top of page
Search

The Exercise Is Over. Now What?Why After Action Reviews Matter

9 hours ago
5 min read

Imagine this: your organization spends weeks preparing for a cybersecurity tabletop exercise. Leadership participates, staff work through a realistic scenario, and the conversation uncovers several important issues. Someone realizes the emergency contact list is outdated. Another team discovers there is confusion about who has the authority to things shut down.


Everyone agrees it was a valuable exercise. Notes are taken, the meeting ends, and everyone goes back to work.


Six months later, the same outdated contact list is still in the plan. Sound familiar?


October is Cybersecurity Awareness Month, and with the mid-term election approaching, many organizations are taking time to review cybersecurity plans, continuity procedures, incident response processes, and emergency communications. It is also a great time to run tabletop exercises and test whether those plans actually work.

But conducting the exercise is only half the job.


The real value comes from what happens after the exercise is over.


The Exercise Finds the Gaps. The AAR Helps Close Them.

An After Action Review, commonly called an AAR, is a structured discussion about what happened during an exercise, incident, project, or significant event. It gives the people involved an opportunity to step back and compare what was supposed to happen with what actually happened.


The conversation does not have to be complicated. At its core, an AAR asks a few basic questions: What worked? What did not work as expected? What surprised us? What should we do differently next time?


Those simple questions can uncover some of your organization’s most important vulnerabilities.


A tabletop exercise may reveal that nobody knows who should contact a critical vendor during an emergency. It may show that a recovery procedure references an employee who left two years ago, or that two departments have completely different assumptions about who makes decisions during a crisis.


Finding those gaps is important, but finding them is not the finish line. The AAR is where you decide what to do about them.


Capture the Lessons While They Are Fresh

Details fade quickly. Immediately after an exercise, participants usually remember the moments when something felt confusing, when a decision took too long, or when someone suddenly said, “Wait, how would we actually do that?” Those are exactly the moments you want to capture.


A few weeks later, everyone is back to their normal responsibilities and those details start disappearing.


That is why the initial AAR should happen as soon as practical after the exercise or event. Give participants an opportunity to talk about what surprised them, what slowed them down, and what information or resources they wish they had.


Just as importantly, include the people who actually perform the work. Executives and leadership may see one part of the situation, while the person answering phones, processing payroll, communicating with residents, supporting students, or working directly with customers may see something completely different.


Those perspectives are often where the most useful lessons are found.


Make the Conversation About Learning, Not Blame

A good AAR should never feel like an investigation into who made a mistake. If people believe they are going to be criticized for identifying a problem, they will quickly learn to stop identifying problems. That defeats the entire purpose.


Instead of asking, “Why didn’t you know what to do?” ask, “What information would have made that decision easier?” Instead of asking who forgot to update something, ask what process could ensure it stays current in the future.


That small change in approach matters.


The goal of an AAR is to understand why the organization responded the way it did and how the organization can improve. People need to feel comfortable saying, “That did not work,” or “I wasn’t sure what I was supposed to do.”


Honest conversations lead to useful improvements. Defensive conversations usually lead to a report that sits on a shelf.


Turn Observations Into Actions

One of the easiest AAR mistakes to make is producing a detailed report filled with observations and recommendations, then never doing anything with it.


A finding such as “the emergency contact list was outdated” is useful, but it is incomplete. The better next step is to decide who will update it, when it will be completed, and how often it will be reviewed going forward.


For example, the improvement might become: Human Resources will validate the emergency contact list every quarter, with the first review completed by the end of November.


Now you have more than an observation. You have an action, an owner, and a timeframe.


The same approach should apply to larger findings. If your exercise identifies uncertainty around executive decision-making, assign someone to clarify the process. If backup procedures were unclear, identify who will revise and test them. If staff could not locate the incident response plan, decide how and where it should be made available.


If nobody owns the improvement, chances are good that it will not happen.


Update the Plans While the Lessons Still Matter

This is where the AAR process comes full circle. If your tabletop exercise identifies a problem with your Incident Response Plan, Continuity of Operations Plan, Continuity of Government Plan, Disaster Recovery Plan, cybersecurity policies, emergency communications procedures, vendor information, or staff responsibilities, update those documents.


Do not wait until next year’s exercise. Your plans should reflect what your organization knows today, not what it knew when the document was originally written. Staff change, vendors change, systems change, responsibilities shift, and new risks emerge.


A plan that never changes eventually becomes a historical document instead of an operational one.


That is why exercises and AARs work so well together. The exercise tests the plan. The AAR identifies what needs to improve. The updates make the plan stronger for the next time you need it.


Pay Attention to What Worked, Too

AARs should not focus only on mistakes and gaps. Sometimes an exercise reveals that a process worked extremely well. Maybe staff communicated quickly across departments. Maybe someone recognized a phishing indicator immediately. Maybe your backup process performed exactly as expected, or someone developed an effective workaround that had never been formally documented.


Those successes should be captured and reinforced.


Understanding why something worked can be just as valuable as understanding why something failed. In some cases, the best outcome of an exercise is discovering an informal practice that should become part of your standard process.


An AAR should help you do more of what works and less of what does not.


Then Test It Again

The best preparedness programs operate as a cycle, not as a series of disconnected events. You plan, exercise, review, improve, update, and exercise again.


If your first tabletop revealed confusion about who has authority to make a critical decision, clarify the process and deliberately test it during the next exercise. If your emergency communications process did not work, improve it and create a scenario that forces the organization to use it again.


The goal is not to prove that your organization has a perfect plan. No plan will account for every possible situation. The goal is to become better at adapting when something unexpected happens.


That is what resilience really looks like.


October Is a Great Reminder, but Improvement Should Be Year-Round

Cybersecurity Awareness Month gives organizations a natural reason to review plans and talk about preparedness. The upcoming election provides another timely opportunity for government organizations to think about cybersecurity, communications, continuity, staffing, vendors, and incident response.


Take advantage of that momentum. But do not let the work stop when October ends or when the election is over. Every exercise, service disruption, cyber incident, major project, outage, and unexpected operational challenge is an opportunity to learn something about your organization.


The important question is whether you take the time to capture that lesson and turn it into an improvement.


Running the exercise shows that you are willing to prepare. Completing the After Action Review, assigning improvements, updating the plans, and testing them again is what makes your organization better prepared the next time.


If your organization is reviewing cybersecurity, continuity, disaster recovery, or incident response plans, Sage 497 Consulting LLC would be happy to help facilitate exercises, After Action Reviews, or improvement planning. Sometimes an outside perspective can help turn lessons learned into practical changes before you really need them.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page