How do you actually improve cybersecurity skills assessment results for incident response?
Been thinking about this since our last exercise. We have great telemetry for the technical side of an incident: logs, timelines, forensic artifacts. We have almost nothing for the human side: which analyst hesitated on a call they should've made fast, where the escalation stalled because someone didn't know who to loop in, whether the person running comms actually had the information they needed when they needed it.
Post-exercise "debriefs" tend to be a group discussion where the loudest opinion wins, not data. Is anyone working on ways to actually instrument this: decision timestamps, communication logs, something more rigorous than a vibes-based retro?