The 2026 edition has come to a successful close! Registrations for IndoSec 2027 will open shortly!The 2026 edition has come to a successful close! Registrations for IndoSec 2027 will open shortly!The 2026 edition has come to a successful close! Registrations for IndoSec 2027 will open shortly!The 2026 edition has come to a successful close! Registrations for IndoSec 2027 will open shortly!
DELEGATE ENQUIRY
Registrations for IndoSec 2026 are now
officially closed!
SPONSOR ENQUIRY
Registrations for IndoSec 2026 are now
officially closed!
Securing Indonesia Emas 2045: Building Cyber Resilience for a Digitally Sovereign Nation
How Indonesia’s national cyber priorities are being realigned in real time as AI-driven threats outpace the defence models Vision 2045 was built on.
How banking, telecommunications, smart infrastructure, and government platforms are building the foundational cyber capabilities that enable digital sovereignty.
What government expects from Indonesian enterprises in 2026, compliance timelines, incident reporting obligations, and the accountability gap between policy on paper and security in practice.
Alfian Ilarizky, S.ST., M,T.
Head of Telecommunication Sector Team, Associate Cyber and Crypto Specialist
The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara BSSN)
09:20 AM – 09:35 AM
Embedding Indonesia’s Personal Data Protection Law into Enterprise Security Architecture
Transition to enforcement, what 350+ platform reviews reveal about where Indonesian organizations are falling short.
Life post- Constitutional Court Decision No. 151/2024; how the “and/or” clarification affects enterprise accountability structures, data handling assignments, and breach response obligations.
Navigating Regulatory Gaps in cross-border data environments, brought about by the gradual adoption of the Lembaga PDP and what to expect when the implementing regulation lands.
Muchtarul Huda
Director of Digital Space Monitoring Strategies and Policies
Ministry of Communications and Digital Affairs (KOMDIGI)
09:35 AM – 09:50 AM
BNPT's Strategic Role in Facing the Threat of Terrorism and Digital Extremism in the Era of Hybrid Threats
How the line between physical and digital extremism has blurred, and what “hybrid threats” actually mean for
Indonesia’s national counter-terrorism strategy in 2026
BNPT’s coordination role across law enforcement agencies in detecting and disrupting digital radicalization
before it translates into real-world action
What protection and support law enforcement officers themselves need as the threat landscape shifts
increasingly online, and how that shapes BNPT’s operational priorities going forward
Brigadier General Sigit Widodo, S.I.K.
Director of Law Enforcement Coordination and Protection of Law Enforcement Officers
National Counter-Terrorism Agency (BNPT)
09:50 AM – 10:10 AM
Who Controls Your Data When AI Is Using It?
Indonesia’s Regulatory Enforcement Gap: Understand how to adopt AI rapidly and safely while staying compliant with national guidelines
Data Sovereignty Redefined: Understand how data sovereignty will not be compromised with the use of AI by practising control, custody, and capability—all three of which are currently disrupted by data leaks through AI prompts, code assistants, and autonomous agents
Need for Strategic AI Countermeasures: Organisations must implement specialised AI security tools—such as Prompt Security to block external data leaks, Singularity AI SIEM to secure internal evidence, and Purple AI Auto Investigation to bridge local talent gaps without outsourcing critical operations offshore
Samuel Ho
Director - Solutions Engineering, Asia
SentinelOne
10:10 AM – 10:30 AM
Beyond Login: Securing Human and AI-Driven Actions
Why authentication alone is no longer enough when humans, applications, automated systems, and AI agents can initiate sensitive actions across complex digital environments.
Establishing trust throughout the human identity journey: from identity proofing and privacy-preserving biometric verification to real-time assessment of device, behaviour, context, and fraud risk.
Extending identity security to AI agents by controlling delegated authority, enforcing time-bound and least-privilege access, and determining when actions should be permitted, denied, or escalated for human approval.
Vira Saksen
Solutions Architect, APJ
Ping Identity
10:30 AM – 11:00 AM
You Don't Have a Backup Problem. You Have a Recovery Proof Problem.
