Learning Objectives:

  • Understand the importance of post-incident review for continuous improvement.

  • Conduct post-incident reviews to identify lessons learned.

  • Apply lessons learned to improve incident response capabilities.

  • Develop a continuous improvement framework for incident response.

6.1 The Importance of Post-Incident Review

Post-incident review is essential for learning from incidents and improving cyber resilience. The FSB’s framework identifies “improvement” as a key component of incident response, which “establishes processes to improve response and recovery capabilities through lessons learned from past cyber-incidents and proactive tools, such as tabletop exercises, tests and drills” .

The Coursera course covers “evaluating post-incident lessons learned and operational metrics to improve response effectiveness, strengthen defenses, and enhance long-term organizational resilience” .

6.2 Conducting Post-Incident Reviews

The Coursera course covers “evaluating post-incident lessons learned” and “operational metrics” . The FSB’s framework identifies lessons learned from past cyber-incidents and proactive tools, such as tabletop exercises, tests and drills .

Key Review Activities:

  • Root Cause Analysis: Identifying the root cause of the incident.

  • Response Assessment: Assessing the effectiveness of the response.

  • Gap Analysis: Identifying gaps in capabilities and procedures.

  • Action Planning: Developing action plans to address gaps.

  • Implementation: Implementing improvements.

6.3 Applying Lessons Learned

The Coursera course covers “evaluating post-incident lessons learned and operational metrics to improve response effectiveness, strengthen defenses, and enhance long-term organizational resilience” .

Key Improvement Areas:

  • Procedures: Improving incident response procedures.

  • Capabilities: Building new capabilities.

  • Training: Providing training to staff.

  • Technology: Investing in new technology.

  • Culture: Building a culture of continuous improvement.

6.4 Continuous Improvement Framework

Key Elements:

  • Regular Reviews: Regularly reviewing incident response capabilities.

  • Tabletop Exercises: Conducting regular tabletop exercises.

  • Metrics: Tracking metrics to measure improvement.

  • Reporting: Reporting on improvement progress.

  • Leadership Commitment: Ensuring leadership commitment to continuous improvement.