Cyber Attack1404 · Module II · Lesson 06 of 8
Article · 12 min

Post-incident review

The blameless retrospective.

Summary

The blameless retrospective. Inside Cyber Attack, Module II — Aftermath — this lesson names a specific move the CEO makes when the situation calls for it. The register is institutional: a working understanding of Post-incident review, sized to be reached for in a real conversation, not recited from a slide.

Objectives
  • 01State Post-incident review in the disciplined sense used throughout Cyber Attack, without softening or slogan.
  • 02Recognize the situation in which Post-incident review is the right move — and the adjacent situation in which it is the wrong one.
  • 03Execute Post-incident review in a live case drawn from your own work or a documented case study, and defend the reasoning in one paragraph.
  • 04Connect Post-incident review to the practiced judgment that governs the institution under fire so it strengthens the practice rather than replacing it.
The Lesson

The situation, stated plainly

The blameless retrospective. Read the sentence twice. It is not a slogan; it is the compressed form of the lesson. The rest of this module returns to it, so the sentence is worth learning by heart. When the CEO briefs post-incident review, this is what the move actually is — no more, no less.

Where it lives in the CEO's calendar

Module II exists because . Post-incident review is one of the the CEO's craft moves that lives inside that situation. Notice which earlier lessons this one leans on and which later lessons will lean on it — the sequencing is deliberate, and the module reads differently once you place this piece.

How the CEO actually handles it

In practice, the CEO does not consult Post-incident review the way a novice consults a checklist. The move is trained in until it becomes an available response — something to sequences without ceremony when the moment arrives. The mark of understanding is not that you can recite Post-incident review; it is that you catch yourself using it, unprompted, and can explain afterward why you did.

The board-book misreading, corrected

The most common misreading is to treat Post-incident review as a maneuver you deploy on the other party. It is not. The CEO's institution remains itself through the crisis and better after it — and the professional application of Post-incident review sits inside that criterion, not outside it. When the move is used cynically, the results are short-lived and the reputation cost is high. When it is used cleanly, it compounds.

Key Ideas
  • Post-incident review is a working move, not a slogan.
  • It belongs to Module II — Aftermath — because that is the situation it addresses.
  • Mastery is unprompted use in the right situation.
  • The adjacent lessons in this module are its natural context.
  • Used cleanly, Post-incident review compounds; used cynically, it does not.
References
  • Horowitz, B. — The Hard Thing About Hard Things.The unvarnished account of the CEO's recurring crises.
  • Buffett, W. — Berkshire Hathaway Chairman's Letters.The canonical annual writings on institutional stewardship.
  • Bower, J. — The CEO Within.The disciplined study of succession and executive judgment.
  • 1404 — Cyber Attack, Module II: Aftermath. The Anabasis Academy.The parent module. Re-read the module framing after finishing the lesson.