Coordinate incident notifications and reports
Draft regulator and customer notices from confirmed case facts, notify stakeholders by severity, and prepare indicators for sharing. Keep external drafts with the people authorized to approve them.
Tools for incident response reporting and communication
MCP servers for the tools used in these examples.
Automation examples and starter prompts
Paste a prompt into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP. Adapt it to your tools and test before deployment. Human tool approvals and advanced case features require Enterprise.
Notify stakeholders when incidents declare
Build me a notification automation in Tracecat. When an incident is declared, notify by a severity matrix: the response channel always, engineering leads at high severity, and executives at critical. Send through Slack and Teams, page named roles through PagerDuty, track who acknowledged, and re-ping non-responders on a timer. First help me understand how this maps to RS.CO-02 and why notification matrices should be agreed before incidents, not improvised during them. Ask me who must know at each severity, including any external parties with contractual notice rights. Talk me through keeping the matrix current as people change roles.
Draft regulator and customer notices
Build me a notification drafting workflow in Tracecat. When an incident is flagged as reportable, start the regulatory clock, and have an AI agent draft the notices from confirmed case facts only: regulator format from our Notion templates, plus the customer version in plain language. Hold every draft for legal approval in the case before anything sends through Gmail. First help me understand how this maps to RS.CO-02 and which notification deadlines apply to us, like the common 72-hour windows. Ask me which regulations and contracts create notice obligations for us. Talk me through how the agent should mark unconfirmed facts so drafts never overstate what we know.
NIST CSF 2.0 mapping: RS.CO
Official NIST category: Incident Response Reporting and Communication. Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
The controls and implementation examples below are NIST source material. The automation prompts above are Tracecat-authored starting points, not evidence of compliance or full control coverage.
- RS.CO-02IR-4IR-6IR-7SR-3SR-8
Internal and external stakeholders are notified of incidents
- Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers
- Notify business partners and customers of incidents in accordance with contractual requirements
- Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval
- RS.CO-03IR-4IR-6IR-7SR-3SR-8
Information is shared with designated internal and external stakeholders
- Securely share information consistent with response plans and information sharing agreements
- Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC)
- Notify HR when malicious insider activity occurs
- Regularly update senior leadership on the status of major incidents
- Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
- Coordinate crisis communication methods between the organization and its critical suppliers
Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.
Build your own security automation
Adapt a starter prompt with your coding assistant, choose where AI agents or fixed workflows fit, and test with your tools.