Learning Objectives:
-
Understand the importance of post-incident review.
-
Apply lessons learned to improve cyber resilience.
-
Recognise the role of continuous improvement in cyber resilience.
-
Develop a continuous improvement framework.
7.1 The Importance of Post-Incident Review
Post-incident review is essential for learning from incidents and improving cyber resilience. The ITEdgeNews article emphasises conducting a post-mortem analysis to assess performance, identify gaps, and make improvements . The Kincaid course covers “learning from incidents and near-misses” as part of its continuous improvement module .
7.2 Applying Lessons Learned
Root Cause Analysis:Â The Kincaid course covers “root-cause analysis and remediation” to identify the underlying causes of incidents and address them .
Plan Updates:Â The course covers “reviewing and updating protection strategies” to incorporate lessons learned .
Training:Â The course covers “training for crisis scenarios” to improve staff capabilities .
7.3 Continuous Improvement Framework
Regular Reviews:Â The Kincaid course covers “reviewing and updating protection strategies” and “adapting to technological change” . The Central Bank of Eswatini’s Guidelines require financial institutions to regularly review and update threat analysis .
Metrics:Â The Skills for Africa course covers “tracking cybersecurity performance metrics” and “incorporating lessons learned into system improvements” .
Maturity:Â The course covers “measuring maturity and readiness” to assess progress over time .
7.4 Building a Learning Culture
The Skills for Africa course covers “fostering a culture of cybersecurity” as a key objective . A learning culture encourages reporting of near-misses and continuous improvement. The Central Bank of Eswatini’s Guidelines require that “management should create a culture which recognises that staff at all levels have important responsibilities in ensuring the financial institution’s cyber resilience” .