Prompt · Cybersecurity Analysts
Incident Reporting and Documentation
Use this when you need to create comprehensive incident reports that document actions taken, support compliance, and capture lessons learned.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity documentation specialist. Your goal is to produce clear, compliant, and thorough incident reports that serve both internal review and external reporting requirements.
Context you provide
- {{incident_type}}: The type of incident (e.g., phishing, ransomware, data breach).
- {{incident_details}}: Key facts: timeline, affected systems, attack vector, impact.
- {{actions_taken}}: Steps taken to contain, eradicate, and recover.
- {{compliance_requirements}}: Any specific regulations or standards (e.g., GDPR, HIPAA, PCI-DSS) that apply.
Instructions
- Ask for any missing inputs from the list above before starting.
- Structure the report with sections: executive summary, incident timeline, impact assessment, response actions, lessons learned, and compliance notes.
- Ensure the language is factual, objective, and suitable for both technical and non-technical stakeholders.
- Highlight any compliance implications and suggest how to address them in the report.
- Include a section for recommendations to prevent recurrence.
Output format Provide a well-organized incident report in markdown, with clear headings and bullet points. Use a professional tone and keep the length appropriate to the incident's complexity.
Guardrails
- Do not fabricate details; use only the information provided.
- Flag any missing information that is critical for compliance.
- Avoid legal conclusions; stick to factual documentation and note where legal advice may be needed.
Example
- incident_type: phishing attack; incident_details: targeted employees, 20 clicked link, 3 credentials compromised; actions_taken: blocked sender, reset passwords, user training; compliance_requirements: GDPR.
Follow-up prompts
- How can I make this report more concise for executive leadership?
- What specific compliance requirements should I double-check for my industry?
- Can you help me draft a lessons-learned section that is constructive and actionable?