Identifying the actual root cause of a security incident is not always as straightforward as you think it is. If you have a security incident that is caused by malware, then often the user gets blamed because he/she clicked on a phishing link and/or visited a doggy website. But actually, a technical security control failed. Was the antimalware solution active, running and were the latest signatures and product updates applied? If not, then the question is why not? If they were applied, then more investigation is required to discover why the antimalware security control failed. This technique is also known as the 5-Why technique. Every time you identify a cause, you ask yourself the question ‘Is this the real root cause behind the security root?’. Important here is to answer the why question. But is this the only technique you can apply to identify a root cause?