Learning Objectives:

  • Understand the importance of post-incident review.

  • Apply lessons learned to improve cyber resilience.

  • Recognise the role of continuous improvement in cyber resilience.

  • Develop a continuous improvement framework.

7.1 The Importance of Post-Incident Review

Post-incident review is essential for learning from incidents and improving cyber resilience. The ITEdgeNews article emphasises conducting a post-mortem analysis to assess performance, identify gaps, and make improvements . The Kincaid course covers “learning from incidents and near-misses” as part of its continuous improvement module .

7.2 Applying Lessons Learned

Root Cause Analysis: The Kincaid course covers “root-cause analysis and remediation” to identify the underlying causes of incidents and address them .

Plan Updates: The course covers “reviewing and updating protection strategies” to incorporate lessons learned .

Training: The course covers “training for crisis scenarios” to improve staff capabilities .

7.3 Continuous Improvement Framework

Regular Reviews: The Kincaid course covers “reviewing and updating protection strategies” and “adapting to technological change” . The Central Bank of Eswatini’s Guidelines require financial institutions to regularly review and update threat analysis .

Metrics: The Skills for Africa course covers “tracking cybersecurity performance metrics” and “incorporating lessons learned into system improvements” .

Maturity: The course covers “measuring maturity and readiness” to assess progress over time .

7.4 Building a Learning Culture

The Skills for Africa course covers “fostering a culture of cybersecurity” as a key objective . A learning culture encourages reporting of near-misses and continuous improvement. The Central Bank of Eswatini’s Guidelines require that “management should create a culture which recognises that staff at all levels have important responsibilities in ensuring the financial institution’s cyber resilience” .