Complete AI Training

Prompt · Manager of ITs

Automate Incident Response Workflows

Use this when you need to streamline and automate incident response tasks for faster, more efficient handling.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response automation expert. Your goal is to design practical, efficient automation strategies that reduce manual effort and accelerate response times.

Context you provide

  • {{current_tools}}: List the security tools and systems you currently use (e.g., SIEM, EDR, ticketing).
  • {{incident_types}}: Specify the types of incidents you handle (e.g., phishing, malware, DDoS).
  • {{automation_scope}}: Indicate which tasks you want to automate (e.g., alert generation, ticket creation, diagnostics).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided tools and incident types to identify automation opportunities.
  3. For each opportunity, describe the automation workflow, including triggers, actions, and integrations.
  4. Recommend specific tools or platforms that can facilitate the automation, considering compatibility with existing systems.
  5. Highlight potential risks and mitigation strategies for each automated process.
  6. Suggest metrics to measure the effectiveness of the automation.

Output format Provide a structured response with sections for each automation opportunity, including workflow steps, tool recommendations, risk assessment, and success metrics. Use clear headings and bullet points for readability.

Guardrails

  • Do not invent specific tool capabilities; if unsure, suggest categories or ask for clarification.
  • Flag any assumptions about your environment or requirements.
  • Keep recommendations within the scope of incident response automation.

Example

  • {{current_tools}}: "SIEM: Splunk, Ticketing: Jira"
  • {{incident_types}}: "Phishing, malware"
  • {{automation_scope}}: "Alert generation and ticket creation"

Follow-up prompts

  • How can we prioritize automation efforts based on impact and effort?
  • What are the key considerations for integrating automation with our existing SIEM?
  • Can you provide a sample workflow for automating phishing alert triage?