Prompts/ IT Managers/ Incidents
IT Managers 25 prompts · Free

Free ChatGPT Prompts for IT Incident Report Writing - 25 Ready Templates for 2026

Get 25 free ChatGPT prompts for IT incident report writing. Copy, paste, fill variables, and generate professional incident reports in 30 seconds.

Best paired with Jasper AI for tone control or Copy.ai for fast iteration.

These prompts generate complete incident reports you can review, edit lightly, and submit. Each prompt takes 30 seconds to fill and produces a professional report that meets documentation standards.

These prompts pair well with Jasper AI for IT Managers-specific tone control, or Copy.ai for fast iteration.

Major System Outages

You are an IT manager documenting a critical system outage for executive review.

Incident: {incident_title} System affected: {system_name} Outage duration: {start_time} to {end_time} ({total_hours} hours) Users impacted: {number_of_users} Business impact: {revenue_loss_or_operational_impact} Root cause: {technical_root_cause} Resolution steps: {key_actions_taken} Responsible team: {team_name} Escalation level: {P1/P2/P3}

Write a 400-500 word executive incident report. Start with a one-sentence impact summary. Follow with timeline, root cause analysis, immediate actions taken, and prevention measures. Use bullet points for technical details. End with next steps and accountability.

When to use it: When your CEO asks for a written explanation of why the main system was down for hours.

Pro tip: Lead with business impact, not technical details. Executives care about customer and revenue impact first.


You are documenting a database corruption incident that caused data loss for compliance reporting.

Database: {database_name} Corruption discovered: {discovery_date_time} Data affected: {data_type_and_volume} Recovery method: {backup_restore_or_other} Data loss period: {from_date} to {to_date} Compliance implications: {regulatory_impact} Discovery method: {monitoring_alert_or_user_report} Recovery time: {hours_to_full_restoration} Preventive measures: {new_controls_implemented}

Write a 350-400 word incident report for compliance and audit teams. Include data integrity assessment, recovery procedures, and regulatory notification requirements. Use technical precision but accessible language.

When to use it: When you need to document data corruption for auditors or compliance officers who aren’t technical.

Pro tip: Quantify data loss precisely. Auditors need exact timeframes and affected record counts for their reports.


You are reporting a network security breach that triggered incident response protocols.

Breach type: {malware/phishing/unauthorized_access} Detection time: {timestamp} Affected systems: {system_list} Attack vector: {entry_point_description} Data accessed: {yes/no/unknown} - {data_types_if_applicable} Containment actions: {immediate_response_steps} External notifications: {customers/partners/authorities} Investigation status: {ongoing/complete} Threat eliminated: {yes/no/monitoring}

Write a 450-500 word security incident report for legal and executive review. Follow the SANS incident response framework. Include containment, eradication, and recovery phases. End with lessons learned and security improvements.

When to use it: When legal counsel needs a formal record of a security incident for potential regulatory filing.

Pro tip: Be precise about data access. “Unknown” is acceptable early on, but update the report as investigation progresses.


You are documenting a cloud service provider outage that affected multiple business units.

Cloud provider: {AWS/Azure/GCP/other} Service affected: {specific_service_name} Provider incident ID: {vendor_ticket_number} Internal applications impacted: {app_list} Business units affected: {department_list} Workaround implemented: {temporary_solution} Customer communication: {yes/no} - {communication_method} SLA breach: {yes/no} - {penalty_amount} Provider ETA: {estimated_resolution_time}

Write a 300-350 word incident report for business unit leaders. Focus on operational impact and recovery timeline. Include provider communication and any SLA implications. Use clear, non-technical language.

When to use it: When business leaders need to understand how a vendor outage affects their operations and timelines.

Pro tip: Reference the vendor’s public status page URL in your report. Business leaders often want to monitor directly.


You are reporting a critical patch deployment that failed and caused system instability.

Patch details: {patch_name_and_version} Target systems: {system_count_and_types} Deployment window: {scheduled_start} to {scheduled_end} Failure symptoms: {specific_issues_observed} Rollback decision: {time_of_rollback_decision} Rollback completion: {time_systems_restored} Testing gaps: {what_testing_missed_this_issue} Change approval: {CAB_reference_number} Vendor communication: {patch_vendor_response}

Write a 400-450 word post-incident report for the Change Advisory Board. Include timeline, decision points, and process improvements. Address testing procedures and change management lessons learned.

