Logo
Cybersecurity

Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

Most organizations detect breaches after 194 days of attacker activity already inside their network. ITSEC Asia, the cybersecurity leader in Indonesia, explains why Threat Hunting is the proactive discipline that changes that equation for good.

Ajeng HadeAjeng Hade
|
Mei 12, 2026
Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

Introduction

Here is a question every security leader should sit with: if an attacker entered your network six months ago, would you know? According to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach now stands at 194 days, nearly half a year of undetected attacker activity operating freely within enterprise infrastructure. Prevention tools, no matter how sophisticated, have already demonstrated they cannot close that window on their own. Firewalls, antivirus software, and multi-factor authentication are necessary. They are not sufficient.

The organizations that understand this distinction are the ones investing in threat hunting: the proactive, intelligence-driven practice of searching for adversaries who have already bypassed the perimeter and are operating in silence. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works with organizations across these regions to build this exact capability before the next breach makes it urgent.

Sources: IBM Cost of a Data Breach Report 2024

The Gap That Reactive Security Cannot Close

The fundamental flaw in reactive cybersecurity is architectural. Security Operations Centers monitor known threat signatures and fire alerts when something matches an established pattern. Endpoint detection tools watch for behaviors that resemble known malware. These systems are valuable, but they are built around what is already understood. Sophisticated threat actors, including nation-state groups and advanced ransomware operators, have spent years learning how to operate within the boundaries of what detection systems consider normal.

CrowdStrike's Global Threat Report documents how attacker breakout time (the window between initial access and lateral movement through a network) has collapsed to just 62 minutes for the fastest observed intrusions, with the average sitting at under three hours. By the time a signature-based alert fires, the attacker has already moved. Threat hunting inverts this dynamic entirely. Rather than waiting for an alert to signal that something went wrong, threat hunters operate from the assumption that a capable attacker is already present and begin searching the environment for indicators of that presence. It is the difference between responding to fire alarms and sending investigators to find smoldering wires before the building ignites.

Sources: CrowdStrike Global Threat Report 2024 · IBM Cost of a Data Breach Report 2024

How Threat Hunting Actually Works

Threat hunting is a hypothesis-driven discipline, not a passive monitoring function. A threat hunter begins with an assumption grounded in threat intelligence and then queries the environment specifically for evidence of adversarial behavior. This process relies on high-fidelity telemetry: comprehensive endpoint logs, network flow data, authentication records, and cloud activity feeds that provide the raw material for investigation. According to SANS Institute research on threat hunting maturity, organizations at higher maturity levels move from ad hoc investigation to structured, repeatable hunt programs with defined hypotheses, documented procedures, and measurable outcomes.

A mature threat hunting program typically operates across three core activities: 

• Hypothesis Formation: Each hunt begins with a threat intelligence-informed assumption, for example that a specific actor group known to target financial institutions tends to abuse Windows Management Instrumentation for lateral movement, and then validates or disproves that assumption through deep log analysis.

• Telemetry Analysis: Hunters examine endpoint behavior, authentication anomalies, unusual network flows, and privilege escalation patterns that automated tools routinely miss because they do not match known-bad signatures.

• Detection Engineering: Every completed hunt, whether it surfaces an attacker or confirms a clean environment, produces refined detection logic that improves the automated systems the SOC relies on going forward.

MITRE ATT&CK, the globally recognized framework cataloging adversary tactics, techniques, and procedures, provides the structured vocabulary threat hunters use to formulate hypotheses and ensure consistent coverage across the kill chain. Organizations that align their hunting programs to ATT&CK demonstrate systematic thinking about attacker behavior rather than chasing individual incidents in isolation.

Sources: SANS Institute: Threat Hunting Maturity Model · MITRE ATT&CK Framework

The Industries That Cannot Wait for an Alert

The consequences of skipping threat hunting are not evenly distributed. Organizations in healthcare, financial services, critical infrastructure, and telecommunications carry disproportionate risk because they hold data and control systems that sophisticated adversaries explicitly prioritize. The Ponemon Institute's 2024 research places the average cost of a healthcare data breach at USD 9.77 million, the highest of any sector for the fourteenth consecutive year. These numbers are not driven primarily by the cost of breach response. They are driven by the cost of undetected attacker dwell time: the months during which an adversary moved through a network, exfiltrated data, and established persistence before anyone noticed.

