The incident is over. Know what needs to change.
A one-off review of an infrastructure incident, once the immediate disruption is under control. You get a documented account of what happened and a prioritized plan to reduce the risk and impact of a repeat.
When it helps
For incidents that leave unanswered questions or too many possible next steps.
Back online, but still unsure why it failed
Service is restored, but you are not sure whether the underlying problem is still there.
- Reconstruct the sequence from available records.
- Check possible causes against the evidence.
- Identify unresolved questions and how to investigate them.
Getting back to normal took too long
The disruption lasted longer than expected, and you want to understand what slowed the response.
- Review when the issue was noticed and acted on.
- Identify delays in decisions, handovers or recovery.
- Recommend changes to help the team respond sooner.
Different teams tell different stories
Several teams or providers were involved, and their accounts do not yet form a clear picture.
- Bring records and accounts into one timeline.
- Separate agreed facts from conflicting explanations.
- Trace how systems and handovers contributed.
Plenty of fixes suggested. No clear order.
Your team has ideas or an existing plan, but needs a clear order for the work that follows.
- Check proposed changes against the findings.
- Prioritize by impact, risk, effort and dependencies.
- Recommend checks to confirm each change helps.
A clear account, with practical next steps.
We agree the incident and questions to cover, then review the available evidence with the people involved.
The incident, response and recovery.
- The affected systems and their relevant connections.
- Available logs, alerts, change records and incident notes.
- Accounts from the people involved.
- Detection, decisions, handovers and recovery steps.
- Immediate fixes and existing follow-up proposals.
- Gaps in evidence that limit what can be concluded.
Shared findings and clear priorities.
- A documented incident timeline and account of the business disruption.
- Findings that distinguish confirmed causes, contributing factors and unresolved questions.
- A prioritized corrective plan, with dependencies and recommended checks to verify the changes.
- A walkthrough to explain the findings and discuss priorities with your team.
Not part of this review.
Any further work is optional and agreed separately.
- Emergency response or restoring service during an active incident.
- Implementing changes or carrying out recovery tests.
- Security breach investigation, formal security testing or compliance audits.
How it works
We coordinate the review and document the findings, so your team can focus on moving forward.
Agree the focus
We discuss the incident, its business impact and your existing concerns or plans. We agree the questions, systems, price and timing before starting.
Gather the evidence
We coordinate records, access and conversations with your team or providers. We can start with incomplete documentation and explain where missing evidence limits the review.
Work through what happened
We build the timeline and check explanations against the evidence, focusing on the systems, working practices and conditions behind the incident. We use read-only access where practical and agree any check that could affect live systems in advance.
Agree the priorities
We walk through the findings, unresolved questions and corrective plan with you. You can use the plan with us, your team or another provider.
Need a clear way forward after an incident?
An informal 30-minute call to discuss the incident and see whether a focused review is the right next step.