Agent Foskett Academy • Microsoft Security Copilot • Module 2 • Lesson 20

Lesson 20 — AI-Assisted Triage Workflows

Executives do not need every alert, query and event from a security investigation.

They need a clear account of what happened, what was affected, what has been done, what risk remains and what decision is required.

This lesson explains how Security Copilot can help translate validated technical evidence into concise business-facing summaries without introducing speculation, exaggerating impact or hiding uncertainty.

Good triage isn't about finding more alerts. It's about finding the few that actually matter.
Agent Foskett AI-Assisted Triage Workflows lesson
What you will learn

This lesson turns technical evidence into clear, accurate and decision-focused executive communication.

✓ Business impact and current status
✓ Completed actions and remaining risk
✓ Confidence, uncertainty and decisions
✓ Board, customer and leadership summaries

Executive-summary workflow

Start with the human-validated technical investigation

Confirm scope, timeline, impact and response status

Define the executive audience and purpose

Ask Security Copilot for a concise business-facing draft

Review every fact, number, date and impact statement

Remove unsupported technical and business claims

State confidence, uncertainty and remaining risk

Identify the decision or approval required

Complete technical, business, legal and communications review

Approve the final executive summary

Executive-summary domains

DomainContentExecutive question
Incident storyWhat happened and how far it progressed.What does leadership need to understand?
ScopeConfirmed users, devices, services, data and business units.How large is the incident?
ImpactOperational, customer, data, financial and regulatory effect.What business harm occurred?
ResponseContainment, remediation, recovery and monitoring.What has been done?
Remaining riskUnresolved exposure, uncertainty and residual control gaps.What still concerns us?
DecisionApproval, escalation, communication or risk acceptance.What does leadership need to decide?

Learning objectives

  • Translate technical findings into business language.
  • Describe scope, impact and current status.
  • Explain completed actions and remaining risk.
  • State confidence and uncertainty.
  • Write for boards, executives and customers.
  • Validate AI-generated summaries.
  • Support clear leadership decisions.

What is an executive incident summary?

An executive incident summary is a concise business-facing account of what happened, what was affected, what has been done and what decisions remain.

Executive is not technical

Executives need enough technical context to understand the incident without reading every alert, query or event.

Start with the audience

A CEO, board member, customer, regulator and operational manager may need different emphasis.

Define the purpose

Clarify whether the summary supports awareness, approval, customer communication, legal review or incident governance.

Lead with the answer

State whether compromise is confirmed, suspected, contained or still under investigation.

Use plain language

Translate technical findings into understandable business terms without losing accuracy.

Avoid unnecessary jargon

Explain specialised terms only when they materially affect the decision.

Keep the attack story short

Summarise the incident in a few clear stages rather than reproducing the full timeline.

Describe what happened

Explain the incident type, initial access path and verified progression.

Describe who was affected

Identify users, teams, customers, suppliers or business units in scope.

Describe what was affected

Identify devices, applications, cloud resources, mailboxes, services and data.

Describe business impact

Explain operational disruption, service availability, customer impact and financial implications.

Separate technical impact

Technical findings such as malware, privilege escalation or mailbox access should support the business explanation.

Avoid invented impact

Do not claim data theft, legal exposure or financial loss without evidence.

Describe current status

State whether the incident is active, contained, eradicated, recovering or closed.

Describe completed actions

Summarise isolation, credential reset, token revocation, message removal, blocking and remediation.

Describe remaining actions

List the work still required and who owns it.

Describe remaining risk

Explain what exposure or uncertainty remains after containment.

State confidence

Use clear confidence labels for major conclusions.

State uncertainty

Identify unresolved questions and missing evidence.

State assumptions carefully

Assumptions should be explicit and never presented as confirmed facts.

State the decision required

Tell executives what approval, funding, communication or risk acceptance is needed.

Use one-page discipline

A good executive summary is usually brief enough to be read in a few minutes.

Keep technical detail available

The executive summary should link to or accompany the full technical report.

Use headings

Clear sections improve scanning and reduce confusion.

Use bullet points selectively

Bullets can highlight impact, actions and decisions without creating a dense event list.

Use a short timeline

Include only the major milestones that explain the incident progression.

Use severity carefully

Distinguish product severity, business impact and organisational priority.

Do not inflate language

Avoid terms such as catastrophic, sophisticated or targeted unless evidence supports them.

Use measurable scope

State the number of confirmed users, devices, mailboxes and resources affected.

Separate confirmed and suspected scope

Do not combine possible entities with confirmed victims.

Explain containment

State what was contained and what controls remain in place.

Explain recovery

Describe restoration, monitoring and validation activities.

Explain residual risk

Residual risk is the exposure that remains after response actions.

Explain customer impact

State whether customer services, data or communications were affected.

Explain regulatory impact

Mention notification or legal review only when supported and approved.

Explain financial impact

Use verified or clearly estimated figures with ownership and confidence.

Explain operational impact

Describe downtime, degraded service, delayed work or business interruption.

Explain reputational impact

Avoid speculation and distinguish actual external awareness from potential concern.

Use Security Copilot for the first draft

Copilot can translate a validated technical summary into business language.

Provide the technical source

Give Copilot the approved timeline, impact assessment and response status.

Define the executive audience

Tell Copilot whether the reader is the board, CEO, customer or regulator.

Set the output structure

Request sections such as summary, impact, response, remaining risk and decision.

Limit the length

Specify a word count or one-page limit.

Request plain language

Ask Copilot to remove unnecessary acronyms and explain required terms.

Request confidence and uncertainty

Require clear labels for confirmed, probable and unresolved findings.

Request no speculation

Tell Copilot not to infer legal, financial or reputational impact.

