Skip to content
Cisco: 9 Out of 10 Companies in Indonesia Can’t Handle Modern Cyberattacks

Cisco: 9 Out of 10 Companies in Indonesia Can’t Handle Modern Cyberattacks

Industry Updates

By Patricia A. Pramono • Studio 1080, Published on June 12, 2025

Reports show that in 2025, most private companies in Indonesia remain critically unprepared to defend against the evolving cybersecurity threats of today.

According to Cisco’s Cybersecurity Readiness Index 2025, only 11% of organizations in Indonesia have achieved a mature level of readiness, a figure that equates to just 17 out of 158 surveyed companies. This highlights a widening disconnect between digital ambition and the operational resilience required to support it.

Meanwhile, cyberattacks have become significantly more complex. The attackers are now faster, more elusive, and increasingly equipped with advanced technologies like artificial intelligence (AI), tools that enable them to bypass traditional defenses with ease. Yet, many organizations continue to operate under outdated security assumptions, often unaware of the hidden vulnerabilities within their own systems.

The stakes have never been higher. A single breach today can compromise sensitive data, interrupt business operations, erode stakeholder trust, and result in serious financial and regulatory fallout. For companies navigating an increasingly competitive and digitized market, cybersecurity can no longer be treated as an IT issue, it must rather be viewed as a strategic business priority.

And yet, the data shows an alarming reality: the majority of Indonesia’s private sector is still far from ready.

A New Era of Digital Threats

The nature of cyberattacks has changed dramatically. No longer confined to traditional phishing or malware, modern threats are high-tech, persistent, and increasingly difficult to detect. From deepfake scams to multi-vector attacks on cloud infrastructure, today’s breaches are designed to move faster than human response.

Also read: Think Before You Click! How to Spot Phishing Scams and Protect Your Data ; From Fiction to Reality: How Deepfakes Are Changing Our World

49% of companies globally experienced at least one cyberattack in the past year, and 71% believe a major incident is likely to disrupt their business in the next 12 to 24 months (Cisco, 2025).

In Indonesia, the risks are even more pronounced. 92% of companies say they struggle to monitor devices connected to their corporate networks, while 84% face challenges managing complex, fragmented security systems (Cisco, 2025). These gaps create the perfect storm: limited visibility, slower response, and vulnerabilities across a growing attack surface.

Complicating this further is the rapid rise of Artificial Intelligence (AI) in both defense and offense.

AI has become a core part of cybersecurity strategies. It is used to automate detection, monitor behavior patterns, streamline response times, etc. But the same technology is also being weaponized by cyber attackers.

91% of organizations in Indonesia reported experiencing at least one AI-related security incident in the past year, including model theft, AI-enhanced social engineering, and data (Cisco,2025). 

Cisco has also found that, globally:

  • 43% of AI-related attacks involved model theft or unauthorized access
  • 42% used AI-enhanced social engineering
  • 38% were linked to data poisoning
  • 35% stemmed from prompt injection attacks

Yet despite this trend, only 48% of global companies believe their employees truly understand how attackers use AI to enhance their techniques. The gap in awareness is particularly dangerous when combined with the growing presence of shadow AI (tools used without approval or oversight). In Indonesia, 55% of companies admit they cannot reliably detect the use of unauthorized AI tools in their environments (Cisco, 2025).

These findings highlight that AI has the power to make defenses smarter and faster. But if mismanaged, it also opens the door to a new class of advanced, adaptive threats.

Also read: AI and Machine Learning, the Future of Cybersecurity 

Why Readiness Is Low in 2025

Cisco’s findings point to five key factors that explain the widespread lack of readiness among Indonesian companies:

  1. Shadow AI and Lack of Visibility
    Over 55% of companies are unable to detect unauthorized use of AI tools in their environments, a risk comparable to the early days of shadow IT.
  2. Unmonitored Devices and Complex Networks
    Hybrid work has increased device diversity, and 92% of companies struggle to track devices connected to their corporate networks. Moreover, fragmented security stacks make incident response slow and ineffective.
  3. Misplaced Confidence
    Despite widespread vulnerabilities, 73% of companies remain confident in their cybersecurity defenses, suggesting a dangerous gap between perception and reality.
  4. Severe Talent Shortage
    A staggering 95% of companies report difficulties filling cybersecurity roles, with many having 10 or more vacancies.
  5. Underinvestment in Security
    Although budgets have increased in absolute terms, only 45% of companies allocate more than 10% of their IT budget to cybersecurity. A drop from 53% in 2024.

