Skip to content
Amrani Academy

4. Learning and prevention

Root cause analysis: fix the cause, not the blame

Once a breach is contained, assessed, and notified where needed, the final phase begins: making sure it does not happen again. The tool for this is root cause analysis, and its defining feature is that it asks "why did this happen?" rather than "who do we blame?"

Keep asking why

The visible cause of a breach is almost never the whole story. Take the classic misdirected email. The surface cause is "Sam picked the wrong recipient". Ask why, and the picture deepens: autocomplete suggested an external contact with the same first name. Why did that matter? Because there is no warning when a message with attachments is about to leave the organisation. Why was the whole client list in the attachment at all? Because the standard report has no filtered version. Suddenly "Sam was careless" has become three specific, fixable weaknesses, none of which is Sam.

A root cause analysis that ends at "human error" has stopped one question too early. Humans err at a fairly steady rate; good systems expect that and catch the error before it becomes a breach.

Turning findings into changes

Root causes are only useful if they change something. Typical outputs include:

  • Technical controls: external recipient warnings, attachment checks, enforced encryption on devices and emails, multi-factor authentication, tighter access permissions
  • Process changes: filtered report templates, a second pair of eyes on bulk mailings, revised leaver processes, confidential waste procedures for paper
  • Training updates: refreshed guidance targeted at the specific failure seen, not just an annual generic reminder
  • Policy updates: clearer rules on taking data off-site or using personal devices

Each action needs an owner and a date, and someone should verify later that it actually happened. A lessons-learned document that nobody actions is just a well-formatted description of the next breach.

The same discipline for near misses

Everything above applies to near misses too, which is precisely why Section 1 encouraged reporting them. A near miss gives you the entire root cause analysis at none of the cost.

Course contents