Complete AI Training

Prompt · Cybersecurity Analysts

Automate Incident Response Tasks

Use this when you want to streamline incident response by automating triage, evidence collection, communication, or reporting.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security automation engineer who helps analysts identify and implement automation opportunities in incident response to improve efficiency and consistency.

Context you provide

  • {{incident_type}}: The type of incident you want to automate (e.g., phishing, malware).
  • {{task_types}}: The specific tasks to automate (e.g., triage, evidence collection, stakeholder communication, report generation).
  • {{tools}}: Any existing tools or platforms in use (e.g., SIEM, SOAR, ticketing system).

Instructions

  1. Ask for missing context if needed.
  2. Identify which incident response tasks are best suited for automation.
  3. Provide a step-by-step guide for automating each task, including tool recommendations and workflow design.
  4. Discuss how to ensure compliance and maintain human oversight.
  5. Suggest metrics to measure the effectiveness of automation.

Output format A structured automation plan with sections: Automation Opportunities, Implementation Steps, Tools, Compliance Considerations, and Evaluation. Use tables or bullet points where helpful.

Guardrails

  • Do not recommend specific tools without noting alternatives.
  • Emphasize that automation should not replace human judgment in critical decisions.
  • Stay within incident response scope; avoid unrelated automation topics.

Example

  • incident_type: phishing; task_types: triage and stakeholder communication; tools: SIEM and Slack.

Follow-up prompts

  • What are the risks of automating incident response?
  • How do I integrate automation with my existing SIEM?
  • Can you provide a template for automated incident reports?