Indonesia Doesn't Need More Alerts. It Needs Fewer Exposed Entry Points.

Image

In June 2024, ransomware took down Indonesia's Temporary National Data Centre. Immigration processing stopped at airports. Passport services stalled. Government agencies across the country lost access to systems overnight. The attackers had walked in through an open door, and Indonesia's cyber defences never saw them coming.

This wasn't a one-off. Government portals keep getting defaced. Credentials keep surfacing on underground markets by the hundreds of thousands. Ransomware groups have made Indonesian government offices, financial institutions, and manufacturers a routine part of their target list. Every one of these incidents starts the same way: a scanner finds an open, listening port, and from there it's just a matter of time.

This is the pattern we walked through with the room at ARGIOS Indonesia. Instead of better detection, what if the port was never there to find?

‍

The problem with defending an open door

Most enterprise security spends its budget watching the front door for intruders. Firewalls, intrusion detection, endpoint monitoring; all of it assumes the door has to stay open for legitimate traffic, so the job is to watch who walks through. 

That assumption is exactly what attackers rely on. Scan enough IP ranges for open SSH, RDP, or database ports, and eventually something answers. Once it does, the server exists on the map, and everything after that is a matter of patience and tooling.

For organisations running legacy applications that can't be patched fast enough, or infrastructure that has to stay reachable for remote teams and vendors, this isn't a hypothetical. It's the daily reality of operating in a threat environment where credential leaks are constant and ransomware crews treat government and financial targets as low-hanging fruit.

‍

Making the door disappear

SSHepherd, built by our partner FullArmor, takes a different approach entirely. Rather than watching an open port more closely, it closes the port. Completely. 

Authorised users still get controlled, real-time access to SSH, RDP, web servers, databases, and file transfer services. To anyone scanning from outside that authorised path, the server simply isn't there.

The effect cascades in a way that's easy to underestimate. No open port means no attack surface to exploit in the first place. No listening service means no log noise from scans and probes, which means security teams stop drowning in alerts that don't matter. And because there's nothing to find, lateral movement between systems has nowhere to start from.

For a country dealing with a steady drumbeat of breaches against exactly the kind of legacy, hard-to-patch, always-on infrastructure that government agencies and financial institutions run, that's not a minor efficiency gain. It's a different threat model altogether.

‍

What the room in Jakarta saw

When Frederick Chung, CEO of Level Five, walked the audience through SSHepherd at ARGIOS, the response wasn't polite applause for a good demo. It was recognition. Everyone in that room has read the same headlines about national data centres and government portals. What landed was the shift from "how do we detect this faster" to "how do we make sure there's nothing to detect."

Our Indonesian Country Manager, Budi, spent the day translating that idea into the specifics of the market: which systems, which sectors, which pain points. The conversations that followed made one thing clear. Indonesia isn't short on awareness of its cybersecurity gap. It's short on infrastructure that closes it.

That's the conversation we're continuing here. If your organisation is running critical infrastructure that has to stay accessible but can't afford to stay exposed, we'd like to talk.

‍