Incident Prevention
o What type of an attack was it? What were the technical aspects of the breach? How did
the threat agents penetrate the system?
o What was the outcome of the attack (data breach, disruption of services, etc.)
o What type of data was accessed? Was the data leaked immediately or was ransom
requested?
• Company and Customer Impact
o How did the victim entity handle the attack? When were they alerted about the breach?
What steps have been taken to identify the attackers and prevent the data leak, if any?
What was the scope of the attack? How many customers were impacted, and which
data points were stolen?
• Remediation
o How did the victim entity handle the consequences of the attack? Were the customers
notified, and if so, when?
• Incident Prevention
o Could this attack have been prevented? If so, how? What can we learn from it?