Post-incident is the final phase of the defensive lifecycle, carried out once recovery is complete. It turns the experience of an incident into lasting improvement. Rather than closing the book, this phase asks what happened, why it happened, and how the organization can be stronger next time. Its findings loop directly back into preparation, making the lifecycle a continuous cycle rather than a straight line. Done honestly and without blame, it is one of the most valuable sources of security learning an organization has.
This pillar covers the work of reflection and improvement.
- Reconstruction and forensics establish a detailed, evidence-based account of how the incident unfolded, from initial access to impact.
- Assessment and lessons learned evaluate what worked, what did not, and what gaps the incident revealed across people, process, and technology.
- Improvement feeding back into preparation translates those lessons into concrete changes to controls, detections, plans, and training.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response
- SANS Institute, lessons learned and incident review resources