Indonesian Political, Business & Finance News

Cybersecurity foundations must be strengthened to face AI advancements

| Source: ANTARA_ID Translated from Indonesian | Technology
Cybersecurity foundations must be strengthened to face AI advancements
Image: ANTARA_ID

Jakarta (ANTARA) - Organisations, including companies and institutions, are deemed to need a strengthening of their cybersecurity system foundations to face the development of Artificial Intelligence (AI), which presents the potential for increased cyberattack threats.

“Although the risks posed by advanced AI are not yet fully understood, organisations still need to strengthen their cybersecurity foundations,” said Adithya Nugraputra, Head of Consulting at Ensign InfoSecurity Indonesia, during a discussion in Jakarta on Wednesday.

According to him, strengthening cybersecurity foundations can include routinely scanning assets accessible via the internet, implementing security system updates, and testing system defences against the latest AI models.

As AI capabilities are evolving rapidly, he stated that cybersecurity managers can no longer rely on static systems.

According to the Ensign 2026 Cyber Threat Landscape Report, the use of AI in cyberattacks is increasingly expanding in the Asia Pacific region.

AI is considered capable of enhancing cyberattack techniques already used by actors, although it does not necessarily replace existing methods.

Techniques still widely used include ‘living-off-the-land’, which involves utilising tools and features already available within the victim’s system. The application of this technique makes malicious activities harder to distinguish from legitimate activities.

First, organisations are advised to treat identity as the first line of defence. Because attackers are now more frequently using valid credentials rather than breaking into systems, system managers need to enhance authentication systems for employees, suppliers, administrators, as well as inactive or over-privileged accounts.

Second, organisations are recommended to manage all assets connected to the internet. Remote access, edge devices, and cloud services can serve as entry points for attackers. Therefore, organisations need to maintain a complete asset inventory and establish deadlines for patching or decommissioning exposed assets.

Third, organisations are advised to apply the same security standards to third parties. Suppliers and service providers with access to a company or institution’s environment can also serve as attack entry points. Consequently, external accounts should have access time limits and be revoked immediately when no longer required.

Fourth, organisations need to monitor data leaving the organisation, not just incoming data. Monitoring should include the volume and destination of outbound data, as well as mechanisms to halt data transmission when necessary.

Fifth, organisations are encouraged to strengthen recovery capabilities during an ongoing attack. Data backups, services, and administrator access can also be targets of attacks. System managers must ensure that recovery processes have been tested and validated, including having procedures to rebuild systems from scratch and establishing decision-making authority during an attack.

“Humans are very, very critical because as technology gets faster, humans continue to learn and experiment. That is what can help companies improve their security,” said Adithya.

In ASEAN, ransomware activity was recorded to have doubled in 2025, with 18 major ransomware groups targeting the region. Data theft is also a primary goal for cyberattack actors.

Attackers utilise edge devices, remote access infrastructure, and third-party suppliers as entry points into target systems, including through unpatched vulnerabilities.

Ensign InfoSecurity also stated in its report that hacktivism has targeted more critical infrastructure in ASEAN, with targets including utility services, energy, transport, telecommunications, and government organisations. The banking, finance and insurance, manufacturing and industry, as well as telecommunications, media, and technology sectors are also targeted due to their possession of valuable data and the operation of essential services.

View JSON | Print