When to use it: When the Change Advisory Board needs to review why a routine patch deployment went wrong.

Pro tip: Include specific testing scenarios that would have caught this issue. The CAB will want to update procedures.

Security Incidents

You are documenting a successful phishing attack that compromised employee credentials.

Attack date: {incident_date} Employees targeted: {number_targeted} Employees compromised: {number_compromised} Email source: {external_domain_or_spoofed} Credentials harvested: {system_access_gained} Data accessed: {files_or_systems_viewed} Detection method: {user_report/monitoring_alert} Account securing: {password_reset/MFA_forced} User retraining: {mandatory/recommended} Email filtering: {new_rules_implemented}

Write a 350-400 word security incident report for HR and executive leadership. Include employee impact, immediate response, and awareness training recommendations. Balance security concerns with HR considerations.

When to use it: When HR needs to understand the human element of a security incident for employee communications.

Pro tip: Avoid naming specific employees in executive reports. Focus on patterns and systematic improvements.


You are reporting unauthorized access to sensitive financial data by a terminated employee.

Former employee: {job_title_not_name} Termination date: {last_work_day} Access discovered: {discovery_date_time} Systems accessed: {specific_applications} Data viewed: {file_types_and_quantities} Access method: {VPN/shared_account/other} Account status: {should_have_been_disabled} Legal notification: {yes/no} - {legal_team_contact} HR process gap: {offboarding_step_missed} Immediate remediation: {accounts_disabled_systems_secured}

Write a 400-450 word incident report for legal and HR leadership. Include timeline, data exposure assessment, and process failures. Recommend offboarding procedure improvements without assigning blame.

When to use it: When legal counsel needs documentation of unauthorized access by former employees for potential legal action.

Pro tip: Document the intended offboarding process versus what actually happened. Legal teams need this gap analysis.


You are documenting a malware infection that spread through the network before containment.

Malware type: {ransomware/trojan/worm} Initial infection: {patient_zero_system} Infection method: {email_attachment/USB/download} Spread timeline: {time_from_infection_to_detection} Systems affected: {total_count_by_department} Data encrypted: {yes/no} - {recovery_method} Network segmentation: {effective/bypassed} Antivirus detection: {blocked/failed/delayed} Recovery time: {hours_to_full_operations} Ransom demand: {amount_or_none}

Write a 450-500 word incident report for insurance claims and executive review. Include financial impact, recovery costs, and security control effectiveness. Provide specific recommendations for prevention.

When to use it: When insurance companies request detailed documentation of malware incidents for claims processing.

Pro tip: Document all costs including overtime, consultant fees, and business interruption. Insurance needs comprehensive financial impact.


You are reporting a social engineering attack that bypassed technical controls through help desk manipulation.

Attack vector: {phone_call/email/in_person} Target: {help_desk/specific_employee} Information sought: {passwords/access/data} Social engineering tactics: {authority/urgency/familiarity} Information disclosed: {what_attacker_learned} Verification process: {followed/bypassed} Escalation occurred: {yes/no} Training compliance: {target_training_status} Policy violation: {specific_procedure_not_followed} Immediate response: {accounts_secured_notifications_sent}

Write a 350-400 word incident report for security awareness training and policy review. Focus on human factors and process improvements rather than individual blame. Include training recommendations.

When to use it: When the security team needs to document social engineering for awareness training and policy updates.

Pro tip: Include exact phrases the attacker used. This helps train staff to recognize similar future attempts.


You are documenting a vendor security breach that exposed customer data processed by your organization.

Vendor: {vendor_name} Service provided: {vendor_function} Breach notification received: {date_time} Customer data involved: {data_types_and_volume} Your customers affected: {number_impacted} Vendor incident reference: {vendor_case_number} Regulatory notification required: {yes/no} - {which_regulations} Customer communication: {timeline_and_method} Contract review: {SLA_penalties_applicable} Alternative vendors: {backup_options_activated}

Write a 400-450 word incident report for legal and customer success teams. Include regulatory obligations, customer communication strategy, and vendor management lessons. Focus on customer impact and trust preservation.

When to use it: When customer-facing teams need to understand and respond to vendor-caused data exposure.

Pro tip: Reference specific contract clauses about security breaches and notification requirements. Legal needs this for vendor discussions.

Performance and Capacity Issues

You are documenting a gradual performance degradation that culminated in user complaints and system slowdown.

