Logo
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

Only 37% of organizations have a formal security process owner. ITSEC Asia, the cybersecurity leader in Indonesia, breaks down the Information Security Process Manager role and why it is the difference between a security program that functions and one that merely exists.

|
Mei 25, 2026
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

Introduction

Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs.

Sources: IBM Cost of a Data Breach Report 2024

What the Role Actually Owns

An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that connect strategy to execution. This includes owning the organization's threat detection workflows, managing the feedback loop between incident response findings and updated controls, and ensuring that frameworks like NIST Cybersecurity Framework 2.0 and MITRE ATT&CK are translated from reference documents into operational practice.

The scope is broader than most job descriptions acknowledge. Threat hunting program governance sits within this role, because threat hunting is not a one-time engagement but a repeatable, hypothesis-driven discipline that requires structured ownership to scale. Compromise assessment processes, which establish whether an organization has already been breached and what changed in the aftermath of an incident, require the same formal management. The SANS Institute's Threat Hunting Maturity Model describes how organizations move from reactive, ad hoc investigations to structured hunt programs with defined hypotheses, documented procedures, and measurable outcomes. That maturity progression does not happen by accident. It happens when someone owns the process.

Sources: NIST Cybersecurity Framework 2.0 · MITRE ATT&CK Framework · SANS Institute: Threat Hunting Maturity Model

Why Threat Hunting and Compromise Assessment Are Now Core Functions

Attacker breakout time, the window between initial access and lateral movement through a network, has collapsed to just 62 minutes for the fastest observed intrusions, with the average sitting at under three hours. Signature-based detection systems and periodic vulnerability scans operate on timescales that no longer match that threat reality. An Information Security Process Manager who understands this dynamic is responsible for ensuring that proactive detection capability, specifically threat hunting and compromise assessment, is embedded in the organization's standard security operations rather than treated as an optional or occasional activity.

Compromise assessment answers a question that organizations are often afraid to ask directly: is there an attacker in our environment right now? Done properly, it provides the forensic baseline that tells security teams what normal looks like, which is the foundation that threat hunting hypotheses are built on. Both functions generate detection logic that feeds back into the Security Operations Center's automated tooling, meaning every hunt cycle and every assessment improves the organization's overall detection posture. The Process Manager's role is to ensure that feedback loop actually closes rather than producing findings that sit in a report nobody acts on. For sectors that carry disproportionate risk, including healthcare, financial services, and critical infrastructure, undetected attacker dwell time, not breach response cost, is the primary driver of breach losses. Managing dwell time is a process problem before it is a technology problem.

Sources: CrowdStrike Global Threat Report 2024 · IBM Cost of a Data Breach Report 2024 · Ponemon Institute Data Breach Research 2024

The Frameworks, Standards, and Regulatory Pressure Shaping the Role

The external environment has made Information Security Process Management less optional in recent years. NIST CSF 2.0 explicitly elevated the Govern function, recognizing that cybersecurity strategy must be embedded in enterprise risk governance rather than siloed in IT. Regulators overseeing financial services and critical infrastructure, including BSSN through Indonesia's national cybersecurity strategy and the EU's NIS2 Directive internationally, increasingly expect organizations to demonstrate active, documented detection capability rather than perimeter defense alone. Auditors and regulators are asking to see evidence of process, not just evidence of tooling.

The MITRE ATT&CK framework gives Information Security Process Managers a structured vocabulary for that documentation. When a threat hunt is scoped, it can be mapped to specific ATT&CK techniques, which means the coverage of the organization's proactive detection program is visible, communicable to leadership, and auditable. When a gap is identified, the remediation can be tracked against the same framework. This kind of structured, evidence-based approach to security process management is increasingly what distinguishes organizations that satisfy regulators and recover cleanly from incidents from those that are caught without an adequate answer when a breach investigation begins.

Sources: NIST Cybersecurity Framework 2.0 · MITRE ATT&CK Framework · BSSN National Cybersecurity Strategy

Build the Process Capability Before the Incident Makes It Urgent

The organizations that experience the most damaging breaches are rarely those with the worst tools. They are the ones operating without formal process ownership: no one tracking whether threat hunting is happening systematically, no one ensuring that compromise assessment findings translate into updated detections, no one governing the feedback loop that turns security spend into measurable risk reduction. The Information Security Process Manager role exists to close that gap, and organizations that invest in this function before an incident forces it are the ones that recover faster, spend less, and demonstrate genuine security maturity to regulators and boards.

ITSEC Asia provides threat hunting, compromise assessment, digital forensics, and incident response capabilities for organizations across Indonesia, Singapore, Australia, and the UAE. If your organization wants to assess its current process maturity, establish formal ownership of detection and response workflows, or build proactive security capability before an incident makes it necessary, speak with our specialists directly.

👉 Consult with our security specialists https://itsec.asia/contact

Share this post

You may also like

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace. That gap is becoming harder to ignore. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%. The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology. NEW TECHNOLOGY CREATES NEW SECURITY SKILLS A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities. An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them. A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive. The

ITSEC AsiaITSEC Asia
|
Agu 27, 2026 — 4 minutes read
Calculating the Cost of Securing Your Business
Cybersecurity

Calculating the Cost of Securing Your Business

Tips

As the strategic importance of information security continues to grow for organizations of all sizes, and the complexity of information security increases across industries, business decisions are increasingly driven by the need to protect their intellectual assets and safeguard their IT infrastructure from evolving cybersecurity threats. Securing customer records, protecting sensitive financial information, and complying with regulatory requirements can create significant pressures on IT decision-makers and their resources. While many organizations have traditionally outsourced critical elements of their IT operations to managed service providers, more and more businesses are proactively outsourcing their security functions to specialized information security service providers. This has led to a need for evaluating the benefits of outsourcing security elements and comparing them to managing these processes internally. I wrote this article to help business leaders understand the best way to approach Managed Security Service Providers (MSSPs) in the context of Total Cost Ownership (TCO), a subject that is frequently discussed and of interest to both technical and non-technical leaders. INTERNAL SOLUTIONS OR OUTSOURCING? The key to evaluating

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 — 8 minutes read
The Next Identity Skills Gap Is Hiding Behind the Login Screen
Cybersecurity

The Next Identity Skills Gap Is Hiding Behind the Login Screen

Most people understand authentication as a familiar sequence. Enter credentials, prove who you are and access the application. Modern systems keep working long after that login screen disappears. Applications use identity and access tokens to determine what users and workloads are allowed to do. Tokens support capabilities such as single sign-on, federation and API access. NIST describes them as a central part of access management infrastructure and zero trust architectures. On 15 September, NIST finalized IR 8587 with CISA involvement, providing implementation guidance for protecting tokens and assertions from forgery, theft and misuse. The publication covers identity providers, authorization servers, cryptographic key protection, token verification and lifecycle controls. For cybersecurity teams, there’s a workforce implication hiding inside that architecture. IDENTITY SECURITY HAS BECOME AN ENGINEERING SKILL IAM can sound administrative: create accounts, assign permissions, remove access when someone leaves. Those responsibilities remain. Cloud applications, APIs and machine identities have added another technical layer. Security professionals increasingly need to understand: * How tokens are issued, validated, renewed and revoked * How SSO and federation

ITSEC AsiaITSEC Asia
|
Sep 23, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe