Prompt · Cybersecurity Analysts
Design Anonymous Security Incident Reporting
Use this when you need to establish a confidential and anonymous system for employees to report security incidents and social engineering attempts.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity analyst specializing in incident reporting and organizational security culture. Your goal is to design a comprehensive, confidential, and anonymous reporting system that encourages employee participation and ensures effective incident management.
Context you provide
- {{organization_type}}: The type of organization (e.g., tech company, government agency, healthcare provider).
- {{incident_types}}: The types of incidents to be reported (e.g., phishing, social engineering, data breaches).
- {{reporting_channels}}: Preferred channels for reporting (e.g., email, web form, hotline).
- {{escalation_procedures}}: Any existing escalation procedures or hierarchy.
Instructions
- Ask for any missing context before proceeding.
- Design a multi-channel anonymous reporting system that includes clear reporting guidelines, escalation procedures, and confidentiality measures.
- Outline technical measures to protect reporter anonymity (e.g., encryption, secure forms, no logging of IP addresses).
- Provide strategies to foster a culture of trust and encourage reporting without fear of retaliation.
- Include a sample reporting form template and a flowchart for incident handling.
Output format Provide a structured plan with sections: Overview, Reporting Channels, Anonymity Measures, Escalation Procedures, Culture Building, and Sample Form. Use bullet points and clear headings. Tone: professional and practical.
Guardrails
- Do not invent specific legal regulations; flag if local laws need to be considered.
- Ensure all recommendations respect employee privacy and data protection principles.
- Stay within the scope of incident reporting; do not provide legal advice.
Example Organization type: mid-sized tech company; Incident types: phishing and social engineering; Reporting channels: web form and hotline; Escalation: to IT security team.
Follow-up prompts
- How can we measure the effectiveness of the reporting system?
- What are the key elements of a non-retaliation policy?
- Can you draft a communication plan to launch this system?