System: {application_or_service_name} Performance issue detected: {first_noticed_date} User complaints started: {complaint_timeline} Performance metrics: {response_time_degradation} Peak usage period: {time_of_worst_performance} Root cause identified: {database/network/application_issue} Monitoring gaps: {metrics_not_captured} Temporary mitigation: {immediate_fix_applied} Capacity planning: {resource_scaling_needed} User impact: {number_affected_and_business_functions}

Write a 350-400 word performance incident report for capacity planning and user experience teams. Include trending data, user impact assessment, and infrastructure scaling recommendations.

When to use it: When you need to justify infrastructure spending after performance issues affected user productivity.

Pro tip: Include specific user workflow impacts, not just technical metrics. Business leaders understand lost productivity better than response times.


You are reporting a storage capacity crisis that nearly caused data writes to fail.

Storage system: {SAN/NAS/cloud_storage} Capacity reached: {percentage_full} Growth rate: {GB_per_day_recent_trend} Critical threshold: {percentage_triggering_alerts} Business risk: {applications_at_risk} Emergency expansion: {temporary_solution_implemented} Data archival: {old_data_moved_or_deleted} Monitoring effectiveness: {alert_timing} Procurement timeline: {permanent_solution_ETA} Cost impact: {emergency_procurement_costs}

Write a 300-350 word capacity incident report for finance and operations leadership. Focus on business continuity risk and cost implications of emergency procurement versus planned expansion.

When to use it: When finance needs to understand why you’re requesting emergency budget approval for storage expansion.

Pro tip: Compare emergency procurement costs to planned expansion costs. Finance teams need this ROI analysis for future planning.


You are documenting a memory leak that caused application crashes during peak business hours.

Application: {application_name} Crash pattern: {frequency_and_timing} Memory consumption: {baseline_vs_peak_usage} User sessions affected: {concurrent_users_impacted} Business transactions lost: {failed_processes_or_orders} Detection method: {monitoring_alert_or_user_report} Temporary fix: {application_restart_frequency} Development team: {vendor_or_internal} Code review initiated: {yes/no} Permanent fix ETA: {development_timeline}

Write a 400-450 word application incident report for development and business operations teams. Include user experience impact, business process disruption, and development priority recommendations.

When to use it: When business operations needs to understand how application instability affects their daily workflows.

Pro tip: Quantify lost transactions or incomplete processes. Operations teams need this to assess downstream business impact.


You are reporting a network bandwidth saturation that slowed critical business applications.

Network segment: {WAN_link_or_LAN_segment} Bandwidth utilization: {percentage_at_peak} Traffic source: {video_calls/file_transfers/backup} Applications affected: {business_critical_systems} Time period: {duration_of_saturation} QoS effectiveness: {traffic_prioritization_results} Temporary mitigation: {traffic_limiting_or_scheduling} Bandwidth upgrade: {additional_capacity_needed} Cost analysis: {upgrade_cost_vs_productivity_loss} Traffic trending: {growth_projections}

Write a 350-400 word network capacity report for infrastructure and finance teams. Include productivity impact analysis and bandwidth expansion business case.

When to use it: When you need executive approval for network bandwidth upgrades based on performance impact.

Pro tip: Document which business applications were prioritized during saturation. This shows your QoS strategy effectiveness.


You are documenting a database performance issue that caused application timeouts and user frustration.

Database: {database_name_and_type} Performance symptoms: {slow_queries/timeouts/locks} Query response time: {baseline_vs_degraded_performance} Peak usage correlation: {timing_with_business_activity} Index optimization: {missing_or_fragmented_indexes} Hardware utilization: {CPU/memory/disk_bottlenecks} Application impact: {user_facing_symptoms} DBA analysis: {technical_root_cause} Immediate tuning: {quick_fixes_applied} Long-term solution: {hardware_or_architecture_changes}

Write a 400-450 word database performance report for application and infrastructure teams. Include business impact, technical analysis, and resource planning recommendations.

When to use it: When application teams need to understand why their software suddenly became unresponsive.

Pro tip: Correlate database slowdowns with specific business processes. This helps prioritize which optimization efforts matter most.

Data and Backup Failures

You are documenting a backup failure that was discovered during a recovery test.

Backup system: {backup_solution_name} Failed backup dates: {date_range_of_failures} Data affected: {systems