Double Loop Learning

A disciplined way of questioning and testing the underlying values and assumptions behind actions to uncover true root causes and craft better countermeasures, rather than treating only the symptoms.

Key Points

  • Goes beyond quick fixes by examining the beliefs, rules, and policies that drive behavior.
  • Used in retrospectives and postmortems to reach root causes and design systemic changes.
  • Requires psychological safety so team members can challenge assumptions without blame.
  • Often results in updates to workflows, definitions of done, policies, and decision criteria.

Example

During a sprint retrospective, a team keeps missing integration targets. Instead of adding more buffer or extra testing (a surface fix), they question their working agreements and Definition of Done. They discover that integrating only at the end of the sprint and having separate code branches are core assumptions causing the delays. The team changes policy to integrate daily, adopts trunk-based development, and pairs on merge conflicts. The misses drop significantly in the next release.

PMP Example Question

A Scrum team repeatedly experiences production defects. The Scrum Master proposes challenging the teams Definition of Done, testing strategy, and release policy to uncover root causes before choosing fixes. What approach is the Scrum Master using?

  1. Single-loop learning focused on quick corrective actions
  2. Double loop learning that questions underlying assumptions and policies
  3. Updating the lessons learned register only
  4. Issuing a change request to add more testers

Correct Answer: B — re-examining underlying assumptions to fix root causes

Explanation: Double loop learning explicitly challenges governing values and assumptions to identify and address systemic causes, not just symptoms.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course