Back to Resources
Incident Report / Post-Mortem Template: visual preview
Template

Incident Report / Post-Mortem Template

Root Cause Analysis & Lessons Learned Capture

Overview

After the firefighting is over, the real work begins. A well-structured incident post-mortem turns every security incident into a learning opportunity that strengthens your defenses. This template walks you through documenting the incident timeline, identifying root causes, measuring business impact, and defining corrective actions that actually get implemented. Whether you follow a blameless post-mortem process inspired by Google SRE practices or a more traditional incident review, the goal is the same: build resilience, not assign blame.

Post-Mortem Sections

  • Executive summary and incident classification
  • Detailed timeline with UTC timestamps and key decisions
  • Root cause analysis (primary and contributing factors)
  • Impact assessment: data, systems, customers, and financial
  • Detection and response effectiveness review
  • Corrective actions with owners, deadlines, and verification steps
  • Lessons learned and process improvements
  • Communication review: internal and external response
  • Appendices: evidence logs, communication records, IOCs

Root Cause Analysis Methods

MethodBest forApproach
5 WhysSimple, single-cause incidentsAsk "why" iteratively until you reach the root cause: commonly used in blameless post-mortems
Fishbone (Ishikawa)Complex incidents with multiple contributing factorsCategorize causes across people, process, technology, and environment
Fault Tree AnalysisHigh-severity incidents requiring formal analysisMap failure paths in a logical tree structure
Timeline AnalysisIncidents with unclear sequence of eventsPlot every action and event chronologically to identify gaps
Contributing Factors AnalysisSystemic issues across teamsIdentify organizational, process, and tooling factors that enabled the incident

Writing the Timeline

The timeline is the backbone of any good post-mortem report. Start from the earliest indicator of compromise, not from when the alert fired. Include every significant event: initial access, lateral movement, detection, triage decisions, containment actions, communications sent, and full recovery. Use UTC timestamps throughout for consistency. Note where there were delays and why: were analysts waiting for approvals? Did detection take too long? Was the escalation path unclear? The timeline should tell the story of both the attack and the response.

Impact Assessment Framework

Quantify the impact across multiple dimensions. How many records were exposed? Which systems were offline and for how long? Were customers directly affected? What was the financial cost including incident response fees, legal expenses, and lost revenue? Document regulatory implications: was this a reportable breach under GDPR, HIPAA, CERT-In, or state breach notification laws? Include reputational impact where measurable. The impact section is what leadership and the board care about most.

Blameless Post-Mortem Best Practices

A blameless post-mortem culture, pioneered by Google SRE and adopted by organizations like Etsy, PagerDuty, and Atlassian, focuses on systemic improvements rather than individual fault. Key principles: (1) Assume everyone acted with the best information available at the time. (2) Focus on "what" and "how": not "who." (3) Reward people for surfacing contributing factors honestly. (4) Document decisions that seemed reasonable in context, even if they later proved wrong. (5) Track recurring themes across post-mortems to identify systemic gaps in tooling, process, or training.

Corrective Actions That Stick

Every post-mortem produces a list of action items, but the ones that matter have three things: a clear owner, a realistic deadline, and a verification step. Assign each action to a specific person, not a team. Set deadlines within 30, 60, or 90 days depending on complexity. Schedule follow-up reviews to confirm implementation. Track completion rates across all post-mortems in tools like Jira, PagerDuty, or your GRC platform to identify systemic issues like chronic underinvestment in detection or repeated access control failures.

Using AI for Post-Mortem Generation

Modern incident response platforms, including Hunto AI, can auto-generate post-mortem drafts by correlating alert timelines, analyst actions, and remediation steps from your SIEM and ticketing systems. AI-generated post-mortems provide a structured starting point: pre-populating the timeline, affected assets, and detection-to-containment metrics: so your team can focus on root cause analysis and lessons learned rather than manual documentation.

Frequently asked questions