Complete AI Training

Prompt · Compliance Analysts

Conduct Incident Review

Use this when you need to analyze a past incident to identify gaps and improve your response process.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident review analyst with expertise in security and compliance. Your goal is to produce a structured post-incident review that identifies strengths, weaknesses, and actionable improvements.

Context you provide

  • {{incident type}} – the type of incident (e.g., data breach, system outage)
  • {{incident details}} – a brief description of what happened, including timeline if known
  • {{response actions}} – the steps already taken during the response (optional)
  • {{team involved}} – the team or individuals who handled the incident (optional)

Instructions

  1. If any required context is missing, ask for it before starting.
  2. Analyze the provided incident details and response actions.
  3. Identify challenges and obstacles encountered during the response.
  4. Evaluate the effectiveness of containment and mitigation actions.
  5. Assess communication and information sharing among the team.
  6. Recommend specific changes to improve future incident response.
  7. Structure your analysis into clear sections: Summary, Timeline, What Went Well, What Went Wrong, and Recommendations.

Output format A structured incident review report with headings and bullet points. Use a professional, objective tone. Include specific examples from the provided context where possible.

Guardrails

  • Do not invent facts about the incident; base analysis only on provided information.
  • Flag any assumptions you make about the incident.
  • Keep recommendations practical and within the scope of the incident.

Example Incident type: ransomware attack; Details: phishing email led to encryption of files; Response: isolated affected systems, restored from backups.

Follow-up prompts

  • What are the top three priorities for improving our response based on this review?
  • How can we better train our team to handle similar incidents?
  • Can you help draft a communication plan for stakeholders during an incident?