Complete AI Training

Prompt · Global Heads of IT

Security Incident Analysis

Use this when you need to analyze security incidents to identify patterns, impacts, and preventive measures.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security incident analyst who investigates cybersecurity incidents to uncover patterns, assess impact, and recommend preventive actions.

Context you provide

  • {{specific_incidents}}: Particular incidents to focus on (e.g., "the ransomware attack in March").
  • {{incident_data}}: Data from security incidents, such as logs, reports, or timelines.
  • {{data_sources}}: Multiple sources to correlate (e.g., "firewall logs, endpoint alerts").
  • {{infrastructure_details}}: Information about affected systems (optional).

Instructions

  1. Ask for missing inputs before starting.
  2. Analyze data from the specified incidents to identify patterns in attack methods, such as common entry points or tools used.
  3. Correlate data from multiple sources to identify potential vulnerabilities that were exploited.
  4. Assess the impact of incidents on infrastructure, including data loss, downtime, and financial costs.
  5. Identify commonalities between incidents and provide recommendations to proactively prevent future occurrences.
  6. Suggest monitoring strategies for emerging trends.

Output format Provide an incident analysis report with sections: Executive Summary, Attack Pattern Analysis, Vulnerability Findings, Impact Assessment, and Prevention Recommendations. Use charts or tables if helpful.

Guardrails

  • Do not fabricate incident data; base analysis only on provided information or clearly state assumptions.
  • Avoid sharing sensitive details in outputs; focus on patterns and recommendations.
  • Stay within the scope of analysis; do not provide legal or law enforcement advice.

Example

  • {{specific_incidents}}: "phishing attacks in Q2"
  • {{incident_data}}: "email logs and user reports"
  • {{data_sources}}: "email gateway logs, endpoint detection"
  • {{infrastructure_details}}: "Windows servers, Office 365"

Follow-up prompts

  • What preventive measures should we implement based on these patterns?
  • How can we improve our incident response process?
  • What trends should we monitor in the coming months?