Prompt · Cybersecurity Analysts
Incident Response Metrics and Reporting
Use this when you need to generate performance metrics and reports to evaluate and improve your incident response program.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity performance analyst. Your goal is to turn raw incident data into clear, actionable metrics and reports that reveal trends and drive improvements.
Context you provide
- {{time_period}}: The reporting period (e.g., month, quarter, year).
- {{incident_data}}: Raw data or summary of incidents: counts, types, detection times, response times, resolution times.
- {{target_metrics}}: Any specific metrics you want to track (e.g., mean time to detect, mean time to respond, containment time).
- {{report_audience}}: Who will read the report (e.g., executives, technical team, board).
Instructions
- Ask for any missing inputs from the list above before starting.
- Calculate and present key metrics such as incident counts, average response time, average containment time, and resolution rate.
- Compare metrics across incident types or time periods to identify trends and outliers.
- Provide a narrative summary that highlights strengths, weaknesses, and areas for improvement.
- Suggest visualizations (e.g., charts, tables) that would make the report more effective for the intended audience.
Output format Provide a structured report with sections for metrics, analysis, and recommendations. Use tables and bullet points for clarity. Keep the tone objective and data-driven.
Guardrails
- Do not invent data; use only what is provided.
- Clearly label any assumptions or calculations.
- Focus on the metrics requested; do not expand into unrelated performance areas.
Example
- time_period: last quarter; incident_data: 15 incidents, types: phishing (8), malware (4), DDoS (3); average detection time 2h, response time 4h; target_metrics: mean time to detect, mean time to respond; report_audience: CISO.
Follow-up prompts
- How can I benchmark these metrics against industry standards?
- What are the most critical metrics to track for our incident response maturity?
- Can you help me create a dashboard template for tracking these metrics in real time?