What are the most common post-mortem analysis mistakes you make?
Incident response (IR) is a critical process that aims to contain, analyze, and recover from security incidents. However, IR is not complete without a post-mortem analysis, which is a systematic review of what happened, why it happened, and how to prevent it from happening again. A post-mortem analysis can help you identify the root causes, the lessons learned, and the action items for improvement. However, many IR teams make common mistakes that can undermine the effectiveness and value of their post-mortem analysis. In this article, we will discuss some of these mistakes and how to avoid them.
-
Rob T. LeeTechnical Advisor to US Govt | Chief of Research and Head of Faculty, SANS Institute | Cybersecurity Researcher |…
-
Anirudh KhannaBackup and Recovery | Disaster Recovery | Cyber Recovery | AWS Cloud | Vmware | IEEE Senior Member
-
Farukh IsmailovLogistics Safety Engineer @ NCOC N.V. | IOSH MS | Risk Management | HSE Competency Assurance | Compliance