Agenda

We’ve got it all.

The agenda is specially curated to bring out the most pressing topics from the industry.

08:00 AM – 09:00 AM

REGISTRATION & COFFEE

09:00 AM – 09:05 AM

INAUGURATION & OPENING CEREMONY

09:05 AM – 09:20 AM

Securing Indonesia Emas 2045: Building Cyber Resilience for a Digitally Sovereign Nation

  • How Indonesia’s national cyber priorities are being realigned in real time as AI-driven threats outpace the defence models Vision 2045 was built on
  • How banking, telecommunications, smart infrastructure, and government platforms are building the foundational cyber capabilities that enable digital sovereignty
  • What government expects from Indonesian enterprises in 2026, compliance timelines, incident reporting obligations, and the accountability gap between policy on paper and security in practice

09:20 AM – 09:35 AM

Embedding Indonesia’s Personal Data Protection Law into Enterprise Security Architecture

  • Transition to enforcement, what 350+ platform reviews reveal about where Indonesian organizations are falling short
  • Life post- Constitutional Court Decision No. 151/2024; how the “and/or” clarification affects enterprise accountability structures, data handling assignments, and breach response obligations
  • Navigating Regulatory Gaps in cross-border data environments, brought about by the gradual adoption of the Lembaga PDP and what to expect when the implementing regulation lands

09:35 AM – 09:50 AM

From First Response to Prosecution: Strengthening Cybercrime Investigation and Law Enforcement Response in Indonesia

  • Lessons from PDNS 2 and Brain Cipher on how quickly law enforcement can mobilise once a national-scale cyber incident is declared, and what still slows that response down today
  • How the Cybercrime Investigation Centre is building digital forensics capacity to keep pace with increasingly sophisticated ransomware and financial cybercrime operations
  • What Indonesian enterprises should actually expect from law enforcement during and after a breach – reporting timelines, evidence preservation, and the realistic path from incident to prosecution

09:50 AM – 10:10 AM

Autonomous Defence: Neutralizing Threats at Non-Human Speed

  • With 3.64 billion attacks in H1 2025, human-led threat detection is losing ground against modern adversaries in Indonesia and how AI response would look like in practice
  • How behavioural AI would have effectively identified the Brain Cypher attack during its 72-hour dormancy period before activation and what endpoint protection gaps the attack revealed across critical Indonesian infrastructure
  • From alert fatigue to agentic investigation, how Purple AI is undertaking complete forensic investigations at machine speeds effectively solving the SOC bottlenecks and helping shorten the time between detection and response

10:10 AM – 10:30 AM

Zero Trust Starts with Identity

  • How the PDNS 2 attack demonstrated that disabling a single security credential opened the door to a national-scale ransomware disaster
  • How Ping’s Identity for AI platform governs machine identities with time-bound, least-privilege access before they become the next major breach point
  • The practical roadmap for Indonesian CISOs to implement continuous, authentication across their workforce and customer base, curbing the credential vulnerabilities that attackers exploit most

10:30 AM – 11:00 AM

Panel Discussion

Recovering at the Speed of Attack - Building Data Resilience in the Age of Agentic AI

  • Why so many organizations remain confident in their recovery capabilities right up until the moment they actually need to recover, and what that gap looks like in practice across Indonesian enterprises
  • How agentic AI is compressing the timeline between initial compromise and full-scale damage, and what that means for how fast an organization actually needs to bounce back
  • Rethinking resilience for a hybrid, multi-cloud, identity-driven environment, where the real test isn’t preventing every attack but proving you can recover clean when one gets through

11:00 AM – 11:30 AM

NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE

11:30 AM – 11:50 AM

Fireside Chat

From Incident to Institution: What Indonesia's Most Significant Cyberattack Taught Us About Building a Resilient Digital State

  • Strengthening incident transparency and breach notification discipline across government institutions
  • Protecting national data repositories from mass exfiltration and credential compromise
  • Rebuilding institutional trust following high-visibility breach events

11:50 AM – 12:10 PM

Implementing Zero Trust in Complex Enterprise Environments: Lessons, Pitfalls, and Operational Realities

  • Usage of separate tools to monitor networks, manage devices, control access, and detect threats creating a fragmented picture where no single team has complete visibility
  • ManageEngine’s independently verified numbers reframe the conversation PAM360 delivers 219% ROI in under 4 months, Endpoint Central delivers 442% ROI over three years, and their SIEM solutions cut false positives by 90%, saving analyst hours that Indonesian security teams simply don’t have to waste
  • With generative AI projected to reduce employee-driven cybersecurity incidents by 40% through behaviour-specific training by 2026, the organizations that integrate AI into their IT management fabric now will be the ones that don’t make headlines next year

12:10 PM – 12:30 PM

From Vision to Deployment

  • The talk isn’t “here’s what agentic AI can do for your SOC”, rather “here’s what it’s already doing for Indonesian organizations.” Also, how this addressed the data sovereignty barrier
  • How Google’s Threat Hunting, Detection Engineering, and Alert Triage agents are delivering 90% faster threat detection in production
  • Managing legacy protocols, real-time operational requirements, and safety-critical environments

12:30 PM – 12:50 PM

The Human Firewall in the Age of AI

  • Why Southeast Asia leads the world in breach frequency, with APAC organizations experiencing 3.5 breaches per year versus 2.8 globally
  • How KnowBe4’s data from 70,000+ organizations proves that adaptive, AI-driven security training can reduce phishing susceptibility from 33% to 4.1% within 12 months
  • How Indonesian enterprises deploying bots, automated workflows, and AI copilots are creating a new class of non-human vulnerability that requires the same behavioural governance framework as their human workforce

12:50 PM – 01:00 PM

The Identity Gaps Nobody Talks About: How Lateral Movement Turned PDNS Into a National Crisis

  • 31% of enterprise accounts are service accounts; over-privileged, under-monitored, and invisible to standard security tools, gaps that exist in most Indonesian organizations
  • Indonesia’s banks, telcos, and government agencies run hybrid environments where Active Directory, legacy applications, and command-line interfaces sit alongside modern cloud platforms, and how Silverfort is the only platform that protects these blind spots without touching the underlying systems
  • Strengthening endpoint telemetry integration into incident containment workflows

01:00 PM – 02:00 PM

LUNCH BREAK

02:00 PM – 02:30 PM

Panel Discussion

Cloud Without Compromise - Securing Indonesia's Rapid Shift to Multi-Cloud and Hybrid Infrastructure

  • How rapid cloud adoption, API sprawl, and ecosystem partnerships are quietly building hidden dependencies that could unravel Indonesia’s digital resilience from the inside
  • Why security built into cloud architecture at design stage – across identity, data flows, and third-party integrations – is the only model that survives a $360 billion attack surface
  • How embedding cybersecurity leadership into core cloud and infrastructure decisions, not just compliance sign-off, is the governance shift separating resilient Indonesian enterprises from vulnerable ones

02:30 PM – 02:50 PM

Ransomware Response and Recovery: Lessons from Regional Breaches and Operational Disruptions

  • Why ransomware campaigns are escalating across Southeast Asia’s healthcare, financial, and public sector & what Indonesian enterprises can learn from every breach that happened before theirs
  • How to make the right call under pressure, containment, negotiation, disclosure, and restoration when every minute of downtime costs more than the last
  • What comes after the breach navigating regulatory reporting, rebuilding stakeholder trust, and recovering operationally when the damage is already done

02:50 PM – 03:20 PM

Panel Discussion

Cybersecurity 3.0 – Securing the Future of Hyperconnected and Autonomous Digital Economies

  • How machine-driven transactions, decentralized services, and digital identity are rewriting the rules of trust and what that means for how Indonesian enterprises enforce it
  • Why containing breaches after they happen is no longer a viable strategy and how Indonesian enterprises are shifting to security models that predict and adapt before the attack lands
  • How to build sustained cyber resilience in environments where automation, scale, and speed create competitive advantage all while attacks surface in equal measure

03:20 PM – 03:30 PM

NETWORKING & END OF DAY 1

08:00 AM – 09:00 AM

REGISTRATION & COFFEE

09:00 AM – 09:15 AM

Securing Indonesia's Maritime Frontier: Cybersecurity Challenges in National Surveillance Systems

  • How maritime surveillance systems – radar networks, vessel tracking, and coastal monitoring infrastructure – are becoming high-value targets in Indonesia’s expanding digital defence perimeter
  • The operational reality of securing legacy maritime sensor networks alongside modern satellite and AI-driven surveillance platforms, often running on infrastructure never designed with cyber resilience in mind
  • What it takes to protect the systems safeguarding Indonesia’s 17,000+ islands and vast territorial waters from both physical and cyber-enabled threats, and where BAKAMLA’s mandate intersects with national cyber defence

09:15 AM – 09:30 AM

Protecting Critical Information Infrastructure in a Digitally Interdependent National Economy

  • How a single compromised payment node took down 282 public services and what it takes to stop the cascade before it starts
  • Where does TNI’s mandate begin and civilian enterprise obligations end
  • Does the military cyber force arrive as a capable, doctrine-driven partner or as a mandate without a mechanism

09:30 AM – 09:50 AM

Where Indonesia's Cyber Resilience Framework Is Working & Where Business Is Still on Its Own

  • Addressing the gap between government policy ambition and enterprise operational reality
  • Having regulations that fit the workforce Indonesia has, enabling security not just mandating it
  • What a shared incident response and cross-enterprise cooperation building the security foundation means for Indonesia’s $200 billion digital economy

09:50 AM – 10:10 AM

What 661 Real Attacks Tell Us About How Indonesian Organizations Will Be Breached Next

  • Identity is simultaneously the most targeted and least protected layer of the stack, and attackers are reaching your Active Directory server within 3-4 hours of initial access
  • 88% of ransomware payloads deploy outside business hours; 79% of data exfiltration happens at night and on weekends, Sophos MDR fills this gap.
  • Indonesian organizations are losing to attackers using basic, proven techniques against fundamental security hygiene failures mandating work towards fixing the foundation first

10:10 AM – 10:30 AM

Trusted by Default, Breached at Scale: FortiBleed and the Supply Chain Blind Spot

  • Emergence of structured marketplaces selling network access, ransomware toolkits, and bulk stolen credentials
  • Specialization within cybercrime networks where reconnaissance, exploitation, and monetization are separated into services
  • Incorporating underground intelligence monitoring into proactive enterprise defence strategy

10:30 AM – 11:00 AM

Panel Discussion

Building Indonesia's Cyber Risk Backbone: Can Locally Built Solutions Meet the Demands of a $130 Billion Digital Economy?

  • Whether local certification is a meaningful quality signal or just a procurement checkbox
  • How the domestic cybersecurity industry is keeping pace with the now $130B Indonesian Digital Economy
  • Indonesian-built risk management platforms can realistically handle the complexity of securing a super-app, a national bank’s hybrid cloud infrastructure, or a telco network serving 270 million people, and whether the honest answer is a hybrid of local and global solutions

11:00 AM – 11:30 AM

NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE

11:30 AM – 11:50 AM

Fireside Chat

When Cyber Risk Becomes Business Risk: The Conversation Indonesian Boards Are No Longer Avoiding

  • How to make the board care about cybersecurity before the breach makes them.
  • What does a CEO or board member actually need to understand about cyber risk and what detail is counterproductive?
  • Developing internal offensive security capabilities that evolve alongside emerging attack techniques.

11:50 AM – 12:00 PM

You Already Have the Patch. Why Haven't You Applied It?

  • Most Indonesian organizations are being breached through unpatched, known vulnerabilities that have had fixes available for weeks or months, the remediation backlog is thus the problem
  • Qualys TruRisk Eliminate uses AI-driven risk scoring to automatically identify which vulnerabilities in your specific environment are being actively exploited right now and deploys patches autonomously before attackers can act
  • Establishing verification discipline and layered communication controls to reduce human exploitation vectors

12:00 PM – 12:10 PM

Indonesia's Security Blind Spots: Why Your Own Team Will Never Find What a Global Hacker Community Can

  • HackerOne’s global community of 300,000+ ethical hackers bring completely fresh eyes finding the vulnerabilities that internal teams and automated scanners consistently miss, before malicious actors find them first.
  • Compromise of smaller ecosystem participants providing indirect access into high-value networks and sensitive data repositories
  • Embedding real-time third-party risk visibility into procurement, vendor lifecycle management, and contractual security governance

12:10 PM – 12:20 PM

Cybersecurity as a Business Enabler: Why Indonesia's Chambers of Commerce Are Prioritizing Digital Trust

  • Why cybersecurity is becoming a competitiveness issue for Indonesian businesses, not just a regulatory checkbox, and what that shift means for companies trying to attract investment and partnerships
  • How industry bodies like KADIN are stepping in to help businesses, especially SMEs and mid-market enterprises, build baseline cyber resilience without world-class security budgets
  • What role business chambers play in bridging the gap between government cybersecurity policy and the operational reality of Indonesian enterprises

