Tracecat
Book a demo
Respond
RS.CO

Coordinate incident notifications and reports

Draft regulator and customer notices from confirmed case facts, notify stakeholders by severity, and prepare indicators for sharing. Keep external drafts with the people authorized to approve them.

Tools for incident response reporting and communication

MCP servers for the tools used in these examples.

Automation examples and starter prompts

Paste a prompt into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP. Adapt it to your tools and test before deployment. Human tool approvals and advanced case features require Enterprise.

Notify stakeholders when incidents declare

Build me a notification automation in Tracecat. When an incident is declared, notify by a severity matrix: the response channel always, engineering leads at high severity, and executives at critical. Send through Slack and Teams, page named roles through PagerDuty, track who acknowledged, and re-ping non-responders on a timer. First help me understand how this maps to RS.CO-02 and why notification matrices should be agreed before incidents, not improvised during them. Ask me who must know at each severity, including any external parties with contractual notice rights. Talk me through keeping the matrix current as people change roles.

Draft regulator and customer notices

Build me a notification drafting workflow in Tracecat. When an incident is flagged as reportable, start the regulatory clock, and have an AI agent draft the notices from confirmed case facts only: regulator format from our Notion templates, plus the customer version in plain language. Hold every draft for legal approval in the case before anything sends through Gmail. First help me understand how this maps to RS.CO-02 and which notification deadlines apply to us, like the common 72-hour windows. Ask me which regulations and contracts create notice obligations for us. Talk me through how the agent should mark unconfirmed facts so drafts never overstate what we know.

Share indicators with trusted partners

Build me an intel sharing workflow in Tracecat. When an incident closes, have an AI agent extract the shareable indicators, strip anything that identifies us or our customers, format the package for our sharing community, and hold it for my approval before posting. Log what was shared, with whom, and under what marking. First help me understand how this maps to RS.CO-03 and how traffic light protocol markings govern what we can share. Ask me which sharing communities we belong to. Talk me through the sanitization rules the agent must never violate.

NIST CSF 2.0 mapping: RS.CO

Official NIST category: Incident Response Reporting and Communication. Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies

The controls and implementation examples below are NIST source material. The automation prompts above are Tracecat-authored starting points, not evidence of compliance or full control coverage.

  • RS.CO-02
    IR-4
    IR-6
    IR-7
    SR-3
    SR-8

    Internal and external stakeholders are notified of incidents

  • RS.CO-03
    IR-4
    IR-6
    IR-7
    SR-3
    SR-8

    Information is shared with designated internal and external stakeholders

Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.

Build your own security automation

Adapt a starter prompt with your coding assistant, choose where AI agents or fixed workflows fit, and test with your tools.