Desk live·
ForensicPost
Ransomware/Method/File 25-1107

Nevada Published After-Action Reports Almost No Other Public Body Does

Nevada has published public-facing after-action reports and shared lessons at conferences. It is the practice this corpus has spent 380 files establishing does not exist.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPublic-sector disclosure practice
ActorUnattributed
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Nevada has been described as publishing public-facing after-action reports following cyber incidents and sharing lessons at conferences and other forums.

This Is The Gap The Corpus Keeps Naming

At 25-0522 this desk recorded that published advisories convey indicators and hunting guidance but never what the experience was like — how the access looked to the people who found it, what convinced them, what they tried that did not work.

That file concluded such knowledge normally stays inside the affected organisation, because sharing it means describing your own failures to peers and potential litigants, and that an exercise was the only mechanism the corpus had found for moving it.

A published after-action report is a better mechanism, and it is the first one this database has recorded.

Public Bodies Can Do It And Companies Structurally Cannot

A US state faces public records law, legislative oversight and no shareholders. Publishing a candid account of what went wrong is uncomfortable and not litigable in the way it would be for a company facing the 1,900 class actions at 25-1228.

A company that published the same document would be handing a plaintiff’s firm its case. The litigation mechanism this corpus filed as the fastest accountability route in the US therefore suppresses the single most useful output an incident can produce.

That is a real trade-off and this desk does not know how to resolve it. Protected disclosure — a safe-harbour for candid technical accounts, inadmissible in litigation — exists in other safety-critical fields and appears nowhere in the 2025 reforms at 25-1113.

And It Is The Corpus’s Own Selection Bias, Addressable

At 25-0807 this desk recorded that a database assembled from disclosures records failures in detail and successes almost never, so every generalisation here about response is drawn from organisations whose response did not work.

After-action reports are the correction. If they were routine, this corpus would be able to say what works rather than only what failed. Graded medium: the practice is described in reporting and this desk has not reviewed the reports themselves.

This is an analysis file

Built on reporting of the practice, listed below. This desk has not reviewed the underlying after-action reports. Corrections: corrections@forensicpost.com.

Sources
  1. How St. Paul, Minn., recovered from a ransomware attackGovTech
  2. St. Paul, Minnesota, fell victim to a cyberattack in July. It’s still recovering.Smart Cities Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary