Lesson 20 — AI-Assisted Triage Workflows
Executives do not need every alert, query and event from a security investigation.
They need a clear account of what happened, what was affected, what has been done, what risk remains and what decision is required.
This lesson explains how Security Copilot can help translate validated technical evidence into concise business-facing summaries without introducing speculation, exaggerating impact or hiding uncertainty.

What you will learn
This lesson turns technical evidence into clear, accurate and decision-focused executive communication.
Executive-summary workflow
↓
Confirm scope, timeline, impact and response status
↓
Define the executive audience and purpose
↓
Ask Security Copilot for a concise business-facing draft
↓
Review every fact, number, date and impact statement
↓
Remove unsupported technical and business claims
↓
State confidence, uncertainty and remaining risk
↓
Identify the decision or approval required
↓
Complete technical, business, legal and communications review
↓
Approve the final executive summary
Executive-summary domains
| Domain | Content | Executive question |
|---|---|---|
| Incident story | What happened and how far it progressed. | What does leadership need to understand? |
| Scope | Confirmed users, devices, services, data and business units. | How large is the incident? |
| Impact | Operational, customer, data, financial and regulatory effect. | What business harm occurred? |
| Response | Containment, remediation, recovery and monitoring. | What has been done? |
| Remaining risk | Unresolved exposure, uncertainty and residual control gaps. | What still concerns us? |
| Decision | Approval, escalation, communication or risk acceptance. | What does leadership need to decide? |
Learning objectives
- Translate technical findings into business language.
- Describe scope, impact and current status.
- Explain completed actions and remaining risk.
- State confidence and uncertainty.
- Write for boards, executives and customers.
- Validate AI-generated summaries.
- Support clear leadership decisions.
What is an executive incident summary?
An executive incident summary is a concise business-facing account of what happened, what was affected, what has been done and what decisions remain.
Executive is not technical
Executives need enough technical context to understand the incident without reading every alert, query or event.
Start with the audience
A CEO, board member, customer, regulator and operational manager may need different emphasis.
Define the purpose
Clarify whether the summary supports awareness, approval, customer communication, legal review or incident governance.
Lead with the answer
State whether compromise is confirmed, suspected, contained or still under investigation.
Use plain language
Translate technical findings into understandable business terms without losing accuracy.
Avoid unnecessary jargon
Explain specialised terms only when they materially affect the decision.
Keep the attack story short
Summarise the incident in a few clear stages rather than reproducing the full timeline.
Describe what happened
Explain the incident type, initial access path and verified progression.
Describe who was affected
Identify users, teams, customers, suppliers or business units in scope.
Describe what was affected
Identify devices, applications, cloud resources, mailboxes, services and data.
Describe business impact
Explain operational disruption, service availability, customer impact and financial implications.
Separate technical impact
Technical findings such as malware, privilege escalation or mailbox access should support the business explanation.
Avoid invented impact
Do not claim data theft, legal exposure or financial loss without evidence.
Describe current status
State whether the incident is active, contained, eradicated, recovering or closed.
Describe completed actions
Summarise isolation, credential reset, token revocation, message removal, blocking and remediation.
Describe remaining actions
List the work still required and who owns it.
Describe remaining risk
Explain what exposure or uncertainty remains after containment.
State confidence
Use clear confidence labels for major conclusions.
State uncertainty
Identify unresolved questions and missing evidence.
State assumptions carefully
Assumptions should be explicit and never presented as confirmed facts.
State the decision required
Tell executives what approval, funding, communication or risk acceptance is needed.
Use one-page discipline
A good executive summary is usually brief enough to be read in a few minutes.
Keep technical detail available
The executive summary should link to or accompany the full technical report.
Use headings
Clear sections improve scanning and reduce confusion.
Use bullet points selectively
Bullets can highlight impact, actions and decisions without creating a dense event list.
Use a short timeline
Include only the major milestones that explain the incident progression.
Use severity carefully
Distinguish product severity, business impact and organisational priority.
Do not inflate language
Avoid terms such as catastrophic, sophisticated or targeted unless evidence supports them.
Use measurable scope
State the number of confirmed users, devices, mailboxes and resources affected.
Separate confirmed and suspected scope
Do not combine possible entities with confirmed victims.
Explain containment
State what was contained and what controls remain in place.
Explain recovery
Describe restoration, monitoring and validation activities.
Explain residual risk
Residual risk is the exposure that remains after response actions.
Explain customer impact
State whether customer services, data or communications were affected.
Explain regulatory impact
Mention notification or legal review only when supported and approved.
Explain financial impact
Use verified or clearly estimated figures with ownership and confidence.
Explain operational impact
Describe downtime, degraded service, delayed work or business interruption.
Explain reputational impact
Avoid speculation and distinguish actual external awareness from potential concern.
Use Security Copilot for the first draft
Copilot can translate a validated technical summary into business language.
Provide the technical source
Give Copilot the approved timeline, impact assessment and response status.
Define the executive audience
Tell Copilot whether the reader is the board, CEO, customer or regulator.
