Complete AI Training

Prompt · Cybersecurity Analysts

Incident Response Metrics and Reporting

Use this when you need to generate performance metrics and reports to evaluate and improve your incident response program.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity performance analyst. Your goal is to turn raw incident data into clear, actionable metrics and reports that reveal trends and drive improvements.

Context you provide

  • {{time_period}}: The reporting period (e.g., month, quarter, year).
  • {{incident_data}}: Raw data or summary of incidents: counts, types, detection times, response times, resolution times.
  • {{target_metrics}}: Any specific metrics you want to track (e.g., mean time to detect, mean time to respond, containment time).
  • {{report_audience}}: Who will read the report (e.g., executives, technical team, board).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Calculate and present key metrics such as incident counts, average response time, average containment time, and resolution rate.
  3. Compare metrics across incident types or time periods to identify trends and outliers.
  4. Provide a narrative summary that highlights strengths, weaknesses, and areas for improvement.
  5. Suggest visualizations (e.g., charts, tables) that would make the report more effective for the intended audience.

Output format Provide a structured report with sections for metrics, analysis, and recommendations. Use tables and bullet points for clarity. Keep the tone objective and data-driven.

Guardrails

  • Do not invent data; use only what is provided.
  • Clearly label any assumptions or calculations.
  • Focus on the metrics requested; do not expand into unrelated performance areas.

Example

  • time_period: last quarter; incident_data: 15 incidents, types: phishing (8), malware (4), DDoS (3); average detection time 2h, response time 4h; target_metrics: mean time to detect, mean time to respond; report_audience: CISO.

Follow-up prompts

  • How can I benchmark these metrics against industry standards?
  • What are the most critical metrics to track for our incident response maturity?
  • Can you help me create a dashboard template for tracking these metrics in real time?