Jakarta, INTI - Cyber threats against businesses worldwide, including in Indonesia, have reached record highs in 2024. Companies are increasingly facing challenges in identifying which threats pose the greatest financial risks to their operations. One notable trend is cybercriminals shifting their focus to mid-sized organizations, which often possess valuable data but lack the robust cybersecurity infrastructure of larger enterprises.
This article delves into how evolving cyber threats target mid-sized organizations, their impact on businesses in Indonesia, and mitigation steps to tackle these challenges effectively.
Key Facts About Cyber Threats in 2024
- Vendor Outages: 47% of UK companies experienced vendor outages lasting more than 12 hours. In Indonesia, similar data highlights significant reliance on third-party vendors in the business ecosystem.
- Average Cost of Cyber Breaches: In 2023, the average cost of cyber breaches in the UK reached £10,830. In Indonesia, reports from the National Cyber and Encryption Agency (BSSN) estimate cybercrime losses in trillions of rupiah annually.
- Financial Risk Awareness: 54% of UK companies utilize quantitative risk registries to track financial impacts. However, in Indonesia, this practice is primarily adopted by larger enterprises.
The Primary Threat: Ransomware and Regulatory Focus on Data Breaches
Ransomware, a type of malicious software that encrypts files until a ransom is paid, has been identified as the leading cyber threat globally. In Indonesia, similar trends show a rise in ransomware attacks targeting both government institutions and the private sector.
However, regulatory pressures, such as Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions (PSTE), have driven many companies to focus more on preventing data breaches. This disproportionate emphasis often shifts attention away from the equally dangerous threat of ransomware.
Weaknesses in Third-Party Vendor Management
Research by Resilience and YouGov highlights vendor management as a critical weak point in corporate cybersecurity strategies. Only 35% of business leaders in the UK believe that vendor due diligence is an effective risk mitigation tool.
In Indonesia, reliance on third-party vendors for IT services, logistics, and other operations has surged. Unfortunately, most companies lack adequate due diligence mechanisms to manage these risks, increasing the likelihood of attacks exploiting vendor security gaps.
Cybersecurity Education Challenges for Mid-Sized Companies
Employee cybersecurity education programs are often the most recognized mitigation strategy. However, research shows that these programs are not always effective without a holistic approach.
In Indonesia, small and mid-sized enterprises (SMEs) are particularly vulnerable to cyberattacks due to limited resources for cybersecurity training. This is concerning, as SMEs contribute over 60% of Indonesia’s GDP, according to the Indonesian Employers Association (Apindo), making vulnerabilities in this sector a significant threat to the national economy.
Why Are Mid-Sized Companies Prime Targets?
Mid-sized organizations are often considered "soft targets" by cybercriminals due to the following reasons:
- Limited Resources: Less comprehensive security infrastructure compared to larger firms.
- Valuable Data: Possession of customer data or sensitive information with high market value.
- Lack of Risk Awareness: Insufficient understanding of cyber threats and mitigation strategies.
In Indonesia, growing businesses face similar challenges. Many companies have yet to recognize the importance of allocating budgets for cybersecurity as a long-term investment.
Steps Toward Cyber Resilience in Indonesia
According to Vishaal Hariprasad, CEO of Resilience, traditional approaches to managing cyber risks are no longer sufficient. To build cyber resilience, organizations must:
- Adopt a Financial Lens: Assess cyber risks as financial risks to enable better decision-making.
- Invest in Security Technology: Leverage advanced technologies like AI and analytics for real-time threat detection and response.
- Enhance Awareness and Education: Involve all organizational levels in comprehensive cybersecurity awareness programs.
The Role of Government and Private Sector in Addressing Cyber Threats
Collaboration among government entities, private companies, and academic institutions is key to tackling cyber threats. The Indonesian government, through BSSN, has launched various initiatives to raise awareness of cybersecurity's importance, including training and certifications for IT professionals.
However, these efforts must be expanded to promote the adoption of cybersecurity technologies in the SME sector and offer incentives to companies investing in security infrastructure.
The growing sophistication of cyber threats requires a more strategic and collaborative approach. Mid-sized organizations in Indonesia must realize that cyber risks are not merely technological challenges but business risks that directly impact operational sustainability.
By embracing advanced technologies, increasing employee awareness, and adopting a financial perspective, companies can build stronger cyber resilience. These measures are crucial to safeguarding valuable data and maintaining customer trust amidst an increasingly complex threat landscape.