Review every claim

Compare the draft with the validated investigation record.

Review numbers

Confirm affected user, device, message, file and resource counts.

Review dates and times

Check every major milestone against the approved timeline.

Review impact statements

Confirm that impact language matches evidence and business-owner input.

Review response status

Ensure completed and pending actions are accurately represented.

Review residual risk

Confirm unresolved issues and controls with the incident commander.

Review audience sensitivity

Remove unnecessary personal, confidential or regulated details.

Review classification

Apply organisational handling and distribution rules.

Review legal wording

Use approved legal or regulatory language where required.

Review customer wording

Customer-facing summaries should be factual, clear and appropriately scoped.

Review board wording

Board summaries should emphasise business impact, risk, governance and required decisions.

Review media wording

Public statements require communications and legal approval.

Use version control

Record changes as the investigation develops.

Mark preliminary summaries

Early summaries should clearly state that the investigation is ongoing.

Update after material changes

Revise the summary when scope, impact or confidence changes.

Avoid summary drift

Do not let old wording persist after evidence has changed.

Preserve source links

Keep a traceable path from executive statements to technical evidence.

Record Copilot contribution

Document that Copilot assisted drafting while humans approved the final report.

Use peer review

Have technical and business reviewers confirm the summary.

Measure usefulness

Evaluate clarity, accuracy, decision support and reader understanding.

Keep the final decision human

The incident commander or authorised leader approves the final executive communication.

Example executive-summary prompt

Using the approved technical incident report and validated investigation timeline, produce a 350-word executive summary for the Chief Executive Officer.

Include:
1. What happened
2. When it occurred
3. Confirmed users, devices, systems and data affected
4. Verified business impact
5. Current incident status
6. Containment and remediation completed
7. Remaining risk and unresolved questions
8. Confidence level for major conclusions
9. Decisions or approvals required
10. Next update time or milestone

Use plain business language.
Do not speculate about financial, legal, regulatory or reputational impact.
Do not include raw logs, KQL or unnecessary acronyms.

Agent Foskett investigation: “The Board didn’t need 5,000 events…”

The technical team produced a 12-page incident report

It contained 5,000 endpoint events

Three hundred authentication records

Eighty KQL queries

Dozens of screenshots

The CEO asked one question

“Are we compromised?”

Agent Foskett rebuilt the report

Confirmed compromise affected one user and one endpoint

No evidence showed data theft or cloud compromise

The user account was secured and the device isolated

Malicious email copies were removed

Residual risk remained around credential reuse and monitoring

No executive decision was required beyond continued investigation funding

The final summary fitted on one page

The technical report remained available for the response team

Leadership understood the incident in under two minutes
The technical report proved the case. The executive summary explained the decision.

Executive-summary validation checklist

AreaQuestionValidation action
StatusIs compromise confirmed, suspected, contained or unresolved?Use the approved incident status.
ScopeAre affected counts confirmed?Check users, devices, services and data.
ImpactIs every business-impact claim supported?Confirm with technical and business owners.
TimelineAre major milestones accurate?Compare with the approved timeline.
ResponseWere listed actions completed?Review action and recovery status.
RiskIs residual risk clearly explained?State unresolved issues and controls.
UncertaintyAre unknowns visible?Document gaps and confidence.
AudienceIs the language appropriate?Remove unnecessary jargon and detail.
DecisionIs the required leadership action clear?State approval or escalation needed.
ApprovalHas the summary completed review?Record technical and executive ownership.

Key takeaways

  • Executive incident summaries translate validated technical evidence into business-facing communication.
  • Executives need the incident story, scope, impact, response, remaining risk and required decision.
  • Product severity and business impact are not the same thing.
  • Confirmed and suspected scope should remain separate.
  • Impact statements must be supported by technical evidence and business-owner input.
  • Security Copilot can accelerate drafting but should receive only approved source material.
  • Preliminary summaries must state that the investigation is ongoing.
  • Financial, legal, regulatory and reputational claims should not be inferred.
  • The full technical report should remain available for specialists.
  • The final executive communication remains a human-approved organisational record.

What Agent Foskett checked

  • Confirmed compromise
  • Affected users
  • Affected devices
  • Data-access evidence
  • Cloud evidence
  • Containment status
  • Residual risk
  • Business impact
  • Required decision
  • Final approval

Best practices

  • Lead with the answer.
  • Use plain language.
  • State confirmed scope.
  • Explain verified impact.
  • Show completed actions.
  • Describe remaining risk.
  • State uncertainty.
  • Request a decision.
  • Keep technical detail available.
  • Require human approval.

Related Agent Foskett resources

Continue through Module 2 and review the timeline and incident-summary lessons that provide the validated evidence used in executive communication.

Continue the Microsoft Security Copilot Academy

Lesson 20 translates technical findings into executive communication. The next lesson focuses on AI-assisted triage workflows.
⬅ Previous lesson
Lesson 18 — Building Investigation TimelinesTurn scattered events into a verified chronological attack story.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 2
Lesson 20 — AI-Assisted Triage WorkflowsUse Copilot to prioritise incidents, identify immediate actions and reduce repetitive review without skipping validation.

How do you produce executive incident summaries with Microsoft Security Copilot?

Security Copilot can help convert approved technical investigation findings into concise executive summaries covering incident scope, business impact, response status, remaining risk and required decisions.

Executive cybersecurity incident reporting

Executive reports should use plain language, separate confirmed and suspected impact, state uncertainty and avoid unnecessary logs, queries and technical detail.

Validate AI-generated executive summaries

Every number, date, status, impact statement and recommendation should be checked against the approved technical timeline and reviewed by authorised technical and business owners.