Logo
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

Only 37% of organizations have a formal security process owner. ITSEC Asia, the cybersecurity leader in Indonesia, breaks down the Information Security Process Manager role and why it is the difference between a security program that functions and one that merely exists.

Ajeng HadeAjeng Hade
|
Mei 25, 2026
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

Introduction

Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs.

Sources: IBM Cost of a Data Breach Report 2024

What the Role Actually Owns

An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that connect strategy to execution. This includes owning the organization's threat detection workflows, managing the feedback loop between incident response findings and updated controls, and ensuring that frameworks like NIST Cybersecurity Framework 2.0 and MITRE ATT&CK are translated from reference documents into operational practice.

The scope is broader than most job descriptions acknowledge. Threat hunting program governance sits within this role, because threat hunting is not a one-time engagement but a repeatable, hypothesis-driven discipline that requires structured ownership to scale. Compromise assessment processes, which establish whether an organization has already been breached and what changed in the aftermath of an incident, require the same formal management. The SANS Institute's Threat Hunting Maturity Model describes how organizations move from reactive, ad hoc investigations to structured hunt programs with defined hypotheses, documented procedures, and measurable outcomes. That maturity progression does not happen by accident. It happens when someone owns the process.

Sources: NIST Cybersecurity Framework 2.0 · MITRE ATT&CK Framework · SANS Institute: Threat Hunting Maturity Model

Why Threat Hunting and Compromise Assessment Are Now Core Functions

Attacker breakout time, the window between initial access and lateral movement through a network, has collapsed to just 62 minutes for the fastest observed intrusions, with the average sitting at under three hours. Signature-based detection systems and periodic vulnerability scans operate on timescales that no longer match that threat reality. An Information Security Process Manager who understands this dynamic is responsible for ensuring that proactive detection capability, specifically threat hunting and compromise assessment, is embedded in the organization's standard security operations rather than treated as an optional or occasional activity.

Compromise assessment answers a question that organizations are often afraid to ask directly: is there an attacker in our environment right now? Done properly, it provides the forensic baseline that tells security teams what normal looks like, which is the foundation that threat hunting hypotheses are built on. Both functions generate detection logic that feeds back into the Security Operations Center's automated tooling, meaning every hunt cycle and every assessment improves the organization's overall detection posture. The Process Manager's role is to ensure that feedback loop actually closes rather than producing findings that sit in a report nobody acts on. For sectors that carry disproportionate risk, including healthcare, financial services, and critical infrastructure, undetected attacker dwell time, not breach response cost, is the primary driver of breach losses. Managing dwell time is a process problem before it is a technology problem.

Sources: CrowdStrike Global Threat Report 2024 · IBM Cost of a Data Breach Report 2024 · Ponemon Institute Data Breach Research 2024

The Frameworks, Standards, and Regulatory Pressure Shaping the Role

The external environment has made Information Security Process Management less optional in recent years. NIST CSF 2.0 explicitly elevated the Govern function, recognizing that cybersecurity strategy must be embedded in enterprise risk governance rather than siloed in IT. Regulators overseeing financial services and critical infrastructure, including BSSN through Indonesia's national cybersecurity strategy and the EU's NIS2 Directive internationally, increasingly expect organizations to demonstrate active, documented detection capability rather than perimeter defense alone. Auditors and regulators are asking to see evidence of process, not just evidence of tooling.

The MITRE ATT&CK framework gives Information Security Process Managers a structured vocabulary for that documentation. When a threat hunt is scoped, it can be mapped to specific ATT&CK techniques, which means the coverage of the organization's proactive detection program is visible, communicable to leadership, and auditable. When a gap is identified, the remediation can be tracked against the same framework. This kind of structured, evidence-based approach to security process management is increasingly what distinguishes organizations that satisfy regulators and recover cleanly from incidents from those that are caught without an adequate answer when a breach investigation begins.

Sources: NIST Cybersecurity Framework 2.0 · MITRE ATT&CK Framework · BSSN National Cybersecurity Strategy

Build the Process Capability Before the Incident Makes It Urgent

The organizations that experience the most damaging breaches are rarely those with the worst tools. They are the ones operating without formal process ownership: no one tracking whether threat hunting is happening systematically, no one ensuring that compromise assessment findings translate into updated detections, no one governing the feedback loop that turns security spend into measurable risk reduction. The Information Security Process Manager role exists to close that gap, and organizations that invest in this function before an incident forces it are the ones that recover faster, spend less, and demonstrate genuine security maturity to regulators and boards.

ITSEC Asia provides threat hunting, compromise assessment, digital forensics, and incident response capabilities for organizations across Indonesia, Singapore, Australia, and the UAE. If your organization wants to assess its current process maturity, establish formal ownership of detection and response workflows, or build proactive security capability before an incident makes it necessary, speak with our specialists directly.

👉 Consult with our security specialists https://itsec.asia/contact

Share this post

You may also like

This is Why You Should Automate Your Cybersecurity
Cybersecurity

This is Why You Should Automate Your Cybersecurity

DO YOU NEED TO AUTOMATE YOUR CYBERSECURITY OPERATIONS? The answer is likely "yes," and whenever I ask anyone about automation, they unequivocally state that automation will undoubtedly enhance the overall cybersecurity foundation if implemented correctly in their organizations. They say "if" because the organizations I speak with, not many of them have actually implemented automation into their operations, even if they intend to do so. They usually reason that they are too busy to stop and learn how. Here are some of the strongest reasons to automate... We live in a world where launching cyber attacks on an organization is far cheaper than defending it. To make matters worse, the threat landscape is becoming increasingly difficult to cover. You face exponentially growing threats where adversaries are getting the upper hand every day while your security tools incessantly warn you. Business resilience is the ultimate goal of any cybersecurity operation, and the only way to improve the overall resilience of your organization is to improve your overall efficiency in protecting it.

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 4 minutes read
Is Using a VPN Really Safe? Here’s the Reality Check.
Cybersecurity

Is Using a VPN Really Safe? Here’s the Reality Check.

INTRODUCTION Today, almost everything we do happens online, from working and studying to shopping and banking. While the internet makes life easier, it also comes with certain risks, especially when it comes to privacy and data security. Many people connect to public Wi-Fi in places like cafés, airports, or hotels without realizing that these networks may not always be secure. In some cases, attackers can monitor or intercept data that travels through these connections. This is where VPN apps become useful. A VPN app helps create a safer internet connection by protecting your data and hiding your online identity. Even if you are using an open network, a VPN can help keep your activity more private. This article will explain what a VPN app is, how it works, and why it has become an important tool for safer internet use. Source: pr.norton.com [https://pr.norton.com/blog/privacy/what-is-a-vpn?utm_], security.org [https://www.security.org/vpn/?utm_], fortinet.com [https://www.fortinet.com/resources/cyberglossary/vpn-wifi?utm_] WHAT IS A VPN APP? A VPN app is a tool that helps protect your internet connection and online activity. VPN stands for Virtual Private Network.

ITSEC AsiaITSEC Asia
|
Mar 13, 2026 6 minutes read
Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 7 minutes read

Receive weekly
updates on new posts

Subscribe