Jan. 30, 2023, 10:39 p.m. | USENIX

USENIX www.youtube.com

A Post Incident Review Review

Tom Partington, ANZx

Our post incident process is a little different to most, and mainly because of what it doesn't include rather than what it does.

We don't identify a root cause, we don't create or track action items, and we don't report on incident counts or MTTRs. We also work in a highly regulated industry, in a 1000+ person organisation, and repeat incidents are rare.

In this talk I'll discuss how we developed this …

action apac don identify incident incident review incidents industry organisation process report review root work

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Junior Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Associate Director, Operations Compliance and Investigations Management

@ Legend Biotech | Raritan, New Jersey, United States

Analyst, Cyber Operations Engineer

@ BlackRock | SN6-Singapore - 20 Anson Road

Working Student/Intern/Thesis: Hardware based Cybersecurity Training (m/f/d)

@ AVL | Regensburg, DE