Agenda
Agenda
Opening (10 min)
- Ground rules
- Blame-free commitment
- Meeting objectives
Incident Overview (20 min)
- Timeline presentation
- Impact summary
- Response actions taken
What Went Well (20 min)
- Quick detection after encryption
- Effective team communication
- Business continuity plan worked
What Needs Improvement (30 min)
- Detection capabilities
- Initial response time
- Communication to executives
Root Cause Discussion (20 min)
- Technical causes
- Process gaps
- Training needs
Action Items (15 min)
- Prioritized improvements
- Owner assignment
- Timeline commitment
Closing (5 min)
- Next steps
- Follow-up schedule