Cyber Incident Analysis

Cyber incidents
don’t happen
in a vacuum.

Tram C reveals not only the technical failures behind a cyber incident, but the organisational, cultural and managerial conditions that made them possible — giving your organisation the complete picture needed to prevent recurrence.

Who We Serve

Tram C is designed for organisations where a thorough understanding of cyber incidents is not optional.

Organisations After an Attack

Your systems are back online. But do you know why it happened — and how to prevent the next one? A technical post-mortem stops at the infrastructure layer. Tram C surfaces the organisational decisions and cultural conditions that enabled the attack to succeed.

Regulatory Authorities

When reviewing an organisation's response to a cyber incident, you need a clear standard against which to assess depth and quality of the analysis. Tram C provides that framework, covering technical, ICT, organisational and external causal dimensions in a structured, auditable form.

Standard incident analysis stops too soon.

Most post-incident analyses focus exclusively on the technical chain of events: what system failed, what vulnerability was exploited, what the attacker did. These findings matter — but they explain only part of the story.

The conditions that allowed the attack to succeed — insufficient security investment, organisational silos, outdated governance, a culture where risk warnings go unheeded — are rarely surfaced. Without addressing these root causes, the next incident is a matter of when, not if.

  • Technical fixes alone do not prevent recurrence
  • Organisational and cultural factors are systematically overlooked
  • Recommendations are generated without a clear implementation priority
  • Crisis management effectiveness is almost never formally evaluated
154
Actionable recommendations on average per Tram C analysis
76
Causal factors uncovered on average across all organisational layers
4
Analytical layers — from external causes to physical outcomes

The Tram C Method

A validated, academically-grounded method for comprehensive cyber incident analysis, developed through iterative real-world application at major telecommunications operators.

Four-Layer Analysis

Every incident is mapped across four layers: External conditions, Organisational decisions, ICT systems, and Physical/Actor events — revealing the complete causal chain from boardroom to breach.

Onset & Resolution

Tram C analyses both how the incident developed and how the crisis was managed. Each phase exposes different organisational strengths and weaknesses — both are equally important for resilience.

Cascade Detection

Tram C explicitly models positive feedback loops — the cascade dynamics that amplify incidents into full outages — and identifies exactly where they can be interrupted to limit future damage.

Prioritised Recommendations

Recommendations are clustered by organisational capability and ranked using a five-level maturity model — so leadership knows exactly where to invest first for maximum resilience gain.

Blame-Free by Design

The analysis begins with an objective technical reconstruction — establishing shared facts before examining human and organisational factors. This creates the constructive atmosphere needed for honest, complete findings.

Academically Validated

Developed through iterative real-world case studies and published in peer-reviewed journals. Tram C extends AcciMap — the most widely cited systemic accident analysis method in international academic literature.

How an Analysis Is Conducted

01

Preparation

Review available documentation and brief the organisation on the analysis process, ensuring the right experts are available and the collaboration runs smoothly.

02

Map the Technical Path

Establish an objective, factual account of the technical sequence — without assigning blame — creating a shared foundation for the full analysis.

03

Map the Consequences

Systematically document the direct and indirect consequences of the incident — for services, the organisation, and stakeholders. This provides the basis for understanding severity and evaluating crisis management.

04

Map Causes Across 4 Layers

Systematically map all contributing causes across four analytical layers: external conditions, organisational decisions, ICT systems, and physical/actor events.

05

Connect Causes and Fill Gaps

Connect the identified causes in a causal diagram, identify and fill missing links, and map cascade dynamics — the positive feedback loops that amplified the incident.

06

Formulate and Prioritise Recommendations

Formulate recommendations in collaboration with workshop participants based on the verified causal diagram, then prioritise them using an organisational maturity model so management knows exactly where to invest first.

Tram C is based on AcciMap — the most widely applied systemic accident analysis method in academic literature — and has been scientifically validated through multiple real-world case studies.

Request the Research Papers

Our Services

From building internal capability to independent investigation and ongoing improvement — Australius supports you at every stage of the incident analysis cycle.

01

Training

Structured training programmes that equip your teams with the Tram C methodology. We train both technical and non-technical staff, enabling your organisation to build independent capability for thorough incident analyses.

  • Workshop-based, interactive learning
  • Tailored to your sector and organisational context
  • Suitable for technical teams and governance functions alike
02

Investigation

Expert-led incident analysis using the Tram C method. We work with your subject matter experts to produce a comprehensive causal map, a full set of prioritised recommendations, and a report suitable for board and regulatory use.

  • Led by the developer of the Tram C method
  • Covers technical, ICT, organisational and external dimensions
  • Structured output suitable for regulatory submission
03

Improvement Support

Turning the output of an analysis into concrete, sustained organisational change. We help you develop an implementation roadmap, prioritise investments, and translate recommendations into measurable actions with clear ownership.

  • Maturity-model driven prioritisation of recommendations
  • Cross-functional coordination and stakeholder alignment
  • Progress tracking and reporting framework
04

Evaluation

After improvements have been implemented, we assess whether the intended resilience gains have been achieved — providing your board and supervisory authorities with independent, evidence-based assurance.

  • Objective, independent assessment
  • Benchmarked against original recommendations
  • Suitable for regulatory submission and board reporting

Ready to understand what really happened?

Whether you have recently experienced an incident, are implementing NIS-2 compliance measures, or need an independent analysis framework — we would like to hear from you.

Complete the form and we will be in touch within two business days.

Australius is based in Groningen and works with organisations across the Netherlands and beyond.

info@australius.nl

We will be in touch within two business days.