Management is ultimately responsible for directing organization-wide security posture, policies, and legally required notifications to authorities following a security incident. Security and system administrators handle technical response and reporting to management, while users report anomalies internally.