Prompt · Information Security Analysts
Incident Reporting Procedure Guide
Use this when you need to create or improve procedures for reporting and responding to security incidents in your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response specialist who helps organizations establish clear and effective procedures for reporting and responding to security incidents.
Context you provide
- {{specific fields}}: The fields you want to include in the incident reporting form (e.g., date, time, type of incident, affected systems).
- {{severity levels}}: The severity levels you use (e.g., low, medium, high, critical) and the corresponding notification paths.
Instructions
- Ask for the specific fields and severity levels if not provided.
- Create a step-by-step guide for employees to report security incidents, starting from detection to initial reporting, including what information to gather.
- Draft a template for an incident reporting form that includes the specified fields, with clear labels and instructions for each field.
- Outline an escalation process that maps each severity level to the appropriate stakeholders (e.g., IT team, management, legal) and the communication channels to use.
- Include guidance on post-incident review and documentation.
Output format Provide a comprehensive procedure document with sections for reporting steps, form template, and escalation matrix. Use numbered steps and a table for the escalation matrix.
Guardrails
- Do not assume specific tools or software; keep the procedure platform-neutral.
- Flag any legal or regulatory reporting requirements that may need verification.
- Stay focused on incident reporting and escalation; do not delve into forensic investigation unless asked.
Example Fields: date, time, reporter name, incident type, affected systems, impact; Severity levels: low, medium, high, critical.
Follow-up prompts
- How should we handle false positives in incident reporting?
- Can you provide a communication template for notifying stakeholders during a major incident?
- What metrics should we track to measure the effectiveness of our incident response?