Your SOC Can’t Handle a Cyber Crisis Alone
The technical team may find the incident first. What happens next quickly becomes everybody else’s problem too.

Imagine a ransomware incident at 10:30 on a Tuesday morning.
The SOC detects suspicious activity and starts investigating. Soon IT needs to isolate systems. Management wants to know whether operations should continue. Legal needs facts. Communications may need to prepare a response. Someone has to decide whether customers or authorities need to be informed.
By lunch, cybersecurity has become an organizational exercise.
That reality is reflected in current training from the International Telecommunication Union. An ITU Academy incident response course currently open for applications uses three scenarios: a ransomware attack, a data breach and an attack affecting a national education system. Participants work through the incident response lifecycle using collaborative tabletop exercises.
The lesson is useful far beyond education. Incident response capability depends on how well different people can make decisions together.
Technical Skill Is Only One Layer
A strong SOC can identify malicious activity, analyse evidence and recommend containment. It still needs an organization around it that knows what happens next.
Useful incident response capability therefore spreads across several functions:
- SOC and security teams investigate, contain and preserve evidence.
- IT and infrastructure teams understand affected systems and recovery dependencies.
- Management makes operational and risk decisions with incomplete information.
- Legal and compliance teams assess regulatory and contractual obligations.
- Communications teams prepare accurate information for employees, customers or other stakeholders.
None of these groups needs identical cybersecurity expertise.
They do need enough shared understanding to work through the same incident.
ITU’s 2026 Regional CyberDrill for the Americas illustrates that model. The exercise brought together technical and management officials from CIRT, CERT and SOC environments alongside cybersecurity authorities, ministries, regulators and academia. Its objectives included improving technical capability, communication, incident management and coordination.
Tabletop Exercises Reveal Awkward Questions Early
A tabletop exercise is deceptively simple. Give a team a plausible incident and ask what they would do.
Then keep asking questions.
Who can authorize taking a critical system offline? Who contacts the regulator? Can the organization restore the affected service? Who briefs the CEO? What happens if the person who normally approves something is unreachable?
Suddenly the incident response plan starts developing holes.
That’s useful. A simulation can reveal unclear ownership, outdated contact lists, missing escalation paths and assumptions that looked perfectly reasonable inside a document.
ITU’s cyber disaster response training uses this approach explicitly, combining tabletop scenarios with hands on exercises and debriefs to develop communication and decision making during cyber attacks.
Finding those gaps during an exercise is considerably cheaper than discovering them while ransomware is spreading.
Train the Team Around the Technology
Technical cyber range exercises remain valuable, particularly for SOC analysts and incident responders. The next step is connecting those technical exercises with the people who have to act on their findings.
A realistic scenario might begin with analysts investigating suspicious activity, then require a handover to management, an operational decision from IT and a concise briefing for communications.
That type of practice fits naturally within ITSEC Cyber & AI Academy, where scenario based learning can help participants connect technical cybersecurity capability with the coordination and judgment required during real incidents.
The SOC may be the first room where the alarm goes off.
A prepared organization knows what every other room does next.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ITU Academy: Incident Response for Secure School Connectivity · ITU: 16th Regional CyberDrill for the Americas, 2026 · ITU Academy: Cyber Disaster Response Simulation Exercises
.png)