Understand the gap between organisations’ confidence in recovery and their actual, tested recovery capabilities
Explore how AI has compressed the timeline from initial compromise to full-scale damage from weeks to hours, while recovery timelines remain largely unchanged
Learn how to benchmark recovery maturity and demonstrate that data can be restored clean, fast, and to a regulator’s satisfaction across hybrid, multi-cloud and identity-driven environments
Keith Sng
CTO, APJ
Veeam Software
11:00 AM – 11:30 AM
NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE
11:30 AM – 11:50 AM
Fireside Chat
Securing the Backbone: What It Takes to Protect Indonesia's Data Center Infrastructure
How Indonesia’s data center ecosystem is evolving as more essential government and enterprise functions move onto shared or managed infrastructure, and what “critical infrastructure” actually means in that new reality
Why operational technology (OT) resilience is a different discipline entirely from traditional IT security, and where Indonesian data center operators tend to underestimate that gap
Lessons learned from the National Data Center incident, and how centralising government and financial sector data operations at a ministerial or group level is reshaping how resilience and incident response get coordinated
Moderator
Erick Hadi
Secretary General
Indonesia Data Center Ecosystem Council (IDCEC)
Nuzli Hernawan
Vice President Infrastructure & Cybersecurity
PT. Sigma Cipta Caraka (Telkomsigma)
11:50 AM – 12:10 PM
Please Stop Telling Me AI Will Fix Cybersecurity
AI changed the clock, not the fundamentals. Attackers now scan, weaponize, and phish at machine speed, but the breaches we still see at Indonesian enterprises and government agencies start the same way they did five years ago: exposed systems, weak identities, unpatched code, and someone clicking. Faster attackers punish the same old gaps harder
AI without context is just faster confusion. An AI that summarizes 10,000 alerts still gives you 10,000 alerts. Real value only appears when code, cloud exposure, identity, and threat intelligence are connected, so the machine can show an actual attack path instead of a prettier dashboard.
The right question isn’t “does it use AI” but “does it let my analysts decide faster and better.” Using Google SecOps agents as a working example, we’ll walk through what agentic triage, investigation, and detection engineering look like when the human stays in control, and where the limits still are
Marcel Judodihardjo
Customer Solutions Consultant
Google Cloud Security
12:10 PM – 12:30 PM
Strengthening Indonesia’s Cyber Shield: Visibility, Identity, and Resilience
Visibility: Gain comprehensive visibility across user activities, endpoints, networks, and digital assets to identify risks and detect threats early.
Identity: Strengthen identity security and privileged access as a critical line of defense in today’s increasingly connected IT environment.
Resilience: Enhance the organization’s ability to detect, respond to, and recover from cyber incidents quickly and effectively.
Ichsan Hasibuan
Technical Consultant
ManageEngine
12:30 PM – 12:50 PM
Securing Tomorrow: The Next Decade in Cyber
Understand the five trends that will affect cybersecurity over the next decade.
Learn about the impact of AI on cyber attacks.
Explore why quantum computing is one of the biggest future challenges in cybersecurity.
Dr Kawin Boonyapredee
CISO Advisor APJ
KnowBe4
12:50 PM – 01:00 PM
Securing identity from AD to AI
Point security solutions can no longer keep up as companies now need to consolidate identity security across every environment they run, from on-prem Active Directory and local accounts to modern cloud identities.
Machine identities and now agentic AI identities are adding a new layer of complexity to an already fragmented identity landscape.
A new approach to consolidating identity security across all IAM silos, delivering not just unified visibility but real runtime enforcement.
Jason Teo
Channel Account Manager, APJ
Silverfort
01:00 PM – 02:00 PM
LUNCH BREAK
02:00 PM – 02:30 PM
Panel Discussion
Cloud Without Compromise - Securing Indonesia's Rapid Shift to Multi-Cloud and Hybrid Infrastructure
How rapid cloud adoption, API sprawl, and ecosystem partnerships are quietly building hidden dependencies that could unravel Indonesia’s digital resilience from the inside.
Why security built into cloud architecture at design stage – across identity, data flows, and third-party integrations – is the only model that survives a $360 billion attack surface.
How embedding cybersecurity leadership into core cloud and infrastructure decisions, not just compliance sign-off, is the governance shift separating resilient Indonesian enterprises from vulnerable ones.
Moderator
Dr. Charles Lim
Head of Talent Development
Indonesian Digitalization and Cybersecurity Association (ADIGSI)
Arief Ristanto
Head of Cyber Security Department
Astra International
Dominic Chandra
General Manager of Corporate Information System & Technology Division
PT United Tractors Tbk
Joseph Lembayung
IT and Digital Transformation Director
PT Darma Henwa Tbk
02:30 PM – 02:50 PM
Sandi Data: Solution Initiative for Data Security, Information Confidentiality, and Data Leak Prevention
BSSN’s Sandi Data initiative and its role in strengthening national data security and information confidentiality.
Practical approaches to preventing data leaks across government and critical infrastructure systems.
