After containing a ransomware incident that hit a water-utility SCADA jump host, the city files a polished after-action PDF and shelves it. What should happen next for lessons learned to improve operations?
Select an answer to reveal the explanation.
Short Explanation
A lessons-learned binder that never changes the playbook is a trophy, not a fix. Use the review to tighten detections, steps, and controls so the next jump-host scare ends faster.
Full Explanation
Lessons learned close the incident-management loop by driving concrete updates to playbooks, detections, configurations, and controls. Filing an after-action report without operational change fails to reduce recurrence risk for critical infrastructure such as water utilities. Security operations should treat the review as an engineering and process input, not an archival ritual. Preserving and acting on findings also supports auditability of continuous improvement.