Let's talk
Post-Incident Review and Hardening Plan

The incident is over. Know what needs to change.

A one-off review of an infrastructure incident, once the immediate disruption is under control. You get a documented account of what happened and a prioritized plan to reduce the risk and impact of a repeat.

Best fit

When it helps

For incidents that leave unanswered questions or too many possible next steps.

  • Back online, but still unsure why it failed

    Service is restored, but you are not sure whether the underlying problem is still there.

    • Reconstruct the sequence from available records.
    • Check possible causes against the evidence.
    • Identify unresolved questions and how to investigate them.
  • Getting back to normal took too long

    The disruption lasted longer than expected, and you want to understand what slowed the response.

    • Review when the issue was noticed and acted on.
    • Identify delays in decisions, handovers or recovery.
    • Recommend changes to help the team respond sooner.
  • Different teams tell different stories

    Several teams or providers were involved, and their accounts do not yet form a clear picture.

    • Bring records and accounts into one timeline.
    • Separate agreed facts from conflicting explanations.
    • Trace how systems and handovers contributed.
  • Plenty of fixes suggested. No clear order.

    Your team has ideas or an existing plan, but needs a clear order for the work that follows.

    • Check proposed changes against the findings.
    • Prioritize by impact, risk, effort and dependencies.
    • Recommend checks to confirm each change helps.
Scope & deliverables

A clear account, with practical next steps.

We agree the incident and questions to cover, then review the available evidence with the people involved.

What's included

The incident, response and recovery.

  • The affected systems and their relevant connections.
  • Available logs, alerts, change records and incident notes.
  • Accounts from the people involved.
  • Detection, decisions, handovers and recovery steps.
  • Immediate fixes and existing follow-up proposals.
  • Gaps in evidence that limit what can be concluded.
What you receive

Shared findings and clear priorities.

  • A documented incident timeline and account of the business disruption.
  • Findings that distinguish confirmed causes, contributing factors and unresolved questions.
  • A prioritized corrective plan, with dependencies and recommended checks to verify the changes.
  • A walkthrough to explain the findings and discuss priorities with your team.
Out of scope

Not part of this review.

Any further work is optional and agreed separately.

  • Emergency response or restoring service during an active incident.
  • Implementing changes or carrying out recovery tests.
  • Security breach investigation, formal security testing or compliance audits.
Process

How it works

We coordinate the review and document the findings, so your team can focus on moving forward.

  1. Agree the focus

    We discuss the incident, its business impact and your existing concerns or plans. We agree the questions, systems, price and timing before starting.

  2. Gather the evidence

    We coordinate records, access and conversations with your team or providers. We can start with incomplete documentation and explain where missing evidence limits the review.

  3. Work through what happened

    We build the timeline and check explanations against the evidence, focusing on the systems, working practices and conditions behind the incident. We use read-only access where practical and agree any check that could affect live systems in advance.

  4. Agree the priorities

    We walk through the findings, unresolved questions and corrective plan with you. You can use the plan with us, your team or another provider.

Get in touch

Need a clear way forward after an incident?

An informal 30-minute call to discuss the incident and see whether a focused review is the right next step.