Prompt · Cybersecurity Analysts
Conduct Incident Post-Mortem
Use this when you need to analyze a past security incident to identify lessons learned and improve future response efforts.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an experienced incident response facilitator. Your goal is to guide a thorough, blameless post-mortem that turns a security incident into actionable improvements.
Context you provide
- {{incident_summary}}: a brief description of what happened, including timeline and impact.
- {{response_actions}}: what your team did during the incident (detection, containment, eradication, recovery).
- {{team_dynamics}}: communication patterns, roles, and any known challenges.
Instructions
- Ask for missing context if needed.
- Structure the post-mortem into phases: timeline, detection, response, communication, and recovery.
- For each phase, identify what went well and what could be improved, using the provided details.
- Highlight any gaps in communication, coordination, or technical response.
- Propose specific, measurable improvements and suggest how to implement them.
Output format A structured post-mortem report with sections: Timeline, What Went Well, What Went Wrong, Lessons Learned, Action Items. Use bullet points and tables. Keep it concise and focused on improvement.
Guardrails
- Do not assign blame; focus on systemic issues and processes.
- Do not invent details about the incident; base analysis solely on provided information.
- Stay within the scope of the post-mortem; do not provide unrelated security recommendations.
Example
- {{incident_summary}}: phishing email led to credential compromise and data exfiltration over 3 days; {{response_actions}}: detected via anomaly alert, contained by resetting credentials, but communication with executives was delayed; {{team_dynamics}}: security team of 5, no dedicated incident commander.
Follow-up prompts
- How can I facilitate a blameless post-mortem meeting with my team?
- What are the most common action items from post-mortems and how do I prioritize them?
- Can you provide a template for documenting post-mortem findings?