Business & Technology
Semperis’ Hargraves says real-time documentation boosts cyber resilience
When investigating the cause of a cybersecurity crisis, “You can’t improve what you can’t reconstruct and what you’ve forgotten,” stated Marie Hargraves, Principal Crisis Management Consultant at Semperis. Adding, organisations build genuine cyber resilience not during the acute phase of an incident, but in the post-incident review that follows it.
Hargraves, who supported and exercised national crisis and incident response teams across government and healthcare sectors in the United Kingdom, said real-time documentation captured during a crisis is central to making that review effective.
The approach: applying the concept of continual service improvement to a crisis. Examining where an organisation’s processes, people or technology fell short. That might mean an escalation path that was missing, or an unplanned piece of shadow IT that only became apparent once the organisation was forced to work around it.
“It should be part of your crisis plan, it shouldn’t be separated,” said Hargraves. “The post-incident review should happen straight away.”
She said a mature organisation would typically aim to close most gaps in its people, processes and technology within six months of an incident, though full recovery can take longer where digital infrastructure has been affected, and staff have had to revert to manual processes in the interim. A separate challenge then emerges when digital systems come back online: someone has to transfer manual records and processes back into digital systems, a task she said is often overlooked in recovery planning.
Semperis’s crisis management platform, Ready1, is designed to operate independently of an organisation’s main IT and communication systems, so that it remains usable if a network is degraded or compromised during an incident. Hargraves said the tool automatically timestamps actions and tasks in both GMT and local time as a crisis unfolds, which she said matters for organisations with a global footprint, and allows teams to manually add context around decisions as they are made.
“If anyone has ever been in a [cyber] crisis, you’ll know that memory degrades quickly during high-pressure incidents. Critical decisions, assumptions, and pivots are often lost if they’re not documented as events unfold. This is where the resilience happens post-incident. So it’s these nuances and these pivots that, if you can document them in real time in one single source of truth, you’re going to be able to look at those lessons identified and action them, which is going to increase your resilience overall,” she said.
The platform stores contact details, cyber insurance policies and third-party retainer information that teams often struggle to locate quickly during a live incident, alongside documents that remain accessible even if an organisation’s own network is unavailable. This extends to verifying, in advance, that contacts such as a firewall vendor or retainer partner are still current, rather than an organisation discovering during a crisis, in the early hours of the morning, that a contact has since left the role.
The aim is to allow any team involved in a crisis, whether cyber, legal or finance, to reconstruct a full and accurate timeline of what happened once the incident has ended, using a single record rather than piecing one together from separate systems and handover notes.
Hargraves worked within the UK Home Office Digital Data and Technology Directorate, and said the experience shaped her approach to post-incident review at Semperis. She contrasted this with what she described as a common pattern in organisational exercises, where teams run a scheduled test every six months without anyone committing to a decision, then repeat the same exercise later having changed little, often because staff are reluctant to take ownership of a call.
She said she would instead re-exercise her team against a previous real crisis roughly every six months, testing whether lessons identified at the time had actually been acted upon. She said this mattered because of high turnover in cybersecurity functions, citing what she described as an average turnover of around 40 per cent a year in security operations centres, which she said meant lessons risked being lost if they were not embedded into process rather than left with the individuals who identified them.
Hargraves was supporting incident response during the SolarWinds Orion compromise in 2021, which she described as a supply-chain failure with dependencies across many systems that few organisations had anticipated. She said the episode underlined the need for organisations to complete business impact analysis in advance of a crisis, understanding which dependencies exist and what losing them would mean, rather than discovering that during the incident itself.
Organisations need to translate technical detail into terms the wider business understands, framing incidents around business outcomes rather than purely technical detail, so that leadership, operational teams and cyber specialists are working from the same account of events. She said this is only possible if the decisions and context behind them are captured as they happen, rather than reconstructed from memory afterwards.
“I think communication is one of the biggest cybersecurity vulnerabilities we have, because we are still siloing digital teams from the operational businesses,” said Hargraves. ” So perhaps we need to get a little bit better at positioning how we’re talking through a crisis and put it into terms of business outcomes, so we’re all talking the same language.”