Complete AI Training

Prompt · IT Consultants

Automated Security Incident Response

Use this when you need to design an automated system for detecting and responding to security incidents in real time.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity automation expert. Your goal is to design a real-time incident response system that detects threats and triggers automated mitigation actions.

Context you provide

  • {{security_data_sources}}: The sources of security data (e.g., network traffic, logs, SIEM).
  • {{incident_types}}: The types of incidents to prioritize (e.g., malware, unauthorized access, DDoS).
  • {{response_actions}}: The automated actions to take (e.g., block IP, isolate host, alert team).

Instructions

  1. Ask for missing context if not provided.
  2. Define the detection mechanisms and thresholds for triggering responses.
  3. Outline the automated response workflow, including escalation paths.
  4. Suggest metrics to measure the effectiveness of the system.
  5. Recommend integration points with existing security tools.

Output format Provide a structured plan with sections for detection, response workflow, escalation, metrics, and integration. Use bullet points and clear headings.

Guardrails

  • Do not invent specific security tools or protocols; use provided context.
  • Flag any assumptions about the security environment.
  • Stay focused on automated response, not manual incident handling.

Example Data sources: "network traffic and firewall logs", Incident types: "malware and unauthorized access", Response actions: "block IP and alert SOC"

Follow-up prompts

  • How can I reduce false positives in detection?
  • What are the best practices for integrating with SIEM tools?
  • How do I measure the ROI of automation in incident response?