Logo
Cybersecurity

Your SOC Can’t Handle a Cyber Crisis Alone

The technical team may find the incident first. What happens next quickly becomes everybody else’s problem too.

ITSEC AsiaITSEC Asia
|
Sep 15, 2026
Your SOC Can’t Handle a Cyber Crisis Alone

Imagine a ransomware incident at 10:30 on a Tuesday morning.

The SOC detects suspicious activity and starts investigating. Soon IT needs to isolate systems. Management wants to know whether operations should continue. Legal needs facts. Communications may need to prepare a response. Someone has to decide whether customers or authorities need to be informed.

By lunch, cybersecurity has become an organizational exercise.

That reality is reflected in current training from the International Telecommunication Union. An ITU Academy incident response course currently open for applications uses three scenarios: a ransomware attack, a data breach and an attack affecting a national education system. Participants work through the incident response lifecycle using collaborative tabletop exercises.

The lesson is useful far beyond education. Incident response capability depends on how well different people can make decisions together.

Technical Skill Is Only One Layer

A strong SOC can identify malicious activity, analyse evidence and recommend containment. It still needs an organization around it that knows what happens next.

Useful incident response capability therefore spreads across several functions:

  • SOC and security teams investigate, contain and preserve evidence.
  • IT and infrastructure teams understand affected systems and recovery dependencies.
  • Management makes operational and risk decisions with incomplete information.
  • Legal and compliance teams assess regulatory and contractual obligations.
  • Communications teams prepare accurate information for employees, customers or other stakeholders.

None of these groups needs identical cybersecurity expertise.

They do need enough shared understanding to work through the same incident.

ITU’s 2026 Regional CyberDrill for the Americas illustrates that model. The exercise brought together technical and management officials from CIRT, CERT and SOC environments alongside cybersecurity authorities, ministries, regulators and academia. Its objectives included improving technical capability, communication, incident management and coordination.

Tabletop Exercises Reveal Awkward Questions Early

A tabletop exercise is deceptively simple. Give a team a plausible incident and ask what they would do.

Then keep asking questions.

Who can authorize taking a critical system offline? Who contacts the regulator? Can the organization restore the affected service? Who briefs the CEO? What happens if the person who normally approves something is unreachable?

Suddenly the incident response plan starts developing holes.

That’s useful. A simulation can reveal unclear ownership, outdated contact lists, missing escalation paths and assumptions that looked perfectly reasonable inside a document.

ITU’s cyber disaster response training uses this approach explicitly, combining tabletop scenarios with hands on exercises and debriefs to develop communication and decision making during cyber attacks.

Finding those gaps during an exercise is considerably cheaper than discovering them while ransomware is spreading.

Train the Team Around the Technology

Technical cyber range exercises remain valuable, particularly for SOC analysts and incident responders. The next step is connecting those technical exercises with the people who have to act on their findings.

A realistic scenario might begin with analysts investigating suspicious activity, then require a handover to management, an operational decision from IT and a concise briefing for communications.

That type of practice fits naturally within ITSEC Cyber & AI Academy, where scenario based learning can help participants connect technical cybersecurity capability with the coordination and judgment required during real incidents.

The SOC may be the first room where the alarm goes off.

A prepared organization knows what every other room does next.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU Academy: Incident Response for Secure School Connectivity · ITU: 16th Regional CyberDrill for the Americas, 2026 · ITU Academy: Cyber Disaster Response Simulation Exercises

Share this post

You may also like

Human + AI: Why the Future of Offensive Security Isn't Human vs Machine
Cybersecurity

Human + AI: Why the Future of Offensive Security Isn't Human vs Machine

Artificial intelligence is transforming cybersecurity. From threat detection and vulnerability management to attack simulations and security operations, AI is enabling organizations to process information faster and automate tasks that once required significant manual effort. As AI adoption accelerates, a common question continues to emerge: Will AI replace cybersecurity professionals? The short answer is no. In reality, the future of offensive security is not about humans competing against machines. It is about combining the strengths of both to create a more effective and sustainable approach to cybersecurity. WHY OFFENSIVE SECURITY IS BECOMING MORE CHALLENGING Modern environments are more complex than ever. Organizations are embracing cloud computing, APIs, remote work and AI-driven applications. At the same time, threat actors are leveraging automation and AI to identify and exploit vulnerabilities faster. Security teams face several challenges: * Expanding attack surfaces. * Increasing volumes of vulnerabilities. * Limited cybersecurity resources. * Alert fatigue. * Time-consuming manual processes. * Growing compliance requirements. As environments continue to evolve, relying exclusively on traditional approaches becomes increasingly difficult. This is where

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read
Data Protection and Cybersecurity Laws in the Asia-Pacific Region
Cybersecurity

Data Protection and Cybersecurity Laws in the Asia-Pacific Region

Info

Apart from sales and trade, the majority of internet users utilize it for socializing and interacting with peers online. For instance, there were 3.8 billion social media users in January 2020, which represents a 9 percent increase from the previous year. The advancements in internet and related communication technologies enable easy access to information from anywhere on the planet. For example, an online merchant operating in Thailand can offer their services to customers residing in the European Union and the United States. In order to address the dissemination of personal information, including financial, medical, and other types of personal data, worldwide through the internet, appropriate legal regulations need to be established to protect the personal data of citizens and the digital assets of organizations while working online. Following the implementation of the General Data Protection Regulation (GDPR) in the European Union (which came into effect on May 25, 2018), which governs data protection and privacy in EU countries and regulates the transfer of personal data outside the European Union and

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 11 minutes read
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

INTRODUCTION Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] WHAT THE ROLE ACTUALLY OWNS An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that

|
Mei 25, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe