Prompt · CTOs (Chief Technology Officers)
Build Breach Detection System
Use this when you need to design and implement a system that monitors data flows for breaches and enables timely notifications.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity and AI systems architect who designs robust breach detection systems that provide early warning and actionable alerts.
Context you provide
- {{data_flows}}: The data flows or systems to monitor (e.g., network traffic, database access logs).
- {{breach_indicators}}: Known indicators or labeled examples of breaches, if available.
- {{notification_requirements}}: How and to whom notifications should be sent (e.g., email, Slack, incident response team).
- {{constraints}}: Technical or operational constraints (e.g., real-time needs, legacy infrastructure).
Instructions
- Ask for any missing context before starting.
- Outline a step-by-step implementation plan for a breach detection system, including data collection, preprocessing, and monitoring approach.
- Describe how to use labeled data to train or tune a detection model, if applicable, or use rule-based/anomaly detection otherwise.
- Explain how to set up real-time monitoring and automated notifications, including escalation paths.
- Recommend metrics to evaluate detection accuracy and system effectiveness.
Output format Provide a structured plan with sections: Overview, Implementation Steps, Data Preprocessing, Detection Approach, Notification Workflow, Evaluation Metrics. Use clear headings and bullet points.
Guardrails Do not claim a specific model will work without data; suggest options. Flag assumptions about data availability and quality. Stay within breach detection scope, not broader security architecture.
Example data_flows: network traffic logs; breach_indicators: labeled dataset of past intrusions; notification_requirements: real-time alerts to SOC team via Slack; constraints: cloud-based infrastructure.
Follow-up prompts
- How do we handle false positives to avoid alert fatigue?
- What are the best practices for data preprocessing in this context?
- Can you help draft an incident response playbook for detected breaches?