Logo
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

Indonesia's cybersecurity challenge isn't simply about having enough people. It's about having enough people with the right skills.

ITSEC AsiaITSEC Asia
|
Agu 24, 2026
The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing.

Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore.

Cybersecurity Needs Are Changing Faster Than Skills

The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge.

The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages.

For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems.

The skills required are also changing rapidly. The World Economic Forum's Future of Jobs Report 2025 lists networks and cybersecurity among the fastest-growing skill areas through 2030, alongside AI and big data and technological literacy.

AI is particularly relevant. According to ISC2, AI was identified as the most pressing skills need by 41% of cybersecurity professionals surveyed, followed by cloud security at 36%.

The modern cybersecurity professional therefore needs to understand more than traditional security controls. They need to understand how modern infrastructure works, how attackers operate and how emerging technologies are changing both attack and defense.

Knowing Cybersecurity Isn't the Same as Doing Cybersecurity

Cybersecurity is a practical discipline.

Someone can understand what a vulnerability is without knowing how to validate it. Someone can understand the role of a Security Operations Center without knowing how to investigate a suspicious alert.

The difference becomes clear in real situations:

  • SOC analysts need to investigate alerts, identify threats and determine the appropriate response.
  • Penetration testers need to discover vulnerabilities, validate their impact and communicate findings clearly.
  • Threat intelligence analysts need to connect technical indicators with attacker behavior and turn that information into useful security decisions.
  • Security professionals working with AI need to understand how AI can improve security while also recognizing the new risks AI systems can create.

These capabilities develop through practice.

That's why cybersecurity education needs to move beyond theory and give learners opportunities to work with realistic tools, scenarios and security challenges.

AI Is Adding Another Layer to the Skills Gap

The rise of AI makes the challenge even more complex.

Security teams can use AI to analyze large volumes of information, automate repetitive tasks and support threat detection and investigation. Attackers can use AI to make their operations faster and more scalable.

At the same time, organizations are introducing AI into products and business processes, creating new security and governance requirements.

Cybersecurity professionals increasingly need to understand both disciplines:

Cybersecurity skills

  • Offensive and defensive security
  • Security operations
  • Threat intelligence
  • Vulnerability management
  • Incident response

AI skills

  • AI and machine learning fundamentals
  • AI security risks
  • AI governance and risk
  • Responsible AI
  • Applying AI to security operations

This combination is creating demand for professionals who can understand both cybersecurity and emerging technology.

Building Practical Cybersecurity and AI Skills

Closing the skills gap requires more than increasing the number of cybersecurity courses available.

Training needs to reflect what professionals actually encounter in the workplace. Learners need opportunities to develop technical skills, solve realistic problems and understand how security decisions are made in operational environments.

That means cybersecurity education should cover areas such as:

  • Offensive security: penetration testing and ethical hacking
  • Defensive security: SOC operations, detection and incident response
  • Threat intelligence: understanding threats and attacker behavior
  • GRC: governance, risk and compliance
  • AI: applying AI while understanding its security and governance risks

This is the approach behind ITSEC Cyber & AI Academy.

ITSEC Cyber & AI Academy

ITSEC Cyber & AI Academy brings ITSEC Asia's cybersecurity experience into a dedicated education platform focused on developing cybersecurity and AI capabilities.

The Academy offers cybersecurity learning paths covering Red Team, Blue Team, threat intelligence and governance, risk and compliance. Its programs connect learning with practical knowledge and industry experience, helping learners understand how cybersecurity skills are applied in real environments.

The Academy also offers AI-focused programs covering areas such as AI and machine learning, AI governance and risk and AI leadership.

The combination matters because cybersecurity and AI are becoming increasingly connected. Organizations need people who understand cybersecurity, while also needing professionals who can assess the security, risk and business implications of AI.

Closing the Gap Starts With Practical Skills

Indonesia's digital economy will continue to create demand for cybersecurity professionals. The question is whether the workforce can develop at the same pace.

Closing the cybersecurity skills gap requires investment in people who can apply their knowledge, adapt to new technologies and solve security problems in real environments.

For students, that means building practical skills early. For IT professionals, it means continuing to develop capabilities as technology and threats evolve. For organizations, it means investing in training that strengthens the capabilities of their existing teams.

The cybersecurity skills gap won't be solved by headcount alone. Indonesia needs professionals who are prepared for the work.

ITSEC Cyber & AI Academy is built to help develop those capabilities through cybersecurity and AI education grounded in industry experience.

Ready to build your cybersecurity and AI skills?

Explore ITSEC Cyber & AI Academy:
https://www.itsec.academy/

Share this post

You may also like

7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know
Cybersecurity

7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know

INTRODUCTION Cyber threats no longer wait for companies to let their guard down. Attacks occur at any time, across sectors, and are increasingly difficult to detect without an integrated monitoring system. According to Gartner, 90% of non-executive board members have no confidence in the value their organizations receive from cybersecurity investments, a gap that continues to widen between leadership expectations and internal team capacity. This is where Managed Security Services (MSS) plays a role. However, not all service providers offer equal protection. Many companies only realize the weaknesses of their vendors when an incident has already occurred. This article discusses seven criteria that should serve as an evaluation reference before you sign a contract with a Managed Security Services provider. Source: gartner.com [http://gartner.com], issglobal.com [https://issglobal.com/perspectives/what-are-managed-security-services/] WHY CHOOSING THE RIGHT MSS IS CRITICALLY IMPORTANT? Throughout 2024 to 2025, companies in the healthcare, automotive, financial, defense, and technology sectors experienced major breaches that cost billions of dollars in losses, exposed millions of data records, and paralyzed operations for months. The pattern found is quite alarming: these

|
Apr 30, 2026 — 6 minutes read
Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 — 6 minutes read
Cybersecurity Skills Need Maintenance Too
Cybersecurity

Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills. Six months later, the environment looks different. A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive. This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance. NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application. The format matters. Learning doesn’t always need another full week away from work. SMALL LEARNING CAN SOLVE SPECIFIC PROBLEMS CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes,

ITSEC AsiaITSEC Asia
|
Sep 14, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe