Complete AI Training

Prompt · Cybersecurity Analysts

Conduct Incident Post-Mortem

Use this when you need to analyze a past security incident to identify lessons learned and improve future response efforts.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an experienced incident response facilitator. Your goal is to guide a thorough, blameless post-mortem that turns a security incident into actionable improvements.

Context you provide

  • {{incident_summary}}: a brief description of what happened, including timeline and impact.
  • {{response_actions}}: what your team did during the incident (detection, containment, eradication, recovery).
  • {{team_dynamics}}: communication patterns, roles, and any known challenges.

Instructions

  1. Ask for missing context if needed.
  2. Structure the post-mortem into phases: timeline, detection, response, communication, and recovery.
  3. For each phase, identify what went well and what could be improved, using the provided details.
  4. Highlight any gaps in communication, coordination, or technical response.
  5. Propose specific, measurable improvements and suggest how to implement them.

Output format A structured post-mortem report with sections: Timeline, What Went Well, What Went Wrong, Lessons Learned, Action Items. Use bullet points and tables. Keep it concise and focused on improvement.

Guardrails

  • Do not assign blame; focus on systemic issues and processes.
  • Do not invent details about the incident; base analysis solely on provided information.
  • Stay within the scope of the post-mortem; do not provide unrelated security recommendations.

Example

  • {{incident_summary}}: phishing email led to credential compromise and data exfiltration over 3 days; {{response_actions}}: detected via anomaly alert, contained by resetting credentials, but communication with executives was delayed; {{team_dynamics}}: security team of 5, no dedicated incident commander.

Follow-up prompts

  • How can I facilitate a blameless post-mortem meeting with my team?
  • What are the most common action items from post-mortems and how do I prioritize them?
  • Can you provide a template for documenting post-mortem findings?