How this initiative fits into Indonesia’s broader cryptographic and data protection strategy.
Yan Hadynoer, S.S.T.TP., M.T.
Head of the Cryptography Service Bureau
The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara BSSN)
02:50 PM – 03:20 PM
Panel Discussion
Cybersecurity 3.0 – Securing the Future of Hyperconnected and Autonomous Digital Economies
How machine-driven transactions, decentralized services, and digital identity are rewriting the rules of trust and what that means for how Indonesian enterprises enforce it.
Why containing breaches after they happen is no longer a viable strategy and how Indonesian enterprises are shifting to security models that predict and adapt before the attack lands.
How to build sustained cyber resilience in environments where automation, scale, and speed create competitive advantage all while attacks surface in equal measure.
Moderator
Pankaj Dubey
Co-Founder & CTO
Sparkle Security
Yohannes Glen Dwipajana
SVP - Head of Enterprise Security
Indosat Ooredoo Hutchison
Rendra Perdana
Chief Information Security Officer / VP Information Security
DANA Indonesia
Farina Mutia
Information Security Head - Country CISO Indonesia
UOB
03:20 PM – 05:00 PM
NETWORKING & END OF DAY 1
08:00 AM – 09:00 AM
REGISTRATION & COFFEE
09:00 AM – 09:15 AM
Protecting Today's Data from Tomorrow's Threats: BSSN's PQC Migration Initiative
BSSN’s roadmap for migrating Indonesia’s cryptographic infrastructure to post-quantum standards ahead of the threat quantum computing poses to current encryption.
How government and critical national systems are being prioritised in the transition to quantum-resistant security.
What Indonesian organisations should be doing now to prepare for a post-quantum future.
Giyanto Awan Sularso, S.Kom., M.M
Director of Cyber Security and Crypto Policy for Technology
The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara BSSN)
09:15 AM – 09:30 AM
Securing Indonesia's Maritime Frontier: Cybersecurity Challenges in National Surveillance Systems
How maritime surveillance systems – radar networks, vessel tracking, and coastal monitoring infrastructure – are becoming high-value targets in Indonesia’s expanding digital defence perimeter.
The operational reality of securing legacy maritime sensor networks alongside modern satellite and AI-driven surveillance platforms, often running on infrastructure never designed with cyber resilience in mind.
What it takes to protect the systems safeguarding Indonesia’s 17,000+ islands and vast territorial waters from both physical and cyber-enabled threats, and where BAKAMLA’s mandate intersects with national cyber defence.
Col. Adriansyah Putra Harahap
Senior IT Officer
Indonesian Maritime Security Agency (BAKAMLA)
09:30 AM – 09:50 AM
From Cyber Incident to Financial Intelligence: Building Indonesia’s Resilience Against Cyber-Enabled Financial Crime
How cyber breaches increasingly translate into financial crime, and what PPATK’s transaction monitoring reveals about the money trail behind Indonesia’s major cyber incidents.
Bridging the gap between cybersecurity response and financial intelligence, why containing a breach isn’t the same as stopping the money it enables.
What Indonesian enterprises and financial institutions need to report, and how fast, to give financial intelligence a fighting chance against increasingly cyber-enabled crime.
Afra Azzahra
Team Lead Strategic Intelligence and Policy Evaluation
Indonesian Financial Transaction Reports and Analysis Centre PPATK (Pusat Pelaporan dan Analisis Transaksi Keuangan)
09:50 AM – 10:10 AM
Agentic AI and the Future of Cyber Defense
As AI shifts from content generation to autonomous decision-making, government agencies, public sector organisations, and Indonesian businesses face a new era of opportunity and cyber risk.
Agentic AI systems can plan, act, and adapt with minimal human intervention, creating unprecedented value while opening up new attack surfaces and security challenges.
Exploring the evolving role of Agentic AI and why trust, governance, and resilience are critical as governments and businesses move into an AI-driven future.
Eng Hao Tan
Senior Manager, Sales Engineering
Sophos
10:10 AM – 10:30 AM
Trusted by Default, Breached at Scale: FortiBleed and the Supply Chain Blind Spot
Exploiting Default Trust: Attackers weaponized native firewall commands to quietly harvest millions of credentials.
Supply-Chain Amplification: Breaching IT service providers to gain access across hundreds of customer networks.
AI-Accelerated Initial Access: Automated brokers operating at machine speed to feed major ransomware crews.
