Turn incident lessons into tracked improvements
Have an AI agent read case records and propose updates to your incident response plan. Turn concrete fixes from incidents and exercises into tickets with owners.
Tools for improvement
MCP servers for the tools used in these examples.
Automation examples and starter prompts
Paste a prompt into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP. Adapt it to your tools and test before deployment. Human tool approvals and advanced case features require Enterprise.
Turn case retros into tracked improvements
Build me a case-triggered workflow in Tracecat that runs when a significant case closes. Have an AI agent read the case timeline and comments, extract what slowed the response down and what information was missing, and open a Linear improvement issue for each concrete fix. Post a weekly digest of open improvements and their age to the team channel. First help me understand how this maps to ID.IM-03 and why improvements from daily operations beat annual lessons-learned documents. Ask me which case types deserve a retro. Talk me through keeping the improvement backlog from becoming a graveyard.
Keep the incident response plan current
Build me a quarterly workflow in Tracecat that checks our incident response plan against reality. Have an AI agent read the plan in Notion, compare its steps and contacts against how our last quarter of incidents actually ran in Incident.io, and draft proposed updates: steps nobody follows, contacts who left, and paths real incidents took that the plan never mentions. First help me understand how this maps to ID.IM-04 and what makes response plans drift from practice. Ask me where the plan lives and who owns it. Talk me through whether the agent should propose edits directly or assemble evidence for a human review session.
Mine test and exercise results for fixes
Build me an automation in Tracecat that turns security test results into tracked work. Import findings from pentest reports, purple team exercises, and tabletop notes, dedupe them against known gaps, and open a Jira ticket per new finding with the exercise context attached. Track closure and flag findings that resurface across exercises. First help me understand how this maps to ID.IM-02 and why repeat findings are the signal worth escalating. Ask me what format our test results arrive in. Talk me through involving suppliers when an exercise exposes a gap on their side.
NIST CSF 2.0 mapping: ID.IM
Official NIST category: Improvement. Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
The controls and implementation examples below are NIST source material. The automation prompts above are Tracecat-authored starting points, not evidence of compliance or full control coverage.
- ID.IM-01AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2IA-1IR-1IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-8SA-11SA-17(6)SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from evaluations
- Perform self-assessments of critical services that take current threats and TTPs into consideration
- Invest in third-party assessments or independent audits of the effectiveness of the organization's cybersecurity program to identify areas that need improvement
- Constantly evaluate compliance with selected cybersecurity requirements through automated means
- ID.IM-02AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2CP-4IA-1IR-1IR-3IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PM-4PM-31PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-8SA-11SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- Identify improvements for future incident response activities based on findings from incident response assessments (e.g., tabletop exercises and simulations, tests, internal reviews, independent audits)
- Identify improvements for future business continuity, disaster recovery, and incident response activities based on exercises performed in coordination with critical service providers and product suppliers
- Involve internal stakeholders (e.g., senior executives, legal department, HR) in security tests and exercises as appropriate
- Perform penetration testing to identify opportunities to improve the security posture of selected high-risk systems as approved by leadership
- Exercise contingency plans for responding to and recovering from the discovery that products or services did not originate with the contracted supplier or partner or were altered before receipt
- Collect and analyze performance metrics using security tools and services to inform improvements to the cybersecurity program
- ID.IM-03AC-1AT-1AU-1CA-1CA-2CA-5CA-7CA-8CM-1CP-1CP-2IA-1IR-1IR-4IR-8MA-1MP-1PE-1PL-1PL-2PM-1PM-4PM-31PS-1PT-1RA-1RA-3RA-5RA-7SA-1SA-4SA-8SA-11SC-1SI-1SI-2SI-4SR-1SR-5
Improvements are identified from execution of operational processes, procedures, and activities
- Conduct collaborative lessons learned sessions with suppliers
- Annually review cybersecurity policies, processes, and procedures to take lessons learned into account
- Use metrics to assess operational cybersecurity performance over time
- ID.IM-04CP-2IR-8PL-2SR-2
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
- Establish contingency plans (e.g., incident response, business continuity, disaster recovery) for responding to and recovering from adverse events that can interfere with operations, expose confidential information, or otherwise endanger the organization's mission and viability
- Include contact and communication information, processes for handling common scenarios, and criteria for prioritization, escalation, and elevation in all contingency plans
- Create a vulnerability management plan to identify and assess all types of vulnerabilities and to prioritize, test, and implement risk responses
- Communicate cybersecurity plans (including updates) to those responsible for carrying them out and to affected parties
- Review and update all cybersecurity plans annually or when a need for significant improvements is identified
Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.
Build your own security automation
Adapt a starter prompt with your coding assistant, choose where AI agents or fixed workflows fit, and test with your tools.