I am Root (Cause Analysis)
Closing an incident is not the same as learning from it. The work that decides whether it happens again usually starts after everyone has gone back to their day job.
A talk about root cause analysis after security incidents, why RCAs can be neglected, who should be involved beyond security and IT, and how organisations can make sure resulting actions are implemented rather than forgotten.
WATCH THE ORIGINAL (opens on an external site)Incident response gets attention because it is urgent. Root cause analysis gets less, because by the time it is due the pressure has lifted and everyone has something else to do.
This talk is about that gap: understanding what led to an incident, and making sure the answer turns into something other than a document.
What it gets into
- Why root cause analysis after a security incident is often neglected.
- Who should be involved beyond security and IT, and why their view of what happened matters.
- Understanding what actually led to an incident rather than what triggered the alert.
- How organisations can make sure the resulting actions get implemented rather than forgotten.
If your incident process ends when the incident does, this is a useful hour.
Want to talk it through?
If any of this is live in your business right now, a short conversation is usually the fastest way to work out what to do next.