# Post-Incident Review

Incident ID: __________  Review owner: __________  Review date: __________

## Outcome

- Executive summary:
- Business and technical impact:
- Incident duration and recovery point:
- Root cause and contributing conditions:
- Confidence and unresolved questions:

## Timeline

| UTC time | Event / evidence | Decision or action | Owner | Result |
|---|---|---|---|---|
| | | | | |

## Performance

- What detected the incident? What should have detected it?
- Time to validate, scope, contain, eradicate, and recover:
- Evidence or telemetry gaps:
- Decisions delayed by missing authority, ownership, or business context:
- Containment actions that worked, failed, or displaced the threat:
- Communication and coordination observations:

## Improvements

| Finding | Corrective action | Owner | Due date | Verification method | Status |
|---|---|---|---|---|---|
| | | | | | |

Close an action only after its control, detection, playbook, or recovery change has been tested.
