Six weeks after a successful business email compromise that caused a fraudulent supplier payment, the incident has been closed and funds partially recovered. The CISO has asked the incident manager to run the lessons-learned activity. Which approach should the incident manager take as the PRIMARY focus of the session?
- AIdentify the individual finance approver whose failure to verify the bank detail change allowed the payment, so HR can address performance.
- BDocument a detailed technical reconstruction of the phishing email and attacker infrastructure for inclusion in the threat intelligence repository.
- CExamine the timeline against the incident response plan to identify control, process, and detection gaps, and agree owned actions to close them. Correct
- DDraft updated awareness training content about supplier impersonation and schedule a mandatory refresh for the finance department.
Why A is wrong: Singling out an individual creates a blame culture, discourages future reporting, and ignores the systemic controls that should have prevented a single point of failure. CISSP guidance is to treat lessons learned as a process improvement activity, not a disciplinary one.
Why B is wrong: A technical reconstruction is a useful artefact but is a narrow slice of lessons learned. Stopping there misses process, governance, and human-factor lessons that drive most BEC losses and that the CISO needs to act on.
Why C is correct: The post-incident review exists to convert the incident into durable improvement. Comparing what happened to the plan exposes gaps in prevention, detection, response, and communication, and assigning owned actions with due dates is what turns the review into measurable risk reduction.
Why D is wrong: Updated training is a plausible output of the review but is one possible action, not the focus of the session itself. Jumping to a single corrective action without analysing the full timeline tends to leave detection and process gaps unaddressed.