TechKnowSurge
CompTIA CySA+ 3.3 NIST CSF RS.AN-03 NIST 800-53 IR-4 ISC2 CISSP 7.6
VideoSecurityFree

Incident Follow-Up

Effective incident response doesn't end at recovery — the follow-up phase, including root cause analysis and structured after-action reporting, is what drives lasting improvement and reduces future incidents.

Complete this video to capture a CTF flag worth 1 point.

About this video

Post-incident follow-up is a defining factor in the long-term effectiveness of any incident response program. While detection, containment, eradication, and recovery are essential, the learning phase that follows determines whether an organization simply reacts to incidents or actively reduces them. The core of this phase centers on two questions: what caused the incident, and what can be done to prevent it from recurring while improving the response process itself. Structured team debriefs after each incident create the space to work through those questions systematically and drive measurable change. Root cause analysis is the engine of this follow-up process. Rather than addressing only surface-level symptoms, teams trace the chain of events — from the initial procedural failure through its downstream effects on systems and end users — until the true origin is identified. Corrective actions are then scheduled and tracked to ensure they are actually completed, not just acknowledged. Each iteration of this process also prompts a review of detection methods, containment strategies, and recovery procedures, steadily reducing both the frequency and duration of future incidents. The insights gathered through root cause analysis and team review are consolidated into a formal after-action report. This document captures all relevant data, trends, and procedural observations from the incident, serving as both an organizational record and a foundation for future preparedness. Over time, this cycle of response, analysis, and refinement compounds — building a more resilient team, a more effective response framework, and a measurably stronger security posture.

What you'll learn

What's covered

Incident Response Followup

Aligned to

CompTIA CySA+
3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.
NIST CSF
RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
NIST 800-53
IR-4 Incident Handling
ISC2 CISSP
7.6 Conduct incident management

Key terms

Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.
Root Cause Analysis
RCA
A systematic investigation process that identifies the underlying cause of a security incident or system failure, going beyond symptoms to prevent recurrence. RCA findings drive corrective actions and improvements to security controls.
Corrective Action Plan
A documented set of action items developed to address the root cause of an incident and prevent it from happening again.
After-Action Report
AAR
A summary document that captures findings from the incident response process, including root cause analysis, trends, and lessons learned.

Topics

Incident Response Root Cause Analysis After Action Reporting Corrective Action Planning Cybersecurity

Transcript

There was once when I implemented an incident response plan for my team, and there's one step they couldn't get right. As a result I said, fine, we're going to have a meeting after every single incident response until you can get that step right. And as a result everything changed. What I realized is the follow-up to an incident is critical, and although I had it as part of the incident response plan before, that one meeting changed everything. It really reduced the amount of incidents we had, and also improved our incident response.

When it comes to incident follow-up, what I found is that a key part to the success is this last part, the learn part. Get that right and everything else becomes a lot easier.

Two questions to get at

There's really two main questions that I try to get at when it comes to this incident follow-up. What was the cause, and how can we put safeguards in place to make sure it doesn't happen again? And then also, how can we respond better?

Driving down to the root cause

You put so much time and effort into that follow-up, and specifically I actually schedule a meeting where everybody gets together and starts talking about what happened. You really drive down to that root cause and do a full root cause analysis, and you just keep stepping deeper and deeper until you find, well, maybe it is that one procedure which caused a problem on the database, which caused a problem on the application, which caused the problem to the user. So you've got to trace it back to what that root was, and then actually figure out what is it that we can do to make sure this doesn't happen again.

Not only that, but then we have to take some sort of actions to correct the issue, that we put it on our calendar to actually fix these issues so we don't have them again. Now we have less issues, we're impacting the user less, and we're also impacting ourselves less. We're reducing the amount of stress that we have on our lives.

Improving the response itself

It also improves the incident response process, that we take a look and say, how did we detect this? What is it that we can detect better so that way we can be notified sooner? And how can we do the analysis, containment, eradication and recovery better? So where in this process could we have done better? As we analyze that with every single incident, this whole process improves and gets easier. We reduce the amount of time that future incidents are out there, and the future incidents that we actually have.

So really this follow-up and what we've learned creates action items, and it becomes the prep that we have for any future events that we have. There's a cycle with all of this, that we continue to get better and better and improve more.

The after action report

Typically what we do then is put that into an after action report. We take everything from the root cause analysis, all the data that we pulled, all the trends, all the procedures, everything that we did with that, and we put it into an after action report. The after action report then is a summary of everything that happened.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →