Joey Victorino
Capability
Incident Closure Review
Lead
Joey Victorino — personally led
Basis
After the responder’s final report · before the board, the regulator, or the insurer is told closed

An independent incident closure review before the board accepts the word contained.

The incident response firm has delivered its report and the recommendation is to close. Before you accept that, someone with no stake in the answer should read the evidence it rests on.

What I do

Re-read the evidence, not the reportI go back to what was actually collected: the forensic images, the logs, the endpoint telemetry, the identity records, the timeline. The report is the responder’s interpretation. The review tests the interpretation against the source.
Test each material conclusionInitial access, scope, persistence, exfiltration, eradication. Each conclusion is either supported by a named artifact, inferred from the absence of one, or assumed. I write down which, and what the difference means for the decision in front of you.
Name what was never examinedThe systems not imaged, the log sources not retained, the identities not reviewed, the third parties not asked, the time window not covered. Evidence gaps are findings. They are where the second intrusion lives.
State whether closure holdsHolds, holds only with named conditions, or does not hold. One of the three, in writing, with my name on it, along with what has to happen before the minutes record the incident as closed.

Who it is for

General counsel, audit committees, boards, and the CISO who has to sign the closure memo. Most often the report came from an insurer-panel firm, engaged under the policy, on a scope and a budget the carrier approved. That firm may have done good work. It also had a client relationship to protect and a clock to beat, and the questions it did not ask are not in the report. A second opinion from someone off the panel, who does not sell the remediation and will not be hired for the next incident on the strength of what he says about this one, is the check.

The moment is after the responder’s final report and before the closure decision hardens into regulator notifications, customer letters, an insurance narrative, or a representation in a transaction. It is the question the board is actually asking: was it contained, and how do we know. If the intrusion is still active, that is incident response, a different engagement on a different clock.

When not to hire me

Do not hire me to confirm a closure the board has already announced, or to produce a friendlier version of the panel firm’s findings. If the evidence was never preserved and cannot be recovered, I will say the review cannot reach a conclusion, and that is the conclusion you will get. If what you need is a re-run of the full investigation, that is a larger engagement and I will scope it as one rather than call it a review. And if the responder’s work is sound, the review will say so plainly, which is worth having in the file but is not what everyone wants to pay for.

What you get

A written determination of whether the evidence supports contained, eradicated, and closed, tested conclusion by conclusion against the record, with the unexamined areas named and the additional collection or analysis needed to close them. Where the responder’s conclusions hold, the review says so, and the board has an independent basis for its decision. Where they do not, the board hears it from me, in private, before it hears it from the attacker or the regulator. I do not take insurer-panel work, I do not sell the remediation, and the person who reads the evidence is the person who signs the conclusion.

It arrives as a written conclusion in the format of the sample memorandum: the question, the evidence reviewed, the assumptions it rests on, the findings, the unknowns, and what to do next.

Questions people ask

What is an incident closure review?

An independent review, after an incident response firm has reported, of whether the evidence supports the conclusion that the breach was contained and eradicated. It re-reads the collected evidence, tests each material finding against it, identifies what was not examined, and states in writing whether closure holds, holds with conditions, or does not.

How much does an incident closure review cost?

Typically $20,000–$30,000+ depending on scope. Engagements are scoped and priced in writing after a short scoping call. Scope depends on the size of the evidence set, the number of conclusions in the responder's report, and the date the board is working to. Contact me with the report's table of contents and the decision date, and I will reply with a written scope.

Why not ask the incident response firm to confirm containment?

You can, and you should. But the firm is checking its own work, on the evidence set it chose to collect, under the scope the insurer approved. A second opinion from someone with no role in the response and no stake in the outcome answers a different question: not whether the firm did what it was asked, but whether what it was asked was enough.

Related reading