Skip to content
atlas

Don't confuse these

Incident reporting vs Lessons learned

Why they differ

Reporting passes facts on quickly during the event; lessons learned looks back afterwards to improve.

Incident reporting

Incidents & continuity

Telling the right people and authorities about a serious security event, quickly and within set deadlines.

Formal

The duty and process of passing on information about a security incident - inside the organisation and, when rules demand it, to authorities and affected people - in fixed stages and time limits.

In plain English

Like calling the fire brigade and your neighbours as soon as you see smoke, rather than after the fire is out.

In practice

After spotting an attack on its systems, a regional hospital sends the authorities an early warning within 24 hours, a full notification within 72 hours and a final report within a month.

Why it matters

Quick reports let others warn and protect themselves, and missing a legal deadline can bring fines on top of the attack itself.

Lessons learned

Incidents & continuity

Looking back after an incident or exercise to see what worked, what failed and what to change next time.

Formal

The closing step of incident response, in which the people involved review the timeline and decisions without blame and turn findings into owned, dated changes to plans and controls.

In plain English

Like a football team watching the match again on video to see why they let in that goal.

In practice

A week after a ransomware outage, staff at an accounting firm meet for an hour, note that the backup key sat on the very server that was locked, and task the IT manager with moving it by Friday.

Why it matters

Without it the same mistakes return in the next incident, and the organisation pays twice for the same lesson.

Shared connections

Atlas is in beta.