Indonesia’s BSSN: Cyber resilience is national resilience, not just an IT issue

Indonesia’s cyber resilience strategy is focused on strengthening governance, human resources and collaboration across the digital ecosystem, said Air Vice Marshal Tjahjo Kurniawan, Deputy for Cybersecurity Strategy and Policy at National Cyber and Crypto Agency (BSSN).

BSSN Deputy Tjahjo Kurniawan stresses that cyber resilience is not simply an IT issue, but a matter of national resilience. Image: GovInsider

Rather than simply a technical issue, cyber resilience should be treated as part of national resilience. 


This was the stance taken by Indonesia’s Cyber and Crypto Agency (BSSN)’s Deputy for Cybersecurity Strategy and Policy, Air Vice Marshal Tjahjo Kurniawan. 


As the country now increasingly relies on digital technology to deliver public services, this expands the potential attack surface and disruptions are more likely to ripple into everyday life. 


Hence, cyber resilience needs to be built in by design. “When an electronic system is being built, from that moment onwards we must secure it as part of national resilience,” he said. 


Notably, he highlighted that Indonesia’s national cyber resilience strategy should go beyond adopting advanced technologies and focus on strengthening collaborations across society. 


Kurniawan was delivering his keynote at Securing Digital Transformation in Government: Building Cyber Resilience Through Converged Security, organised by GovInsider and Fortinet in Jakarta on August 11. 


According to him, cyberattacks cannot be completely avoided. The government’s task was to “ensure that digital services remain available, trusted by the public, and able to recover quickly when disruption occurs”. 


This approach was also closely linked to digital trust. When that trust erodes, digital transformation loses one of its key foundations. 

AI as both a defence tools and a threat 


He highlighted how artificial intelligence (AI) was adding further complexity to the threat landscape.


On the one hand, AI could help organisations analyse millions of security data points in a short period, identify attack patterns, automate analysis, and accelerate incident response.  


On the other hand, AI was also giving threat actors new capabilities to automate attacks, accelerate exploitation, and generate attacks that were more adaptive and difficult to detect.  


He also highlighted the evolution from generative AI (GenAI) towards agentic AI, where systems can plan and execute a series of tasks autonomously. 


This development made it increasingly important to ensure that humans remain involved in decision-making, he noted. 

Security is not just an IT responsibility  


Kurniawan emphasised the need for organisations to change how they approach security governance.


"Security should not be the sole responsibility of IT departments," adding that executives and decisionmakers must also understand their role in protecting their organisations. 


This is particularly important because attacks do not always exploit technological weaknesses. Human factors also become a point of vulnerability.  


He stressed on the importance of building cybersecurity awareness, including basic practices such as credential and password management.  


Even strong technology can be undermined by unsafe user behaviour. 


He referred to the disruption at Indonesia’s national data centre two years ago, which caused several public services to become unavailable due to poor password management


“However strong the technology is, without stronger cybersecurity awareness it will be futile, because human factors are more decisive than technology.”  


He therefore called for cyber literacy programmes to extend beyond operational and technical staff to executives, including ministers, director-generals, deputies and other senior decisionmakers.  

Building a collective defence ecosystem  


BSSN has been strengthening national capabilities through a range of initiatives, including the development of cybersecurity training centres, cryptography laboratories, and capabilities related to post-quantum cryptography and quantum key distribution. 


Kurniawan said that the government cannot build cyber resilience alone. Cyber threats now cross organisational and sectoral boundaries.  


Governments, the private sector, academia, communities, and international partners therefore need to work together. It is important for organisations to share information to address emerging threats. 


He likened the digital ecosystem to a chain of security. If one link breaks, the entire chain can be compromised.  


“Strengthening one institution alone is not enough if other institutions connected to it remain vulnerable,” he concluded.