Isaac Wong
Senior Solutions Engineer, APAC
SOCRadar
10:30 AM – 11:00 AM
Panel Discussion
Who Secures Indonesia? Building Digital Sovereignty Through a Strong Local Cybersecurity Industry
What does digital sovereignty mean for Indonesia? Exploring how Indonesia can strengthen control and resilience across critical digital infrastructure, cybersecurity technology, data, talent, and national capabilities.
Building a trusted, globally competitive local cybersecurity industry: how Indonesian companies can improve their technology, scalability, reliability, certification, and support capabilities, and how initiatives such as TKDN, local certification, and government procurement can accelerate that growth.
Strengthening critical sectors through local capability and collaboration: how defense, banking, telecommunications, and other strategic industries can leverage Indonesian-built cybersecurity solutions, and the right balance between local and global technologies as government, industry, and financial institutions build the country’s cybersecurity capabilities for the next decade.
Rhesa Yogaswara, S.Mat., M.M., M.F.
Founder & Chief Operating Officer
Indonesia Digital & Cyber Institute (IDCI)
Mayjen TNI Iroth Sonny Edhie, M.H.I.
Head of Army Communications and Electronics Centre
Pusat Komunikasi dan Elektronika Angkatan Darat (Puskomlekad)
Dr. Lasmaida S. Gultom, SE, MBA, D.MIN
President Commissioner / Former Director of Special Examination and Regional Banking Supervision
PT. Indonesia Maju Konsultama / Indonesia Financial Services Authority (OJK)
Ivan Romano, S.Kom., M.Psi.
President Director
PT. Tri Kreasi Mandiri Teknologi
11:00 AM – 11:30 AM
NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE
11:30 AM – 11:50 AM
Fireside Chat
From Connectivity to Cyber Resilience: Securing Indonesia's 5G, IoT, and AI-Powered Enterprise Transformation
The gap between how quickly Indonesian enterprises are adopting 5G, IoT, and AI-driven platforms, and how quickly they’re securing those deployments.
How security needs to be designed in from day one as connectivity moves into industrial and operational environments, not just IT networks.
What effective collaboration between telcos, industry associations, and enterprises actually looks like when building secure digital infrastructure, not just fast infrastructure.
Moderator
Fanky Christian
Secretary General
Asosiasi Pengusaha TIK Nasional (APTIKNAS)
Wai Kiat Kwok
Vice President - Enterprise Product Management and Development
Telkomsel
11:50 AM – 12:00 PM
The Clock Has No Mercy: Racing Frontier AI to the Fix
Frontier AI has collapsed attacker timelines from days to minutes, making yesterday’s sequential, human-paced defense playbook obsolete.
Qualys TruRisk Eliminate uses AI-driven risk scoring to automatically identify which vulnerabilities in your specific environment are being actively exploited right now and deploys patches autonomously before attackers can act.
Establishing verification discipline and layered communication controls to reduce human exploitation vectors.
Himanshu Kathpal
Vice President, Product Management, Platform and Technologies
Qualys
12:00 PM – 12:10 PM
The Security Velocity Dilemma: Defending Indonesia's AI-Accelerated Attack Surfaces with Community-Powered Resilience.
Why the old model is breaking — attack surfaces are expanding faster than any internal team can test them, and AI is accelerating both the code being shipped and the attackers probing it, making annual, point-in-time testing a losing race.
What community-powered security adds — a global researcher community, aligned by incentives and continuously engaged, gives defenders an attacker’s-eye view at a scale and diversity no single team can match, complementing in-house security rather than replacing it.
A practical path for Indonesia — from vulnerability disclosure to continuous testing and CTEM, and how to measure the shift in real exposure rather than compliance checkboxes.
Laurie Mercer
Senior Director of Sales Engineering, EMEA & APAC
HackerOne
12:10 PM – 12:20 PM
Cybersecurity as a Business Enabler: Why Indonesia's Chambers of Commerce Are Prioritizing Digital Trust
Why cybersecurity is becoming a competitiveness issue for Indonesian businesses, not just a regulatory checkbox, and what that shift means for companies trying to attract investment and partnerships.
How industry bodies like KADIN are stepping in to help businesses, especially SMEs and mid-market enterprises, build baseline cyber resilience without world-class security budgets.
What role business chambers play in bridging the gap between government cybersecurity policy and the operational reality of Indonesian enterprises.
