6. Collaborate across departments
Leading a post-incident review is the responsibility of the CISO – or other security or IT leaders. However, it is advisable to also involve people from other departments who can potentially contribute insights. For example, security expert Leverett recommends expanding the post-incident team to include colleagues from governance, legal and risk management: “They may be able to link the root cause of the incident to general, broader policy gaps.”
In Leverett’s opinion, it also makes sense to involve the finance and human resources departments, as well as – depending on the type and severity of the incident – also board members. The expert is convinced that the latter signals strategic prioritization and helps to link technical findings with risk discussions at the governance level.
“It is important that everyone involved has an equal say – regardless of their position or role,” adds Protiviti man Taylor. This not only helps to better penetrate security incidents, but also establishes a cooperative environment.
7. Avoid blame
Fingerpointing during a post-incident review is unlikely to be productive. That’s why IT attorney Haughian also recommends focusing on learning and optimizing: “Appointing blame will get you nowhere. It’s important to uncover the actual sequence of events, understand decision-making processes and identify any factors that contributed to errors. This approach can help make future strategic decisions related to tools, training and policies.”
Leverett also doesn’t believe in a culture of blame: “It’s not about whether a particular individual made the right decision or not. Rather, it’s about asking questions like: ‘Was the team able to make good decisions under the circumstances?’ Or: ‘Would better documentation, different tools or more budget have ensured faster and better results?’”
8. Get active
Any insights gained during a post-incident review are relatively useless if nothing happens afterwards. This means: The findings must be followed by concrete measures.
In order to implement this in the best possible way, legal expert Haughian recommends writing down exactly where optimization needs to be done, when it should happen and who is responsible for it: “These improvements can be software updates, policy changes or new training initiatives. Regardless of this, it is this follow-up that makes a post-incident review really useful. If it is not done, actionable recommendations are also lost – and the whole thing is nothing more than an academic exercise,” notes the data protection expert. (fm)
This article originally appeared at our sister publication CSOonline.com.