12:20 PM – 12:30 PM

Protecting Data Integrity in an Era of Silent Manipulation and Systemic Tampering

  • Data integrity is a regulatory requirement, not just a security best practice and most Indonesian banks cannot currently prove their records haven’t been tampered with
  • Subtle manipulation of transaction logs and operational dashboards creates systemic risk that cascades from individual institutions to market-wide trust
  • What detection mechanisms specifically look for checksum anomalies, log sequence breaks, behavioural deviations in write patterns and how GravityZone’s XDR layer surfaces integrity violations before they reach the board report

12:30 PM – 12:40 PM

See Everything, Store Everything: The Case for Unlimited SIEM in Indonesia

• Energy Logserver was built specifically for petabyte-scale log retention in high-security environments because you cannot investigate what was never recorded
• Their on-premises, open-architecture deployment keeps every log, every alert, and every forensic artifact entirely within Indonesian infrastructure
• Unlimited data model and flexible open-source licensing makes full-spectrum SIEM accessible to the Indonesian banks, telcos, and government agencies that currently rely on underpowered log management tools

12:40 PM – 12:50 PM

212 million Attack Surfaces: Why Indonesia's Mobile-First Economy Is Only as Secure as Its Weakest App

  • Guardsquare’s research reveals a $7 million security blindspot driven by organizational overconfidence
  • With 40,000+ API incidents in H1 2025 and 44% of advanced bot activity now targeting the APIs behind mobile apps rather than the apps directly, Indonesian banks and fintechs face a new attack surface they haven’t mapped
  • Guardsquare’s ThreatCast platform gives security teams real-time visibility into how their apps are being attacked in production right now not in a lab, not in theory, but on the devices of your actual Indonesian customers at this moment

01:00 PM – 02:00 PM

LUNCH BREAK

02:00 PM – 02:30 PM

Panel Discussion

The CISO Mandate - Leading Security in Indonesia's High-Stakes Digital Economy

  • Why the most sophisticated detection stack in your organization cannot protect you from the human decisions made above it
  • Why most insider threats aren’t malicious – they’re the predictable result of process gaps, operational pressure, and accountability that nobody clearly owns
  • How today’s CISOs are turning security awareness from a training checkbox into measurable operational discipline that holds under pressure

02:30 PM – 02:50 PM

Strategic Cybersecurity Investment in High-Growth Digital Economies: Balancing Expansion, Regulation, and Resilience

  • Why Indonesia’s digital expansion is outpacing its security budgets and what enterprises must prioritize when they cannot protect everything equally
  • How to allocate a constrained security budget across fraud prevention, cloud governance, incident response, and talent when the attack surface grows faster than the budget does
  • How to align security investment with regulatory expectations and national digital ambition before the auditor decides you didn’t

02:50 PM – 03:20 PM

Panel Discussion

Privileged Access, Public Exposure - Why Indonesia's Biggest Breaches Start With Someone Who Already Had the Keys

  • Why over-privileged accounts, not external attackers, are the fastest path to lateral movement across Indonesian banks, telcos, and government networks – and what PDNS 2 taught the country about who really holds the keys to critical systems
  • Rethinking privileged access as a living attack surface rather than a static IT control – session, credential, and vendor access that expands quietly until it becomes the breach nobody saw coming
  • Why “least privilege” remains a policy statement in most Indonesian enterprises rather than an operational reality, and what it actually takes to enforce time-bound, monitored, revocable access at scale

03:20 PM – 03:30 PM

NETWORKING BREAK & VISIT TO EXHIBITOR LOUNGE

16:00– 16:30

Red Carpet Moment with Paparazzi Lights

16:30 – 16:40

Opening Ceremony

16:40 – 16:50

Grand Premier Performance

16:50 – 17:00

Keynote Address from VIP Chief Guest

17:00 – 17:20

Introductory Address by the Jury Committee

17:20 – 18:00

Awards Presentation
Ceremony

18:00 – 18:10

Closing Performance

18:10 – 18:20

Closing Remarks

18:20 – 19:30

Cocktail & Gala Dinner

*The above is a running agenda and is subject to change

Stay Informed Subscribe to Our #IndoSec Newsletter