Arif Ilham Adnan
Chairperson of Permanent Committee / Co-Chairman
The Jakarta Chamber of Commerce and Industry (KADIN Jakarta) / Association of Digital Leaders Indonesia (APDI)
12:20 PM – 12:30 PM
Effortless Security, Unmatched Protection: How GravityZone Helps Lean Indonesian Teams Fight Enterprise-Grade Threats
Proven, not just promised. Bitdefender backs its claims with independent test results and law enforcement partnerships — not just marketing
One platform, full coverage
Prevention, protection, and detection & response are unified in a single platform — instead of dozens of disconnected tools
Solves the real bottleneck: people. MDR (24×7 managed response) and PHASR (proactive attack surface reduction) help lean teams get enterprise-level protection without needing a big security staff
Surya Dharma
Channel Sales Engineer
Bitdefender
12:30 PM – 12:40 PM
AI on Prem Framework for Cyber Resilience: Practical Examples Using AI on Prem in the SOC
Discover how “AI on-Prem” strengthens cyber resilience without compromising data control.
See real-world examples of AI-Powered SIEM and SOAR accelerating detection and response.
Learn how to modernize your SOC while staying compliant and keeping sensitive data in-house.
David Beck
Territory Manager, Asia Pacific
Energy Logserver
12:40 PM – 12:50 PM
How to Secure Your Mobile App and the APIs It Interacts With
With 3.8 billion mobile app users, apps are the main way many accomplish everything from shopping to banking.
The exponential growth in mobile app use has generated an increase in volume and sophistication of mobile app attacks. How can organizations ensure their app has the right protection to keep the data within and passing through the app safe?.
Attend this session to learn the importance of protecting your mobile app from reverse engineering and tampering, as well as steps you can take to ensure only your app can interact with your APIs.
Ewout Dhont
Team Lead Solution Engineering
Guardsquare
01:00 PM – 02:00 PM
LUNCH BREAK
02:00 PM – 02:30 PM
Panel Discussion
The CISO Mandate - Leading Security in Indonesia's High-Stakes Digital Economy
Why the most sophisticated detection stack in your organization cannot protect you from the human decisions made above it.
Why most insider threats aren’t malicious – they’re the predictable result of process gaps, operational pressure, and accountability that nobody clearly owns.
How today’s CISOs are turning security awareness from a training checkbox into measurable operational discipline that holds under pressure.
Moderator
Pankaj Dubey
Co-Founder & CTO
Sparkle Security
Yuan Yudistira
IT Security General Manager
PT Siloam International Hospitals Tbk
Bayu Pinasthika
Chief Information Security Officer
PT Pertamina Bina Medika IHC
Johansen Sidabutar
Country Information Security Officer - Indonesia
Citibank
Achmad Rivai
Chief Information Security Officer
Bank Jakarta
02:30 PM – 02:50 PM
Strategic Cybersecurity Investment in High-Growth Digital Economies: Balancing Expansion, Regulation, and Resilience
Why Indonesia’s digital expansion is outpacing its security budgets and what enterprises must prioritize when they cannot protect everything equally.
How to allocate a constrained security budget across fraud prevention, cloud governance, incident response, and talent when the attack surface grows faster than the budget does.
How to align security investment with regulatory expectations and national digital ambition before the auditor decides you didn’t.
Firlie Ganinduto
Chairman
Indonesian Digitalization and Cybersecurity Association (ADIGSI)
02:50 PM – 03:20 PM
Panel Discussion
Privileged Access, Public Exposure - Why Indonesia's Biggest Breaches Start With Someone Who Already Had the Keys
Why over-privileged accounts, not external attackers, are the fastest path to lateral movement across Indonesian banks, telcos, and government networks – and what PDNS 2 taught the country about who really holds the keys to critical systems.
Rethinking privileged access as a living attack surface rather than a static IT control – session, credential, and vendor access that expands quietly until it becomes the breach nobody saw coming.
Why “least privilege” remains a policy statement in most Indonesian enterprises rather than an operational reality, and what it actually takes to enforce time-bound, monitored, revocable access at scale.
Roy Dianton Leonardo
Head of IT Security, GRC & Cyber Security
PT Lion Super Indo.
Dani Aquarius Febrianda
Head of Information Security
PT Prudential Sharia Life Assurance
03:20 PM – 04:30 PM
NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE
04:00 PM – 04:30 PM
Red Carpet Moment with Paparazzi Lights
04:30 PM – 04:40 PM
Opening Ceremony
04:40 PM – 04:50 PM
Grand Premier Performance
04:50 PM – 05:20 PM
Introductory Address by the Jury Committee
05:20 PM – 06:00 PM
Awards Presentation Ceremony
06:00 PM – 06:10 PM
Closing Remarks
06:10 PM – 06:20 PM
Closing Performance
06:20 PM – 07:30 PM
Cocktail & Gala Dinner
*The above is a running agenda and is subject to change