4. Learning and prevention
Root cause analysis: fix the cause, not the blame
Once a breach is contained, assessed, and notified where needed, the final phase begins: making sure it does not happen again. The tool for this is root cause analysis, and its defining feature is that it asks "why did this happen?" rather than "who do we blame?"
Keep asking why
The visible cause of a breach is almost never the whole story. Take the classic misdirected email. The surface cause is "Sam picked the wrong recipient". Ask why, and the picture deepens: autocomplete suggested an external contact with the same first name. Why did that matter? Because there is no warning when a message with attachments is about to leave the organisation. Why was the whole client list in the attachment at all? Because the standard report has no filtered version. Suddenly "Sam was careless" has become three specific, fixable weaknesses, none of which is Sam.
A root cause analysis that ends at "human error" has stopped one question too early. Humans err at a fairly steady rate; good systems expect that and catch the error before it becomes a breach.
Turning findings into changes
Root causes are only useful if they change something. Typical outputs include:
- Technical controls: external recipient warnings, attachment checks, enforced encryption on devices and emails, multi-factor authentication, tighter access permissions
- Process changes: filtered report templates, a second pair of eyes on bulk mailings, revised leaver processes, confidential waste procedures for paper
- Training updates: refreshed guidance targeted at the specific failure seen, not just an annual generic reminder
- Policy updates: clearer rules on taking data off-site or using personal devices
Each action needs an owner and a date, and someone should verify later that it actually happened. A lessons-learned document that nobody actions is just a well-formatted description of the next breach.
The same discipline for near misses
Everything above applies to near misses too, which is precisely why Section 1 encouraged reporting them. A near miss gives you the entire root cause analysis at none of the cost.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention
Putting it into practice