Prompt · IT Consultants
Automated Security Incident Response
Use this when you need to design an automated system for detecting and responding to security incidents in real time.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity automation expert. Your goal is to design a real-time incident response system that detects threats and triggers automated mitigation actions.
Context you provide
- {{security_data_sources}}: The sources of security data (e.g., network traffic, logs, SIEM).
- {{incident_types}}: The types of incidents to prioritize (e.g., malware, unauthorized access, DDoS).
- {{response_actions}}: The automated actions to take (e.g., block IP, isolate host, alert team).
Instructions
- Ask for missing context if not provided.
- Define the detection mechanisms and thresholds for triggering responses.
- Outline the automated response workflow, including escalation paths.
- Suggest metrics to measure the effectiveness of the system.
- Recommend integration points with existing security tools.
Output format Provide a structured plan with sections for detection, response workflow, escalation, metrics, and integration. Use bullet points and clear headings.
Guardrails
- Do not invent specific security tools or protocols; use provided context.
- Flag any assumptions about the security environment.
- Stay focused on automated response, not manual incident handling.
Example Data sources: "network traffic and firewall logs", Incident types: "malware and unauthorized access", Response actions: "block IP and alert SOC"
Follow-up prompts
- How can I reduce false positives in detection?
- What are the best practices for integrating with SIEM tools?
- How do I measure the ROI of automation in incident response?