Lessons-Learned Meeting
Definition
A structured post-incident review, recommended by NIST within approximately two weeks of incident resolution, that examines what happened, what the response did well, what it missed, and what should change. The meeting's outputs update detection rules, playbooks, and the IR plan itself.
- Timing
- Recommended within about two weeks of resolution
- Source guidance
- NIST SP 800-61
- Reviews
- What happened, what worked, what was missed
- Outputs
- Updates to detection rules, playbooks, IR plan
Common questions
Why hold the meeting within two weeks rather than immediately?+
Immediately after closure, participants are often still fatigued and details are hard to synthesize objectively; waiting roughly two weeks lets logs and timelines settle while memory is still fresh enough for accurate reconstruction.
Who typically attends a lessons-learned meeting?+
Responders directly involved in the incident, along with representatives from teams whose tooling or processes are likely to change as a result, such as detection engineering, IT operations, and sometimes legal or communications staff.
Related terms
- Containment Strategy
- A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting...
- Eradication
- The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised...
- Incident Response Lifecycle
- The structured sequence of phases NIST SP 800-61 defines for handling computer security incidents: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity....
- Incident Response Plan
- A formal document that defines an organisation's approach to incident handling: roles and responsibilities, escalation paths, communication procedures, legal and regulatory obligations,...
- Indicators of Compromise (IoCs)
- Artefacts observed on a network or system that suggest an intrusion or malicious activity has occurred, such as unusual outbound connections, known-malicious...