Logo
Cybersecurity

Your SOC Can’t Handle a Cyber Crisis Alone

The technical team may find the incident first. What happens next quickly becomes everybody else’s problem too.

ITSEC AsiaITSEC Asia
|
Sep 15, 2026
Your SOC Can’t Handle a Cyber Crisis Alone

Imagine a ransomware incident at 10:30 on a Tuesday morning.

The SOC detects suspicious activity and starts investigating. Soon IT needs to isolate systems. Management wants to know whether operations should continue. Legal needs facts. Communications may need to prepare a response. Someone has to decide whether customers or authorities need to be informed.

By lunch, cybersecurity has become an organizational exercise.

That reality is reflected in current training from the International Telecommunication Union. An ITU Academy incident response course currently open for applications uses three scenarios: a ransomware attack, a data breach and an attack affecting a national education system. Participants work through the incident response lifecycle using collaborative tabletop exercises.

The lesson is useful far beyond education. Incident response capability depends on how well different people can make decisions together.

Technical Skill Is Only One Layer

A strong SOC can identify malicious activity, analyse evidence and recommend containment. It still needs an organization around it that knows what happens next.

Useful incident response capability therefore spreads across several functions:

  • SOC and security teams investigate, contain and preserve evidence.
  • IT and infrastructure teams understand affected systems and recovery dependencies.
  • Management makes operational and risk decisions with incomplete information.
  • Legal and compliance teams assess regulatory and contractual obligations.
  • Communications teams prepare accurate information for employees, customers or other stakeholders.

None of these groups needs identical cybersecurity expertise.

They do need enough shared understanding to work through the same incident.

ITU’s 2026 Regional CyberDrill for the Americas illustrates that model. The exercise brought together technical and management officials from CIRT, CERT and SOC environments alongside cybersecurity authorities, ministries, regulators and academia. Its objectives included improving technical capability, communication, incident management and coordination.

Tabletop Exercises Reveal Awkward Questions Early

A tabletop exercise is deceptively simple. Give a team a plausible incident and ask what they would do.

Then keep asking questions.

Who can authorize taking a critical system offline? Who contacts the regulator? Can the organization restore the affected service? Who briefs the CEO? What happens if the person who normally approves something is unreachable?

Suddenly the incident response plan starts developing holes.

That’s useful. A simulation can reveal unclear ownership, outdated contact lists, missing escalation paths and assumptions that looked perfectly reasonable inside a document.

ITU’s cyber disaster response training uses this approach explicitly, combining tabletop scenarios with hands on exercises and debriefs to develop communication and decision making during cyber attacks.

Finding those gaps during an exercise is considerably cheaper than discovering them while ransomware is spreading.

Train the Team Around the Technology

Technical cyber range exercises remain valuable, particularly for SOC analysts and incident responders. The next step is connecting those technical exercises with the people who have to act on their findings.

A realistic scenario might begin with analysts investigating suspicious activity, then require a handover to management, an operational decision from IT and a concise briefing for communications.

That type of practice fits naturally within ITSEC Cyber & AI Academy, where scenario based learning can help participants connect technical cybersecurity capability with the coordination and judgment required during real incidents.

The SOC may be the first room where the alarm goes off.

A prepared organization knows what every other room does next.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU Academy: Incident Response for Secure School Connectivity · ITU: 16th Regional CyberDrill for the Americas, 2026 · ITU Academy: Cyber Disaster Response Simulation Exercises

Share this post

You may also like

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing. Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore. CYBERSECURITY NEEDS ARE CHANGING FASTER THAN SKILLS The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages. For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems. The skills required are also changing rapidly. The World

ITSEC AsiaITSEC Asia
|
Agt 24, 2026 5 minutes read
What Makes AI-Powered Penetration Testing Different From Automated Scanners?
Cybersecurity

What Makes AI-Powered Penetration Testing Different From Automated Scanners?

INTRODUCTION How much of what a vulnerability scanner flags every week actually turns out to be real? Research from OWASP puts the false positive rate for common vulnerability types somewhere between 15% and 30%, and separate research from Snyk found that security teams now spend roughly 70% of their time chasing alerts that end up being nothing at all. That gap between what a tool reports and what is actually exploitable is not a minor inconvenience. It is the reason a third of companies surveyed admitted they responded late to a genuine attack because their team was buried in phantom threats instead. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across the region that have learned this the hard way, and the question that keeps coming up is simple. If a scanner already checks the boxes, why does AI-powered penetration testing exist at all, and what does it actually do differently? Source: OWASP false positive research via DEV Community [https://dev.to/kuboidsecurelayer/why-automated-vulnerability-scanners-miss-most-real-security-vulnerabilities-2p96] · Snyk: Minimizing False Positives [https://snyk.io/blog/minimizing-false-positives-enhancing-security-efficiency/] THE FUNDAMENTAL DIFFERENCE: FOLLOWING RULES

ITSEC AsiaITSEC Asia
|
Jul 03, 2026 5 minutes read
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

INTRODUCTION Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] WHAT THE ROLE ACTUALLY OWNS An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that

|
Mei 25, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe