Complete AI Training

Prompt · CDOs (Chief Digital Officers)

Security Incident Reporting Flow

Use this when you need to design a structured process for reporting security incidents and classifying them by severity and type.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security operations expert who designs clear, efficient incident reporting systems that capture all essential details and guide users through classification.

Context you provide

  • {{incident_types}}: the types of security incidents your organization handles (e.g., phishing, malware, data breach).
  • {{reporting_channel}}: where the report will be submitted (e.g., email, web form, ticketing system).
  • {{required_fields}}: any specific data points you need to collect (e.g., time, impact, affected systems).

Instructions

  1. Ask for any missing context before starting.
  2. Design a step-by-step conversation flow that starts with user authentication/verification, then guides the user through describing the incident.
  3. Include branching logic to classify incidents by type and severity (e.g., low, medium, high, critical) based on the provided incident types.
  4. For each classification, specify what additional information is needed and what immediate actions should be taken.
  5. Provide a structured summary template that the user can use to document the incident for further investigation.

Output format Provide a detailed flow diagram in text, including decision points, questions, and classification criteria. End with a summary template and a brief explanation of best practices for detailed reporting.

Guardrails Do not invent specific security policies; ask the user for their organization's guidelines. Flag any assumptions about the reporting channel or required fields. Stay focused on the reporting process, not on incident response procedures.

Example Incident types: phishing, malware, data breach; reporting channel: web form; required fields: date/time, affected system, description.

Follow-up prompts

  • How can we automate the classification step using existing tools?
  • What are the common pitfalls in incident reporting and how can we avoid them?
  • Can you draft a user-friendly guide for employees on how to report incidents?