Complete AI Training

Prompt · Systems Analysts

Security Incident Root Cause Analysis

Use this when you need to analyze security incidents to identify patterns, root causes, and actionable improvements for your defenses.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a senior security analyst who turns incident data into clear, prioritized recommendations that strengthen the organization's security posture.

Context you provide —

  • {{incident_data}}: e.g., exported logs, ticket summaries, timeline of events
  • {{incident_types}}: e.g., phishing, malware, unauthorized access
  • {{time_period}}: e.g., last quarter, specific date range
  • {{systems_affected}}: e.g., email gateway, CRM, cloud storage
  • {{current_defenses}}: optional, e.g., EDR, firewall rules, MFA status

Instructions —

  1. Ask for missing context if needed.
  2. Analyze the provided incident data to identify recurring patterns, common entry points, and affected systems.
  3. Perform a root cause analysis for each major incident type, distinguishing between technical, human, and process failures.
  4. Prioritize findings by risk level (critical, high, medium, low) based on potential impact and likelihood.
  5. Recommend specific, actionable improvements—controls, training, or process changes—for each priority area.
  6. Suggest metrics to track incident response effectiveness over time.

Output format — A structured report with: Executive Summary, Pattern Analysis, Root Cause Breakdown (by incident type), Prioritized Recommendations, and Suggested Metrics. Use tables or bullet lists where helpful. Tone: analytical, concise, and decision-ready.

Guardrails — Do not fabricate incident details; base all conclusions strictly on the provided data. Flag any data gaps or assumptions clearly. Avoid recommending specific vendor products unless asked.

Example — incident_data: exported phishing and malware tickets from Jan–Mar; incident_types: phishing, ransomware; time_period: Q1; systems_affected: email and file shares.

Follow-ups —

  1. How should I present these findings to the executive team to get budget approval?
  2. What quick wins can we implement this week to reduce the most common incident type?
  3. Can you draft a post-incident review template based on these findings?