Skip to content

Post-Mortem Template

Security SpecialistOperations & StrategyDevops

Complete this after significant incidents (P1-P3). Focus on learning, not blame.

How to Use

  1. Copy this template to Post-Mortems folder
  2. Scribe creates draft before the post-mortem meeting
  3. Hold meeting within a week of resolution
  4. All responders contribute
  5. Every post-mortem produces action items with owners and deadlines
  6. Share with team (and publicly if appropriate)

Post-Mortem:

INCIDENT TITLE

Metadata

FieldValue
Incident DateYYYY-MM-DD
SeverityP1 / P2 / P3
Authors
StatusDraft / Final
Incident LogLink to incident log

Summary

[2-4 paragraphs. What happened, when, how long, how it was resolved. Someone unfamiliar should understand the incident after reading this.]


Impact

Users

  • Users affected:
  • Duration:
  • Services unavailable:

Financial

  • Funds at risk:
  • Actual losses:

Reputation

  • Public visibility:
  • Media coverage:

Timeline

Time (UTC)Event
Incident began
Detected
Response started
Root cause identified
Mitigation applied
Resolved

See linked Incident Log for detailed timeline.


Root Cause

Primary Cause

[What was the fundamental reason this happened?]

Contributing Factors

5 Whys

QuestionAnswer
Why did [incident] happen?
Why?
Why?
Why?
Why?

What Went Well

What Went Wrong

Where We Got Lucky

[What fortunate circumstances helped that we shouldn't rely on next time?]


Action Items

Every action item needs an owner and deadline.

ActionOwnerDeadlineStatus

Lessons for Runbooks

Should we create or update a runbook based on this incident?

  • New runbook needed: [type]
  • Existing runbook to update: [which one]
  • No runbook changes needed

Detection

AspectDetails
How detectedMonitoring / User report / Team member / Other
Time to detection
Could we detect faster?

Links

  • Incident Log: [Link to incident log]
  • Relevant PRs:
  • Dashboards:
  • External references:

Meeting Notes

Attendees:Discussion points:

Template based on Incident-Response-Policy