Effective incident response doesn't end at recovery — the follow-up phase, including root cause analysis and structured after-action reporting, is what drives lasting improvement and reduces future incidents.
Incident Response Followup
There was once when I implemented an incident response plan for my team, and there's one step they couldn't get right. As a result I said, fine, we're going to have a meeting after every single incident response until you can get that step right. And as a result everything changed. What I realized is the follow-up to an incident is critical, and although I had it as part of the incident response plan before, that one meeting changed everything. It really reduced the amount of incidents we had, and also improved our incident response.
When it comes to incident follow-up, what I found is that a key part to the success is this last part, the learn part. Get that right and everything else becomes a lot easier.
There's really two main questions that I try to get at when it comes to this incident follow-up. What was the cause, and how can we put safeguards in place to make sure it doesn't happen again? And then also, how can we respond better?
You put so much time and effort into that follow-up, and specifically I actually schedule a meeting where everybody gets together and starts talking about what happened. You really drive down to that root cause and do a full root cause analysis, and you just keep stepping deeper and deeper until you find, well, maybe it is that one procedure which caused a problem on the database, which caused a problem on the application, which caused the problem to the user. So you've got to trace it back to what that root was, and then actually figure out what is it that we can do to make sure this doesn't happen again.
Not only that, but then we have to take some sort of actions to correct the issue, that we put it on our calendar to actually fix these issues so we don't have them again. Now we have less issues, we're impacting the user less, and we're also impacting ourselves less. We're reducing the amount of stress that we have on our lives.
It also improves the incident response process, that we take a look and say, how did we detect this? What is it that we can detect better so that way we can be notified sooner? And how can we do the analysis, containment, eradication and recovery better? So where in this process could we have done better? As we analyze that with every single incident, this whole process improves and gets easier. We reduce the amount of time that future incidents are out there, and the future incidents that we actually have.
So really this follow-up and what we've learned creates action items, and it becomes the prep that we have for any future events that we have. There's a cycle with all of this, that we continue to get better and better and improve more.
Typically what we do then is put that into an after action report. We take everything from the root cause analysis, all the data that we pulled, all the trends, all the procedures, everything that we did with that, and we put it into an after action report. The after action report then is a summary of everything that happened.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →