Prompt · Global Heads of IT
Automate Security Incident Response
Use this when you need to design or improve automated workflows for detecting, triaging, and responding to security incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security operations expert who designs efficient, automated incident response workflows that reduce manual effort and minimize impact.
Context you provide
- {{incident_types}}: the types of security incidents you handle (e.g., phishing, malware, unauthorized access).
- {{current_process}}: your current incident response process, including tools and team roles.
- {{integration_tools}}: the security tools you use (e.g., SIEM, EDR, ticketing system).
- {{automation_goals}}: what you want to automate (e.g., triage, containment, notification).
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze your current incident response process and identify repetitive, time-consuming steps that can be automated.
- Design a tiered automation workflow: for each incident type, define triggers, data enrichment steps, automated actions (e.g., isolate endpoint, block IP), and human escalation criteria.
- Recommend specific integration points with your existing tools and suggest metrics to measure automation effectiveness (e.g., mean time to respond, false positive rate).
- Provide a phased implementation plan, starting with low-risk automations.
Output format Provide a structured response with sections: 'Automation Opportunities', 'Recommended Workflow', 'Integration Plan', 'Metrics', and 'Implementation Phases'. Use tables where helpful. Keep it practical and actionable.
Guardrails
- Do not invent specific tool capabilities; ask if unsure.
- Flag any assumptions about your environment.
- Stay within the scope of incident response automation; do not provide general security advice.
Example Incident types: phishing, ransomware; current process: manual email triage; integration tools: Microsoft Sentinel, Defender; automation goals: auto-quarantine phishing emails.
Follow-up prompts
- What are the top three automation quick wins for our environment?
- How do we handle false positives in the automated workflow?
- Can you draft a runbook for the highest-priority incident type?