI Without Security Is Half a Lesson

Seven hundred and fifty government employees across Kalimantan started AI training this week. The program, run by BLSDM Komdigi Banjarmasin with ASEAN Foundation, covers AI fundamentals, ethics, implementation and something that deserves to sit comfortably beside all three: data security.

That combination makes sense.

Organizations are teaching more people how to use AI because AI is becoming part of ordinary work. Employees can summarize documents, analyse information, draft material and automate routine tasks without writing a line of code.

Every new capability also creates a new question: what exactly are we giving the AI?

The AI Skill Gap Has a Security Side

An employee can be perfectly competent at prompting an AI system while making poor security decisions around it.

Imagine someone needs to summarize a lengthy internal report. Uploading the document may produce an excellent summary. Whether the document should have been uploaded in the first place is an entirely different test.

As AI becomes commonplace, workers need enough security literacy to ask questions such as:

  • What information am I putting into this system?
  • Does it contain personal, confidential or customer data?
  • Which AI tools has my organization approved?
  • Can generated output reveal information that shouldn’t be shared?
  • When should an AI-generated answer be verified before someone acts on it?

None of these questions requires everyone to become a cybersecurity specialist. They require people to understand where convenience ends and risk begins.

The ASEAN Foundation’s AI Ready ASEAN program takes a similar approach at regional scale. It aims to equip 5.5 million people across Southeast Asia with AI skills while emphasizing responsible and ethical adoption.

Cyber Teams Are Learning AI Too

The skills exchange works in the other direction.

NIST’s NICE program has been examining how AI is changing cybersecurity work, skills and careers. Its July workforce webinar argued that existing and incoming cyber professionals need to adapt as AI changes both the technology they protect and the work they perform.

So two training needs are beginning to meet in the middle.

General employees need enough security knowledge to use AI responsibly. Cybersecurity professionals need enough AI knowledge to understand how these systems work, where they fail and how they change organizational risk.

The overlap includes practical areas such as data handling, access control, model and application security, AI-enabled threats and governance.

Simply adding “AI” to a course title won’t magically cover all of that. Sadly, curriculum design remains resistant to shortcuts.

Train for the Moment Someone Clicks Upload

Security training around AI works best when it gets concrete.

Give learners a realistic scenario involving a customer document, internal financial information or source code and ask them to decide what can safely enter an AI system. Let cybersecurity learners examine an AI-enabled workflow and identify where data, identity or access could become exposed.

That kind of practice connects AI literacy with the decisions people actually make at work.

It also fits the practical learning approach of ITSEC Cyber & AI Academy, where cybersecurity and AI can be taught as connected capabilities rather than separate technology subjects.

The next generation of workforce training will increasingly need both. Knowing how to ask AI the right question is useful. Knowing what you shouldn’t tell it may save considerably more trouble.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: BLSDM Komdigi Banjarmasin: 750 Aparatur Ikuti Pelatihan AI, 7 September 2026 · NIST NICE: Shaping the Future of the Cyber Workforce in the Age of AI · ASEAN Foundation: AI Ready ASEAN

Share this post

You may also like

Is Using a VPN Really Safe? Here’s the Reality Check.
Cybersecurity

Is Using a VPN Really Safe? Here’s the Reality Check.

INTRODUCTION Today, almost everything we do happens online, from working and studying to shopping and banking. While the internet makes life easier, it also comes with certain risks, especially when it comes to privacy and data security. Many people connect to public Wi-Fi in places like cafés, airports, or hotels without realizing that these networks may not always be secure. In some cases, attackers can monitor or intercept data that travels through these connections. This is where VPN apps become useful. A VPN app helps create a safer internet connection by protecting your data and hiding your online identity. Even if you are using an open network, a VPN can help keep your activity more private. This article will explain what a VPN app is, how it works, and why it has become an important tool for safer internet use. Source: pr.norton.com [https://pr.norton.com/blog/privacy/what-is-a-vpn?utm_], security.org [https://www.security.org/vpn/?utm_], fortinet.com [https://www.fortinet.com/resources/cyberglossary/vpn-wifi?utm_] WHAT IS A VPN APP? A VPN app is a tool that helps protect your internet connection and online activity. VPN stands for Virtual Private Network.

ITSEC AsiaITSEC Asia
|
Mar 13, 2026 — 6 minutes read
A SOC Can’t Detect What It Never Learned to See
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened. That sounds like the beginning of detection work. In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation. If that work is poor, even an excellent analyst is starting with missing pages. An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2. That’s a useful model for SOC training. VISIBILITY IS A SKILL SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response. Those capabilities

ITSEC AsiaITSEC Asia
|
Sep 17, 2026 — 3 minutes read
Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem
Cybersecurity

Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Indonesia needs more cybersecurity professionals. That part is obvious. What is becoming less obvious is whether the real problem is still about numbers. The 2026 SANS | GIAC Cybersecurity Workforce Research Report found that 60% of surveyed organizations said their teams lacked the right skills to defend against current threats. More concerning, 27% reported breaches directly linked to capability gaps. That changes the conversation. A company can have a security team, a dashboard full of alerts and a stack of expensive tools. The harder question is whether the people behind them know what to do when something unusual happens. CYBERSECURITY WORK IS MOVING FAST Artificial intelligence is making that question harder. AI can already help with alert analysis, vulnerability prioritization and repetitive investigation tasks. Attackers can use the same technology to make attacks faster and easier to scale. In August 2026, Vice Minister of Communication and Digital Affairs Nezar Patria warned that agentic AI could allow cyberattacks to operate with less direct human involvement. He also highlighted threats such as harvest

ITSEC AsiaITSEC Asia
|
Sep 01, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe