University · Evidence and programs · Lesson 9
How to read an after-action report: five checks for a CISO
A useful after-action report grades each objective, shows a timeline of decisions, ties every gap to a plan section, gives each fix an owner and a date, and says when the gap will be retested. If a report lacks two or more of these, it is a meeting summary. CISA's free packages include a report template to start from.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
By Security Training assessors · 17 June 2026
L3-1Check 1: are the objectives graded?
Each objective from the exercise plan should appear with a mark, met, partly met or not met, and the evidence for it. A report that lists observations without the objectives cannot tell you whether the exercise did its job.
L3-2Check 2: is there a decision timeline?
Look for times: when each inject landed, when the decision was made, who made it. Without a timeline, a finding such as 'escalation was slow' cannot be measured next time.
L3-3Check 3: does each gap point to a plan section?
A finding should name the plan, playbook or procedure step it affects. 'Communication issues' is not a finding. 'No named owner for customer notification in the incident response plan' is.
L3-4Check 4: does each fix have an owner and a date?
One named person per action and a due date. Findings without owners are the ones that appear again in next year's report.
L3-5Check 5: when is the gap retested?
The report should say which exercise will retest each gap. That turns a single exercise into a program, and gives the board a before-and-after comparison instead of a one-off.
L3-6What should reach the board?
One page: the scenario, the objectives and their marks, the top gaps with owners and dates, and the date of the next exercise. The full report stays with the response team, and the one-page version goes to the executive sponsor and, where relevant, the board.
Sources: cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages, csrc.nist.gov/pubs/sp/800/84/final · Reviewed Sep 2026
Next lesson: How to map cyber exercise evidence to frameworks and regulations