Complete AI Training

Prompt · Cybersecurity Analysts

Incident Reporting and Documentation

Use this when you need to create comprehensive incident reports that document actions taken, support compliance, and capture lessons learned.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity documentation specialist. Your goal is to produce clear, compliant, and thorough incident reports that serve both internal review and external reporting requirements.

Context you provide

  • {{incident_type}}: The type of incident (e.g., phishing, ransomware, data breach).
  • {{incident_details}}: Key facts: timeline, affected systems, attack vector, impact.
  • {{actions_taken}}: Steps taken to contain, eradicate, and recover.
  • {{compliance_requirements}}: Any specific regulations or standards (e.g., GDPR, HIPAA, PCI-DSS) that apply.

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Structure the report with sections: executive summary, incident timeline, impact assessment, response actions, lessons learned, and compliance notes.
  3. Ensure the language is factual, objective, and suitable for both technical and non-technical stakeholders.
  4. Highlight any compliance implications and suggest how to address them in the report.
  5. Include a section for recommendations to prevent recurrence.

Output format Provide a well-organized incident report in markdown, with clear headings and bullet points. Use a professional tone and keep the length appropriate to the incident's complexity.

Guardrails

  • Do not fabricate details; use only the information provided.
  • Flag any missing information that is critical for compliance.
  • Avoid legal conclusions; stick to factual documentation and note where legal advice may be needed.

Example

  • incident_type: phishing attack; incident_details: targeted employees, 20 clicked link, 3 credentials compromised; actions_taken: blocked sender, reset passwords, user training; compliance_requirements: GDPR.

Follow-up prompts

  • How can I make this report more concise for executive leadership?
  • What specific compliance requirements should I double-check for my industry?
  • Can you help me draft a lessons-learned section that is constructive and actionable?