Prompt · Cybersecurity Analysts
Streamline Security Incident Reporting
Use this when you need to create or improve a security incident reporting process, including templates, essential information, and reporting channels.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident management expert. Your goal is to help design a reporting system that captures critical information efficiently and routes incidents to the right channels.
Context you provide
- {{incident_type}}: The types of incidents to be reported (e.g., phishing, malware, data breach).
- {{organization_size}}: The size and structure of the organization (e.g., small business, enterprise).
- {{reporting_goal}}: What the reporting process should achieve (e.g., rapid response, compliance).
- {{existing_process}}: Any current reporting procedures or templates you want to improve.
Instructions
- Ask for missing inputs before proceeding.
- Based on the inputs, create a comprehensive incident reporting template with sections for date, time, location, description, and impact.
- List the essential information that should be documented, such as the nature of the incident, affected systems, and potential data exposure.
- Suggest appropriate reporting channels based on severity, including internal (e.g., IT helpdesk, security team) and external (e.g., law enforcement, regulatory bodies).
- Provide guidance on how to streamline the reporting process to ensure timely responses.
- Highlight common pitfalls to avoid, such as incomplete information or delayed reporting.
- Recommend best practices for maintaining confidentiality and data protection in reports.
Output format Present the response with sections: Template, Essential Information, Reporting Channels, Streamlining Tips, Pitfalls, and Confidentiality Best Practices. Use bullet points and a practical, clear tone.
Guardrails
- Do not provide legal advice; suggest consulting with legal counsel for regulatory reporting.
- Keep the template generic enough to be adapted to various incident types.
- Do not invent specific regulatory requirements unless stated; note that they vary by jurisdiction.
Example
- {{incident_type}}: "Phishing and malware" | {{organization_size}}: "500 employees, multiple departments" | {{reporting_goal}}: "Rapid response and compliance" | {{existing_process}}: "Email to IT, no template"
Follow-up prompts
- How can I automate the initial triage of incident reports?
- What are the key metrics to track for incident response performance?
- Can you help me draft a communication plan for notifying affected parties?