A Hybrid Cyber Defense Framework for Indonesia’s Military Integration into National Cyber Resilience: A Counterfactual Stress-Test
DOI:
https://doi.org/10.34190/eccws.25.1.4825Keywords:
Cyber Defense, National Resilience, JCDTF, NCCC, Indonesia, Counterfactual Process Tracing, RUU KKSAbstract
The June 2024 ransomware attack on Indonesia’s National Data Center (PDN) disrupted hundreds of public services and exposed that the country’s cyber vulnerability extended beyond weak technical controls to include fragmented authority, unclear mandates, and slow coordination among state actors, which plausibly amplified the scale and duration of disruption. Existing work on Indonesia’s cyber defense and national cyber resilience often treats technological upgrades and institutional reform separately and rarely tests how alternative governance architectures might have altered the trajectory of a real incident. This paper asks whether a hybrid civil-military cyber defense framework could have reduced the operational impact of the PDN incident by mitigating coordination failures across detection, containment, and recovery phases. Drawing on open-source reporting, the study reconstructs an incident timeline and identifies three failure nodes: detection delay, containment delay, and recovery failure linked to backup governance. Conceptually, it refines existing socio-technical accounts by formalizing coordination failure as a second-order amplifier of cyber incident severity that links fragmented authority to decision latency and expanded incident impact once attackers gain a foothold. Building on prior work that designed a cyber defense framework for the Indonesian Armed Forces, the paper extends this architecture to a national civil-military setting by specifying a Hybrid Cyber Defense Framework centered on a civilian-led National Cyber Security Coordination Center (NCCC) with unified incident command and a Joint Cyber Defense Task Force (JCDTF) providing surge technical capacity under democratic safeguards. Using Counterfactual Process Tracing (CPT), grounded in an interventionist theory of causation, the analysis stress-tests this framework against the PDN timeline, holding baseline technical weaknesses constant while minimally rewiring decision paths and information flows at the three failure nodes. Analog evidence from NATO and Singapore suggests integrated monitoring, pre-designated leadership, and joint exercises can compress response cycles without replacing technical controls. The paper offers a mechanism-based template for stress-testing national cyber governance arrangements against concrete incident trajectories and clarifies the democratic boundary conditions under which hybrid civil-military integration is more likely to strengthen cyber resilience.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.