Regulatory frameworks governing these industries have also begun to reflect this reality. NIST's Cybersecurity Framework 2.0 explicitly incorporates continuous monitoring and proactive threat detection as core security functions. Regulators in Indonesia through BSSN's national cybersecurity strategy and internationally through frameworks like the EU's NIS2 Directive increasingly expect organizations to demonstrate active threat detection capability, not merely perimeter defense. For organizations operating in these environments, the question is no longer whether threat hunting belongs in the security program. It is whether the capability is mature enough to be effective when it is needed most.

Sources: Ponemon Institute Data Breach Research · NIST Cybersecurity Framework 2.0 · BSSN National Cybersecurity Strategy

Build Threat Hunting Readiness Before the Incident Forces It

The organizations that keep getting compromised twice are not unlucky. They are operating without the investigative and proactive capability that would tell them, with certainty, whether an attacker is present right now and what changed after the last incident. Threat hunting closes that gap by turning passive telemetry into active intelligence and converting security spend from a reactive cost center into a genuine risk reduction function.

The time to build this capability is before an attacker makes it necessary. ITSEC Asia provides threat hunting, digital forensics, and incident response capabilities for organizations across Indonesia, Singapore, Australia, and the UAE. If your organization wants to assess its current threat hunting maturity or build proactive detection capability before an incident forces the conversation, speak with our security specialists.

👉 Consult with our security specialists https://itsec.asia/contact

Share this post

You may also like

A Guide to CSOC
Cybersecurity

A Guide to CSOC

Hacks

CSOC stands for Cyber Security Operation Center, but it can be a bit confusing because CSOC teams can also be referred to as Computer Security Incident Response Teams (CSIRT), Computer Incident Response Centers (CIRC), Security Operations Centers (SOC), or Computer Emergency Response Teams (CERT). For the purpose of this article, we will stick to the term CSOC. CSOC works in defense to combat unauthorized activities occurring in strategic networks. Its activities include monitoring, detection, analysis, response, and restoration. CSOC is a team of network security analysts organized to detect, analyze, respond to, report, and prevent network security incidents 24/7, 365 days a year. There are various types of CSOCs categorized based on their organizational and operational models, so let's delve deeper and take a closer look at the different types of CSOCs. Virtual CSOC: As the name suggests, this type of operation often lacks dedicated facilities, and team members work periodically using a reactive approach to cyber threats. I believe that the reactive capabilities of virtual CSOCs cannot be sustained

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 7 minutes read
Post-Quantum Cryptography Readiness with ITSEC
Cybersecurity

Post-Quantum Cryptography Readiness with ITSEC

For decades, public-key cryptography has been the backbone of protecting sensitive information, such as financial transactions, personal data, corporate communications, and government secrets. Whether logging into a secure banking app, shopping online, or browsing encrypted websites (like HTTPS), public key infrastructure (PKI) protects your data from cybercriminals. However, the rise of quantum computing introduces transformative and potentially disruptive challenge to this foundation of digital trust. THE QUANTUM REVOLUTION Quantum computers can perform complex computations faster than even the most advanced current supercomputers. While this capability promises breakthroughs in drug discovery and healthcare, materials science or Artificial Intelligence (AI), it also poses a significant threat to current cryptographic systems. Quantum computers could break widely used publickey cryptographic systems (e.g., RSA, ECC), compromising critical infrastructure security such as energy grids, financial systems, and sensitive government communication networks. Compromised public-key cryptography could lead to forged digital certificates or signatures, undermining trust in banking, healthcare, and government services. Quantum cryptography attacks could also compromise billions of connected devices, from smart homes to Industrial Control Systems (ICS), by

ITSEC AsiaITSEC Asia
|
Jul 11, 2025 4 minutes read
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

INTRODUCTION Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] WHAT THE ROLE ACTUALLY OWNS An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that

Ajeng HadeAjeng Hade
|
Mei 25, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe