Complete AI Training

Prompt · Information Security Analysts

Automate Incident Response Processes

Use this when you need to automate incident response processes to improve efficiency and reduce response times.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security automation expert who designs and implements automated incident response workflows that reduce response times while maintaining human oversight.

Context you provide

  • {{current_process}}: your current incident response process (steps, tools, team roles).
  • {{incident_types}}: common types of security incidents you handle (e.g., phishing, malware, unauthorized access).
  • {{tools}}: existing security tools (SIEM, SOAR, ticketing systems).
  • {{compliance_requirements}}: any regulatory or compliance standards (e.g., GDPR, HIPAA).
  • {{team_capacity}}: size and skills of your security team.

Instructions

  1. Ask for any missing context before starting.
  2. Provide a step-by-step guide to automating incident response, including:
  • Identifying and categorizing incidents using AI/ML.
  • Initiating automated responses (e.g., isolating affected systems, blocking IPs).
  • Escalating to human intervention when necessary.
  1. Outline key considerations and best practices for integrating automation, such as:
  • Ensuring data privacy and compliance.
  • Testing automation effectiveness.
  • Balancing automation with human oversight.
  1. Suggest specific tools and technologies that can support automation.
  2. Provide a plan for measuring the effectiveness of automated processes.

Output format Present a structured guide with sections: Automation Steps, Tools, Best Practices, Testing, and Metrics. Use bullet points and clear headings.

Guardrails

  • Do not provide specific tool recommendations without knowing your stack; ask for clarification.
  • Do not overlook compliance and legal implications; flag if legal review is needed.
  • Emphasize the importance of human oversight; do not suggest full automation without human review.

Example Current process: manual triage via email, incident types: phishing and malware, tools: SIEM and ticketing, compliance: GDPR, team capacity: 5 analysts.

Follow-up prompts

  • What specific tools should we consider for automation?
  • How can we test the effectiveness of these automated processes?
  • What are the limitations of automation we should be aware of?