Incident IDExtract the incident ID, ticket number, or referen...
Incident TitleExtract or generate a brief incident title...
Reporting OrganizationExtract the organization reporting the incident...
Report DateExtract the report date. Return in YYYY-MM-DD form...
Incident DateExtract the date the incident occurred. Return in ...
Discovery DateExtract the date the incident was discovered. Retu...
Containment DateExtract the date the incident was contained. Retur...
Incident TypeClassify incident type: Data Breach, Ransomware, P...
Attack VectorIdentify attack vector: Email/Phishing, Web Applic...
Threat ActorThreat actor type: External Attacker, Insider - Ma...
Severity LevelIncident severity: Critical (P1), High (P2), Mediu...
Data BreachDid the incident involve unauthorized access to or...
Data Types AffectedList data types affected: PII, PHI, Financial, Cre...
Records AffectedExtract the number of records or individuals affec...
Systems AffectedList systems, applications, or infrastructure affe...
Root CauseExtract the root cause analysis findings...
Root Cause CategoryClassify root cause: Human Error, Technical Vulner...
Vulnerabilities ExploitedList any CVEs or vulnerabilities exploited. Return...
Timeline of EventsExtract incident timeline as JSON array with keys:...
Immediate ActionsList immediate containment and response actions ta...
Notification RequiredWere regulatory notifications required? Yes or No...
Regulators NotifiedList regulators notified (ICO, HHS, State AG, etc....
Notification DateExtract the date regulators were notified. Return ...
Individuals NotifiedWere affected individuals notified? Yes or No...
Individual Notification DateExtract date individuals were notified. Return in ...
Law EnforcementWas law enforcement involved? Yes or No...
Business ImpactSummarize business impact (downtime, financial los...
Estimated CostExtract estimated incident cost if available. Retu...
Remediation ActionsList remediation and corrective actions taken or p...
Lessons LearnedExtract lessons learned and improvement recommenda...
StatusCurrent incident status: Open, Contained, Remediat...
Insurance ClaimWas a cyber insurance claim filed? Yes, No, Unknow...
Third Party InvolvementExtract any third-party/vendor involvement in the ...