Hone

Lessons · Cybersecurity · the after-action report

The after-action report

After an incident is closed, one short document says what happened with times, what was done, what worked, what did not, and what will change, with a name and a date on every change.

Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.

What it is for

The same phishing run hit the same team twice in a year because the first report said 'staff to be more careful' and nobody owned it. The second report said 'finance to require a callback for any bank-detail change, owner the finance director, by the 30th', and it did not happen a third time.

How to think about it

Write it within a week, while people remember. Keep it blameless: the question is what made the mistake easy, not who made it. Every action gets an owner and a date, and the actions go on the same list as everything else the organisation is doing, or they are decoration.

Worked example

What happened: the timeline, with times, in one paragraph
Facts, from the evidence, not from memory.
What we did: containment at 02:41, eradication by 06:10, service back at 07:55
The response, timed, so the slow part is visible.
What worked, what did not: the alert fired; nobody was on call to see it
Both halves. A report with no second half changes nothing.
Changes: on-call rota for out-of-hours alerts, owner the IT manager, by the 14th
A change, a name, a date. Anything without all three is a wish.

Your turn

An after-action report asks what made the mistake easy, not who made it. Write the word for what it must never assign.

the report assigns actions, never 

The trap

Writing 'staff to be more vigilant' as an action. Nobody owns it, nothing changes, and the same incident is already on its way back.

Practise the after-action report on HoneA question on it now, a coding challenge where there is one, and it is remembered for review. Free, no email needed.