After Action Reviews
Turn every incident into measurable improvement

Practical Guide Free to Use

The most expensive incident is the one you have twice. An after action review is how a breach becomes a maturity jump instead of a repeat event, but only if it's structured, honest, and produces owned actions rather than a shelf document.

Three Rules That Make an AAR Work

1. Blameless, Not Toothless

Attack the process, not the people, or nobody tells the truth. But blameless doesn't mean consequence-free: findings get owners and dates.

2. Run It Within Two Weeks

Memory decays and war stories replace facts. Hold the review while the timeline is still fresh and the logs still exist.

3. Decisions, Not Just Events

The timeline of what happened matters less than the timeline of what you knew, when you decided, and what slowed you down.

The Questions, by Phase

Walk the incident front to back. For each phase, the same four probes: what happened, what worked, what didn't, what changes.

Phase What to Ask
Detection How long from first compromise to first alert? Did the alert come from your tooling, an employee, or an outsider? What would have caught it earlier?
Escalation How long from alert to the right people engaged? Did on-call, severity criteria, and the IR plan actually get used, or bypassed?
Containment What decisions were needed, who made them, and what information was missing? Where did approval bottlenecks cost hours?
Communications Did executives, legal, insurance, and affected teams hear the right things at the right times? What did the business learn from rumor instead of from you?
Recovery Did restoration order match business priority? What dependencies surprised you? How close did backups come to failing you?
Root Cause Separate the entry point from the conditions that let it spread. "Phishing email" is a symptom. Flat network, excess privilege, and missing MFA are causes.

What Comes Out the Other Side

An AAR that doesn't change anything was a meeting, not a review. Four required outputs:

1

Findings Register

Every gap, ranked by risk, not by how awkward it is to say out loud.

2

Owned Actions

Each fix has a named owner, a date, and a definition of done. No "the team will look into it."

3

Plan Updates

IR plan, playbooks, and contact trees corrected to match what the incident proved true.

4

Executive Brief

One page for leadership: what happened, what it cost, what's changing, what it needs funded.

Then test the fixes: a tabletop exercise six months later is how you prove the lessons stuck.

Facilitated AARs

The hardest reviews to run are your own. Olympus Cyber facilitates after action reviews as a neutral party, surfacing what internal politics won't, and turning findings into a roadmap leadership can fund.
🚨 Emergency IR