Cyber Security
The practice of protecting systems, networks and data from digital attack, covering technology, process and people.
Definition
Cyber security is the practice of protecting systems, networks, applications and data from unauthorised access, disruption or destruction, through a combination of technology, documented process and workforce behaviour.
Cyber security is often described as a technology discipline, which is misleading. It has three layers: technology controls such as encryption and access management, process controls such as risk assessment and incident response, and the human layer, meaning the behaviour of the people who operate the systems. A weakness in any one undermines the other two.
The common domains are network security, application security, identity and access management, data protection, and security operations. In regulated Indonesian sectors these map onto specific obligations: OJK expectations for banks, BSSN guidance for critical infrastructure, UU PDP for personal data, and ISO 27001 as the international management-system reference.
The distribution of real-world causes matters more than the neatness of the domains. The majority of breaches begin with a person rather than a defeated technical control: an employee who enters credentials into a convincing page, approves a fraudulent payment, or installs a file from a message. That is why the human layer is not a soft topic within cyber security but its most exploited surface.
At a glance
- Type
- Discipline
- Also known as
- Information security, cybersecurity, keamanan informasi
How it works
- 1
Identify what you hold: systems, data and their criticality to the business
- 2
Assess the threats against them, and the likelihood and impact of each
- 3
Implement controls proportionate to that risk, across technology, process and people
- 4
Monitor whether the controls remain effective as systems and threats change
- 5
Respond and recover when something fails, then feed what you learned back into the assessment
Key points
- Cyber security spans technology, process and people; strength in one does not compensate for weakness elsewhere
- Most breaches begin with a human action rather than a defeated technical control
- Controls should be proportionate to risk, which is also what regulators such as OJK and UU PDP ask for
- It is a continuing programme, not a project with a completion date
- Evidence matters as much as capability, because supervisors assess what you can demonstrate
Best practices
- Base the programme on a documented risk assessment rather than a tool shopping list
- Give the human layer a measurable target, not just an annual training completion figure
- Make security the easier path where possible, since controls people bypass do not protect anything
- Rehearse incident response before you need it, including the communication path
- Report outcomes to the board, not activity, since supervisors ask whether risk is falling
Real-world example
An Indonesian bank passes a technical penetration test with no critical findings, then loses funds weeks later when a finance employee approves a fraudulent transfer requested by someone impersonating a director. No technical control failed. The gap was in the human layer, which the test never examined.
How Claro helps
Claro addresses the human layer specifically, and makes it measurable rather than assumed. Bilingual phishing simulation across email, WhatsApp, SMS and voice, per-user risk scoring, department-level analytics, and exportable evidence mapped to OJK, UU PDP and ISO 27001 expectations.
Frequently asked questions
What is cyber security?
Cyber security is the practice of protecting systems, networks, applications and data from unauthorised access, disruption or destruction. It spans three layers: technology controls, documented process, and the behaviour of the people operating the systems.
What is the difference between cyber security and information security?
They are used interchangeably in most practical contexts. Information security is slightly broader in principle, covering information in any form including paper, while cyber security emphasises digital systems and networks.
Why is the human layer considered the weakest point?
Because most breaches begin with a person rather than a defeated technical control. Attackers target people because deceiving one employee is usually cheaper and more reliable than defeating encryption or a firewall.
What does cyber security mean for banking in Indonesia?
Banks carry sector-specific obligations on top of general practice, including OJK expectations for technology risk management with board accountability, UU PDP for personal data, and often ISO 27001 as the management-system reference. Awareness evidence is a recurring supervisory request.
Related terms
Human Risk Management
A security discipline that identifies, measures, and reduces the risk that people introduce through their everyday behavior.
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Security Awareness Training
Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.
Security Culture
The shared attitudes, beliefs, and everyday behaviors around security that exist across an organization, beyond formal policy and training.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo