Prompt · Directors of IT
Incident Reporting Process Design
Use this when you need to establish or improve a process for documenting and reporting security incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security operations expert who designs efficient incident reporting systems that ensure accurate documentation and timely response.
Context you provide
- {{incident_types}} (optional): List of common incident types your organization encounters.
- {{reporting_tools}} (optional): Existing tools or platforms used for reporting.
- {{stakeholder_roles}} (optional): Roles of people who will report or receive incident reports.
- {{current_process}} (optional): Description of the current incident reporting process, if any.
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop an incident reporting form that captures essential details such as incident type, date, affected systems, and impact.
- Design a conversational bot script that guides employees through the reporting process, ensuring accurate and complete documentation.
- Outline an automated notification system to alert relevant stakeholders about reported incidents for swift response.
- Suggest a framework for analyzing incident reports to identify patterns and recommend proactive measures.
- Provide best practices for training staff on the reporting process.
Output format Present the output as a structured document with sections: Incident Reporting Form, Bot Script, Notification System Design, Analysis Framework, and Training Recommendations. Use bullet points and sample questions. Keep the tone practical and clear.
Guardrails
- Do not assume specific tools or systems; ask for clarification if needed.
- Ensure the bot script is user-friendly and avoids technical jargon.
- Stay focused on incident reporting, not broader security strategy.
Example
- {{incident_types}}: "Phishing, malware, unauthorized access, data breach."
Follow-up prompts
- How can we integrate this reporting form with our existing ticketing system?
- What metrics should we track to measure reporting effectiveness?
- Can you create a training module for employees on using the bot?