09 / AAR (After Action Review)

After-action review

Every exercise ends with a report drafted from what actually happened at the table: the timeline, the decisions, the responses and their evaluations. It follows the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-84 approach to evaluation and the Homeland Security Exercise and Evaluation Program (HSEEP) after-action report and improvement plan structure, and corrective actions are scoped to be tracked to closure within 60 days.

How to read this page

Redacted sample

The report below is an anonymized example, not a real exercise. Names, organizations and figures have been replaced. Your own review is generated the moment ENDEX is called and is visible only to the Executive Sponsor and Operator of your organization and exports to a paginated PDF.

Register to run an exercise

Sample report — redacted

01 / Executive summary

Executive summary

REDACTED SAMPLE. [ORGANIZATION] conducted a 180-minute discussion-based tabletop exercise against a ransomware scenario with recovery denial. The crisis team convened within 12 minutes of first alert and protected the payment platform, but the decision to isolate the virtualization layer waited on an owner who was never named in the plan, costing roughly 40 minutes. Materiality assessment for Securities and Exchange Commission (SEC) Form 8-K Item 1.05 started late and the regulator notification package was still in draft at ENDEX (end of exercise). Eight corrective actions are recommended, all scoped for closure within 60 days.

02 / Exercise overview

Exercise overview

Scenario
SAMPLE — Ransomware with recovery denial, financial services sector
Scope
Discussion-based tabletop, no live systems touched. In scope: [BUSINESS UNIT] payment platform, corporate identity, customer communications. Out of scope: operational technology (OT) environment, physical security.
Planned duration
180 min
Actual duration
168 min
ENDEX reason
Objectives met; operator called ENDEX after the recovery decision
Departments
Information Security (4) · Information Technology (3) · Legal (2) · Communications (2) · Executive (2) · Finance (1)

Training objectives

  • Exercise the crisis escalation path from detection to executive decision (GV.RR, RS.MA).
  • Test the materiality determination workflow against SEC 8-K Item 1.05 timing.
  • Validate recovery sequencing when backups and the hypervisor are suspect (RC.RP).

03 / Timeline of play

Timeline of play

T+Sim timeTypeEntryDetailDept
T+00:1009:10injectEndpoint detection and response (EDR) alerts on mass file rename in the finance file shareReleased to Information Security and Information Technology. Severity HIGH, vector RANSOMWARE.Information Security
T+00:2209:22responseInformation Security convenes the crisis teamContainment started on two hosts; scope not yet established.Information Security
T+00:4509:45situation updateBackup catalog unreachableOperator pushed a mid-exercise update raising recovery uncertainty.ALL
T+01:0510:05decisionIsolate the virtualization management networkSponsor approved isolation, accepting a four-hour outage on internal apps.Executive Leadership
T+02:4811:48endexENDEX calledRecovery sequencing agreed; hotwash held immediately after.ALL

04 / Objective analysis

Objective analysis

Exercise the crisis escalation path from detection to executive decision.

Met
CSF GV.RR-02CSF RS.MA-01IR-4IR-8T+00:22

Crisis team convened at T+00:22 using the documented bridge. Roles were stated aloud and recorded.

Test the materiality determination workflow against SEC 8-K Item 1.05 timing.

Partially Met
CSF GV.RM-05CSF RS.CO-02IR-6T+01:05

Legal opened the assessment at T+01:05 with no pre-agreed materiality criteria; the four-business-day clock was acknowledged but no filing owner was named.

Validate recovery sequencing when backups and the hypervisor are suspect.

Not Observed
CSF RC.RP-02CSF RC.RP-04CP-10IR-4T+02:48

The exercise ended before a restore order was walked through in detail.

05 / Strengths

Strengths

  • Detection to escalation was fast and disciplined, satisfying the intent of DE.AE-06 handoff to response.T+00:10
  • Communications drafted a holding statement without waiting for full facts, supporting RS.CO-02 timeliness.T+00:45
  • Finance identified the wire-fraud secondary risk unprompted, an ID.RA-03 strength.T+00:22
  • The sponsor stated risk tolerance explicitly before approving isolation, exercising GV.RM-02.T+01:05

06 / Areas for improvement

Areas for improvement

No named owner for isolating the virtualization management layer, delaying the decision about 40 minutes.

The response plan assigns hypervisor actions to a team, not a role with authority to accept outage. Under time pressure the group deferred upward twice.

National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 GV.RR-02; Special Publication (SP) 800-61r3 preparation; SP 800-53 incident response control IR-8T+01:05

Materiality criteria were not available at the table.

Legal and Finance reconstructed thresholds live, which is unlikely to survive a real four-business-day clock.

SEC 8-K Item 1.05; NIST CSF 2.0 GV.RM-05T+01:05

07 / Regulatory clocks

Regulatory clocks

RegimeTriggerDeadlineStatus
Securities and Exchange Commission (SEC) Form 8-K Item 1.05Materiality determination on the payment platform outage4 business days from determinationmissed
General Data Protection Regulation (GDPR) Art. 33Confirmed exposure of EU customer records72 hours from awarenessaddressed
HIPAA Breach NotificationProtected health information involved60 daysnot applicable

08 / Corrective actions

Corrective actions

Close within 60 days
ActionOwner roleDuePriorityReference
Name a single accountable role, with a documented deputy, authorized to isolate the virtualization management network.Chief Information Security Officer (CISO)30 dHIGHGV.RR-02; incident response control IR-8
Publish a one-page materiality determination aid with pre-agreed financial and operational thresholds.General Counsel45 dHIGHSEC Form 8-K Item 1.05; GV.RM-05
Run a restore rehearsal from immutable backup for the payment platform.Information Technology Operations Director60 dMEDRC.RP-04; CP-10

09 / Participant feedback prompts

Participant feedback prompts

  • At what point did you know who was making the containment decision?
  • Which information did you need that nobody in the room could provide?
  • What would have changed if the incident had started at 02:00 on a Sunday?
  • Which single change to the plan would have helped you most today?

10 / Appendices

Appendices

Appendix A — Master scenario events list

  • T+00:10 [INJECT] Endpoint detection and response alerts on mass file rename | severity HIGH | vector RANSOMWARE | released to Information Security, Information Technology
  • T+00:45 [SITUATION UPDATE] Backup catalog unreachable | released to ALL
  • T+01:20 [INJECT] Journalist calls with a leaked ransom note | severity MED | vector RANSOMWARE | released to Communications, Executive

Appendix B — Roster

  • Information Security — [REDACTED] (Security Operations Lead)
  • Legal — [REDACTED] (Deputy General Counsel)
  • Executive — [REDACTED] (Chief Operating Officer)