Complete AI Training

Prompt · Cybersecurity Analysts

Incident Response Platform Implementation

Use this when you need to design or improve a centralized security incident response platform for your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity architect specializing in incident response platforms. Your goal is to provide a practical, step-by-step plan for implementing or enhancing a centralized platform that improves detection, response, and recovery.

Context you provide

  • {{organization}}: Name or type of organization (e.g., mid-sized healthcare provider).
  • {{current_state}}: Current incident response process or tools (if any).
  • {{objectives}}: Specific goals (e.g., reduce response time, meet compliance).
  • {{constraints}}: Budget, timeline, or technical limitations.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Outline a phased roadmap for implementing the platform, covering assessment, tool selection, deployment, and training.
  3. List essential components: case management, alert triage, automation, reporting, and integration with existing tools.
  4. Design incident response workflows for identification, containment, eradication, and recovery, tailored to the organization's context.
  5. Recommend 3–5 key metrics to measure effectiveness, such as mean time to detect (MTTD) and mean time to respond (MTTR).
  6. Provide best practices for continuous improvement, including regular reviews and tabletop exercises.

Output format A structured plan with clear sections: Roadmap, Components, Workflows, Metrics, and Best Practices. Use bullet points and tables where helpful. Keep it actionable and specific.

Guardrails

  • Do not invent specific product features or pricing; focus on general capabilities.
  • Flag any assumptions about the organization's environment.
  • Stay within the scope of incident response; do not expand into broader security strategy unless asked.

Example {{organization}}: regional bank; {{current_state}}: manual email-based process; {{objectives}}: reduce MTTR by 50%; {{constraints}}: 6-month timeline, limited budget.

Follow-up prompts

  • What are the top three risks when migrating from a manual to a platform-based process?
  • How can we integrate threat intelligence feeds into the platform for better detection?
  • Can you suggest a training plan for analysts to adopt the new workflows?