Blind Spots in the AI Era: A Missing Piece in Most Strategies

Cisco’s report emphasizes five pillars that define cybersecurity maturity: Identity Intelligence, Machine Trustworthiness, Network Resilience, Cloud Reinforcement, and AI Fortification. Among these, AI Fortification remains the weakest link globally and in Indonesia, where organizations continue to face uncertainty in adopting AI-powered defenses at scale.

While many companies are exploring GenAI tools, few have implemented the necessary guardrails to manage them securely. And with over 60% of global IT teams lacking visibility into prompt inputs made through GenAI tools, making it difficult to monitor what employees are asking, what data is being fed into AI models, and what risks that might expose (Cisco, 2025). In environments where sensitive company or customer data is involved, this becomes a critical vulnerability.

This lack of preparedness creates a false sense of security. While companies might be eager to appear innovative by integrating GenAI into their processes, they are often doing so without the visibility, control, or security posture needed to manage its risks.

For Indonesia in particular, where AI-related incidents have already impacted 91% of companies (Cisco, 2025), the absence of an AI security strategy becomes a systemic weakness.

Recommendations for Improvement

To address these gaps, Cisco’s Cybersecurity Readiness Index 2025 also advises organizations to:

1.Establish a Zero Trust Framework

Assume no user or device is automatically trusted. Enforce continuous verification for every access request across the organization.

2. Integrate AI into Identity and Network Monitoring

Leverage AI to detect abnormal behavior, flag risks in real time, and strengthen security across users, endpoints, and network activity.

3. Invest in AI-Enhanced Cloud Infrastructure

Secure cloud environments with intelligent tools that adapt to evolving threats and protect data across hybrid and multi-cloud systems.

4. Modernize Endpoint and Device Defenses

Ensure all connected devices are protected with updated controls such as firewalls, endpoint detection and response, and vulnerability management.

5. Develop a Comprehensive AI Security Strategy

Create clear internal policies to manage AI use, including model governance, risk assessments, and protection of training data and outputs.

In addition to the global recommendations by Cisco, Cisometric also urge companies to consider localized, practical steps:

  • Cybersecurity Maturity Assessment

Start with an objective evaluation of your current business posture to identify blind spots and prioritize improvements.

  • Employee Awareness Programs

Ongoing training is essential, particularly as phishing and social engineering tactics evolve with AI.

  • SOC Modernization

Companies managing multiple, disconnected tools should consider a Next-Gen Security Operations Center (SOC), an integrated system that leverages AI for proactive threat detection and incident response.

Also read: What Makes a Next-Gen SOC—and Why Your Business Needs One Now 

  • Strategic Cybersecurity Partnerships

Building resilience isn’t a solo effort. Partner with experienced security consultants who can tailor strategies to your organizational needs, especially in high-risk sectors.

Also read: Get to Know Cisometric, As We Fortify Indonesia's Cybersecurity Maturity

Summary

The insights are derived from Cisco’s Cybersecurity Readiness Index 2025, a global study of 8,000 business leaders, including 158 from Indonesia. The report’s most urgent finding for us? Only 11% of Indonesian organizations are truly prepared to face modern cyber threats.

This is a reflection of the growing gap between digital ambition and cybersecurity maturity. As attacks become more sophisticated and AI-powered tools redefine both offense and defense, organizations can no longer rely on outdated security models or siloed solutions.

AI has introduced a new era in cybersecurity. It brings unprecedented speed and precision, but also new threats. Without a clear strategy, strong governance, and integrated defense, companies risk falling behind not just in protection, but in business resilience.

At Cisometric, we help organizations close this readiness gap. From AI-driven threat detection and Next-Gen SOC capabilities to employee training and cybersecurity maturity assessments, we provide tailored solutions to help companies navigate the complexities of today’s digital threats. 

Cyber risks will continue to grow. The question is: will your defenses grow with them?
If you're ready to take the next step toward real cyber readiness, we're here to help.

Contact our team to learn more. Click here.

Follow our social media for more updates:

LinkedIn: Cisometric

Instagram: @cisometric



Reference:

Riset Cisco: Mayoritas Perusahaan di Indonesia Belum Siap dengan Ancaman AI

Studi Cisco: Hanya 11% Organisasi di Indonesia Siap Hadapi Ancaman Siber di Era AI

2025 Cisco Cybersecurity Readiness Index Report 

You may like this...

We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy