{
  "id": 6222434,
  "title": "Cybersecurity governance: From bureaucracy to real-world threats",
  "url": "https://urgent.news/2026/09/08/cybersecurity-governance-from-bureaucracy-to-real-world-threats",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-08T03:10:10.000Z",
  "source": {
    "name": "The Jakarta Post",
    "slug": "the-jakarta-post",
    "url": "https://www.thejakartapost.com/opinion/2026/09/08/cybersecurity-governance-from-bureaucracy-to-real-world-threats.html"
  },
  "original_language": "en",
  "account": "The article examines cybersecurity governance across Southeast Asian nations, highlighting the varying levels of preparedness in the face of growing digital threats. Singapore leads the region with a well-established Cyber Security Agency since 2015, characterized by clear laws, skilled personnel, and robust international partnerships. Malaysia employs a pragmatic approach, sharing responsibilities between CyberSecurity Malaysia and the National Cyber Security Agency, and emphasizes strong public-private collaboration. Thailand and Vietnam have also advanced by passing comprehensive cybersecurity frameworks in 2019 and 2018, enabling them to rapidly scale up their defensive mechanisms.\n\nCambodia, Laos, and Myanmar are still in the early stages, working on establishing basic Computer Emergency Response Team (CERT) capabilities and foundational legal frameworks. Indonesia, meanwhile, has made some progress with the consolidation of national cybersecurity authority under the National Cyber and Crypto Agency (BSSN) in 2017. This move brought together critical infrastructure protection, cryptographic standards, and incident response under one umbrella. The enactment of the Personal Data Protection (PDP) Law in 2022 demonstrated lawmakers' recognition of the scale of digital economy protection needed.\n\nDespite these advancements, the article points out a troubling reality. In 2021 alone, two major data breaches occurred - one at the national health insurance provider BPJS Kesehatan, exposing the personal data of approximately 279 million citizens, and another at the General Elections Commission, which leaked 2.3 million voter records. The following year saw significant data exposures at state-owned giants PLN and Pertamina. By mid-2024, the Brain Cipher ransomware attack crippled the Temporary National Data Center (PDNS), underscoring the vulnerability of centralized public infrastructure.\n\nThe situation illustrates that while there is genuine ambition in Indonesia, persistent structural vulnerabilities continue to hinder effective cybersecurity governance. The article concludes by urging for real enforcement power, adequate funding, and urgent action to address these pressing threats.",
  "summary": "We have the blueprints to defend our digital sovereignty, but without real enforcement power, adequate funding and urgency on AI and quantum threats, the next massive breach is already penciled in.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}