Looking ahead, I believe the single biggest challenge is fragmentation not a lack of cybersecurity technology, but the gap between technology, governance, skills, and coordinated execution.
To become genuinely cyber-resilient, Indonesia needs to move from a “protect the system” mindset to a “keep the country operating under attack” mindset. That means three things:
- Build security into critical infrastructure by design with strong identity controls, segmentation, immutable backups, continuous monitoring, and regular independent testing.
- Create much stronger national coordination and accountability so government, regulators, critical infrastructure providers, and the private sector share threat intelligence and follow consistent minimum-security standards. Indonesia already has a National Cybersecurity Action Plan for 2024 – 2028 and a BSSN strategic plan for 2025 – 2029; the key is translating those frameworks into measurable execution.
- Invest aggressively in people and local capability from cybersecurity professionals and incident responders to Indonesian security technology companies. Indonesia should ultimately be a producer of cybersecurity capability, not simply a consumer of foreign tools.
So, if I had to put it in one sentence: Indonesia’s biggest cybersecurity challenge is turning a collection of security initiatives into a coordinated, continuously tested national resilience capability and the next few years need to be about execution, accountability, and collaboration rather than simply buying more security technology.