09 / AAR (After Action Review)
After-action review
Every exercise ends with a report drafted from what actually happened at the table: the timeline, the decisions, the responses and their evaluations. It follows the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-84 approach to evaluation and the Homeland Security Exercise and Evaluation Program (HSEEP) after-action report and improvement plan structure, and corrective actions are scoped to be tracked to closure within 60 days.
How to read this page
The report below is an anonymized example, not a real exercise. Names, organizations and figures have been replaced. Your own review is generated the moment ENDEX is called and is visible only to the Executive Sponsor and Operator of your organization and exports to a paginated PDF.
Register to run an exerciseSample report — redacted
01 / Executive summary
Executive summary
REDACTED SAMPLE. [ORGANIZATION] conducted a 180-minute discussion-based tabletop exercise against a ransomware scenario with recovery denial. The crisis team convened within 12 minutes of first alert and protected the payment platform, but the decision to isolate the virtualization layer waited on an owner who was never named in the plan, costing roughly 40 minutes. Materiality assessment for Securities and Exchange Commission (SEC) Form 8-K Item 1.05 started late and the regulator notification package was still in draft at ENDEX (end of exercise). Eight corrective actions are recommended, all scoped for closure within 60 days.
02 / Exercise overview
Exercise overview
- Scenario
- SAMPLE — Ransomware with recovery denial, financial services sector
- Scope
- Discussion-based tabletop, no live systems touched. In scope: [BUSINESS UNIT] payment platform, corporate identity, customer communications. Out of scope: operational technology (OT) environment, physical security.
- Planned duration
- 180 min
- Actual duration
- 168 min
- ENDEX reason
- Objectives met; operator called ENDEX after the recovery decision
- Departments
- Information Security (4) · Information Technology (3) · Legal (2) · Communications (2) · Executive (2) · Finance (1)
Training objectives
- Exercise the crisis escalation path from detection to executive decision (GV.RR, RS.MA).
- Test the materiality determination workflow against SEC 8-K Item 1.05 timing.
- Validate recovery sequencing when backups and the hypervisor are suspect (RC.RP).
03 / Timeline of play
Timeline of play
| T+ | Sim time | Type | Entry | Detail | Dept |
|---|---|---|---|---|---|
| T+00:10 | 09:10 | inject | Endpoint detection and response (EDR) alerts on mass file rename in the finance file share | Released to Information Security and Information Technology. Severity HIGH, vector RANSOMWARE. | Information Security |
| T+00:22 | 09:22 | response | Information Security convenes the crisis team | Containment started on two hosts; scope not yet established. | Information Security |
| T+00:45 | 09:45 | situation update | Backup catalog unreachable | Operator pushed a mid-exercise update raising recovery uncertainty. | ALL |
| T+01:05 | 10:05 | decision | Isolate the virtualization management network | Sponsor approved isolation, accepting a four-hour outage on internal apps. | Executive Leadership |
| T+02:48 | 11:48 | endex | ENDEX called | Recovery sequencing agreed; hotwash held immediately after. | ALL |
04 / Objective analysis
Objective analysis
Exercise the crisis escalation path from detection to executive decision.
MetCrisis team convened at T+00:22 using the documented bridge. Roles were stated aloud and recorded.
Test the materiality determination workflow against SEC 8-K Item 1.05 timing.
Partially MetLegal opened the assessment at T+01:05 with no pre-agreed materiality criteria; the four-business-day clock was acknowledged but no filing owner was named.
Validate recovery sequencing when backups and the hypervisor are suspect.
Not ObservedThe exercise ended before a restore order was walked through in detail.
05 / Strengths
Strengths
- ▸Detection to escalation was fast and disciplined, satisfying the intent of DE.AE-06 handoff to response.T+00:10
- ▸Communications drafted a holding statement without waiting for full facts, supporting RS.CO-02 timeliness.T+00:45
- ▸Finance identified the wire-fraud secondary risk unprompted, an ID.RA-03 strength.T+00:22
- ▸The sponsor stated risk tolerance explicitly before approving isolation, exercising GV.RM-02.T+01:05
06 / Areas for improvement
Areas for improvement
No named owner for isolating the virtualization management layer, delaying the decision about 40 minutes.
The response plan assigns hypervisor actions to a team, not a role with authority to accept outage. Under time pressure the group deferred upward twice.
Materiality criteria were not available at the table.
Legal and Finance reconstructed thresholds live, which is unlikely to survive a real four-business-day clock.
07 / Regulatory clocks
Regulatory clocks
| Regime | Trigger | Deadline | Status |
|---|---|---|---|
| Securities and Exchange Commission (SEC) Form 8-K Item 1.05 | Materiality determination on the payment platform outage | 4 business days from determination | missed |
| General Data Protection Regulation (GDPR) Art. 33 | Confirmed exposure of EU customer records | 72 hours from awareness | addressed |
| HIPAA Breach Notification | Protected health information involved | 60 days | not applicable |
08 / Corrective actions
Corrective actions
| Action | Owner role | Due | Priority | Reference |
|---|---|---|---|---|
| Name a single accountable role, with a documented deputy, authorized to isolate the virtualization management network. | Chief Information Security Officer (CISO) | 30 d | HIGH | GV.RR-02; incident response control IR-8 |
| Publish a one-page materiality determination aid with pre-agreed financial and operational thresholds. | General Counsel | 45 d | HIGH | SEC Form 8-K Item 1.05; GV.RM-05 |
| Run a restore rehearsal from immutable backup for the payment platform. | Information Technology Operations Director | 60 d | MED | RC.RP-04; CP-10 |
09 / Participant feedback prompts
Participant feedback prompts
- At what point did you know who was making the containment decision?
- Which information did you need that nobody in the room could provide?
- What would have changed if the incident had started at 02:00 on a Sunday?
- Which single change to the plan would have helped you most today?
10 / Appendices
Appendices
Appendix A — Master scenario events list
- T+00:10 [INJECT] Endpoint detection and response alerts on mass file rename | severity HIGH | vector RANSOMWARE | released to Information Security, Information Technology
- T+00:45 [SITUATION UPDATE] Backup catalog unreachable | released to ALL
- T+01:20 [INJECT] Journalist calls with a leaked ransom note | severity MED | vector RANSOMWARE | released to Communications, Executive
Appendix B — Roster
- Information Security — [REDACTED] (Security Operations Lead)
- Legal — [REDACTED] (Deputy General Counsel)
- Executive — [REDACTED] (Chief Operating Officer)