Massive digitalization brings proportional vulnerabilities. The government is no longer just securing the country's physical borders (land, sea, air), but also maintaining sovereignty in cyberspace. Ransomware attacks on hospitals or the hacking of national population databases are real forms of asymmetric warfare in the modern era.
National Vital Information Infrastructure (IIV), which includes the energy sector (PLN), finance (BI/OJK), transportation (airports/ports), to health services, has become the primary target for state-sponsored hacker groups as well as cybercrime syndicates for ransom.
The National Cyber and Crypto Agency (BSSN) is mandated to orchestrate Indonesia's cyber defense. Its main step is to require every IIV operator agency to conduct regular security audits (penetration testing) and form a Computer Security Incident Response Team (CSIRT) that is ready to handle incidents within minutes.
Besides strengthening from the technical (firewall, encryption) and regulatory sides, the weakest point in cybersecurity is always the human factor (human error). Cybersecurity awareness training for all state officials, from staff level to ministers, is an absolute investment that can no longer be delayed.