Connecting election experts, advancing security
Planning insights from the Election Security Exchange

Planning Desk, Week E-21: Post-Incident Activity—Power-up!

Post-incident activity is the final phase of the Incident Response Process, centered on organizational learning to prevent future incidents or mitigate their impact. After recovery is complete – whether the incident was cyber, operational, or physical – this phase is a critical opportunity to capture lessons learned, strengthen incident response and reporting, and enhance overall election security and resilience. 

Prioritize post-incident activity with three straightforward steps:

  1. Schedule a lessons-learned meeting.
    • Involve all relevant stakeholders.
    • Attendance should be mandatory following any major incident.
    • Your Election Security Working Group should meet after every incident, regardless of severity.
  2. Set clear goals to drive actionable improvement.
    • Understand the root cause of the incident.
    • Evaluate and refine response and reporting processes.
    • Bolster election security and resilience.
  3. Review the incident timeline, response effectiveness, and communication flow by asking these questions:
    • What happened?
    • How well did the Incident Response Team perform?
    • Were our Incident Response Plan and procedures followed?
    • Were our Incident Response Plan and procedures adequate?
    • What information was missing?
    • What actions slowed recovery?
    • What could be done differently?
    • What can be done to prevent future incidents?
    • What indicators should be monitored in the future?
    • Encourage participants to raise additional questions relevant to your jurisdiction to help the Election Security Working Group identify and address vulnerabilities.

Continuous improvement through post-incident analysis sharpens response strategies and reduces the likelihood or impact of future incidents. Every jurisdiction should regularly revisit and test its Incident Response Plan with the core team and security partners who would support real-world response and recovery.

Encourage your team and partners to subscribe to this newsletter to stay informed about good practices as you update your Incident Response Plan in advance of the 2026 general election.


The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.