The organization shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber resilience.
Lessons learned from incident handling shall be translated into updated or new incident handling procedures that shall be tested, approved and trained.