Set the output structure
Request sections such as summary, impact, response, remaining risk and decision.
Limit the length
Specify a word count or one-page limit.
Request plain language
Ask Copilot to remove unnecessary acronyms and explain required terms.
Request confidence and uncertainty
Require clear labels for confirmed, probable and unresolved findings.
Request no speculation
Tell Copilot not to infer legal, financial or reputational impact.
Review every claim
Compare the draft with the validated investigation record.
Review numbers
Confirm affected user, device, message, file and resource counts.
Review dates and times
Check every major milestone against the approved timeline.
Review impact statements
Confirm that impact language matches evidence and business-owner input.
Review response status
Ensure completed and pending actions are accurately represented.
Review residual risk
Confirm unresolved issues and controls with the incident commander.
Review audience sensitivity
Remove unnecessary personal, confidential or regulated details.
Review classification
Apply organisational handling and distribution rules.
Review legal wording
Use approved legal or regulatory language where required.
Review customer wording
Customer-facing summaries should be factual, clear and appropriately scoped.
Review board wording
Board summaries should emphasise business impact, risk, governance and required decisions.
Review media wording
Public statements require communications and legal approval.
Use version control
Record changes as the investigation develops.
Mark preliminary summaries
Early summaries should clearly state that the investigation is ongoing.
Update after material changes
Revise the summary when scope, impact or confidence changes.
Avoid summary drift
Do not let old wording persist after evidence has changed.
Preserve source links
Keep a traceable path from executive statements to technical evidence.
Record Copilot contribution
Document that Copilot assisted drafting while humans approved the final report.
Use peer review
Have technical and business reviewers confirm the summary.
Measure usefulness
Evaluate clarity, accuracy, decision support and reader understanding.
Keep the final decision human
The incident commander or authorised leader approves the final executive communication.
Example executive-summary prompt
Include:
1. What happened
2. When it occurred
3. Confirmed users, devices, systems and data affected
4. Verified business impact
5. Current incident status
6. Containment and remediation completed
7. Remaining risk and unresolved questions
8. Confidence level for major conclusions
9. Decisions or approvals required
10. Next update time or milestone
Use plain business language.
Do not speculate about financial, legal, regulatory or reputational impact.
Do not include raw logs, KQL or unnecessary acronyms.
Agent Foskett investigation: “The Board didn’t need 5,000 events…”
↓
It contained 5,000 endpoint events
↓
Three hundred authentication records
↓
Eighty KQL queries
↓
Dozens of screenshots
↓
The CEO asked one question
↓
“Are we compromised?”
↓
Agent Foskett rebuilt the report
↓
Confirmed compromise affected one user and one endpoint
↓
No evidence showed data theft or cloud compromise
↓
The user account was secured and the device isolated
↓
Malicious email copies were removed
↓
Residual risk remained around credential reuse and monitoring
↓
No executive decision was required beyond continued investigation funding
↓
The final summary fitted on one page
↓
The technical report remained available for the response team
↓
Leadership understood the incident in under two minutes
Executive-summary validation checklist
| Area | Question | Validation action |
|---|---|---|
| Status | Is compromise confirmed, suspected, contained or unresolved? | Use the approved incident status. |
| Scope | Are affected counts confirmed? | Check users, devices, services and data. |
| Impact | Is every business-impact claim supported? | Confirm with technical and business owners. |
| Timeline | Are major milestones accurate? | Compare with the approved timeline. |
| Response | Were listed actions completed? | Review action and recovery status. |
| Risk | Is residual risk clearly explained? | State unresolved issues and controls. |
| Uncertainty | Are unknowns visible? | Document gaps and confidence. |
| Audience | Is the language appropriate? | Remove unnecessary jargon and detail. |
| Decision | Is the required leadership action clear? | State approval or escalation needed. |
| Approval | Has the summary completed review? | Record technical and executive ownership. |
Key takeaways
- Executive incident summaries translate validated technical evidence into business-facing communication.
- Executives need the incident story, scope, impact, response, remaining risk and required decision.
- Product severity and business impact are not the same thing.
- Confirmed and suspected scope should remain separate.
- Impact statements must be supported by technical evidence and business-owner input.
- Security Copilot can accelerate drafting but should receive only approved source material.
- Preliminary summaries must state that the investigation is ongoing.
- Financial, legal, regulatory and reputational claims should not be inferred.
- The full technical report should remain available for specialists.
- The final executive communication remains a human-approved organisational record.
What Agent Foskett checked
- Confirmed compromise
- Affected users
- Affected devices
- Data-access evidence
- Cloud evidence
- Containment status
- Residual risk
- Business impact
- Required decision
- Final approval
Best practices
- Lead with the answer.
- Use plain language.
- State confirmed scope.
- Explain verified impact.
- Show completed actions.
- Describe remaining risk.
- State uncertainty.
- Request a decision.
- Keep technical detail available.
- Require human approval.
Related Agent Foskett resources
Continue the Microsoft Security Copilot Academy
How do you produce executive incident summaries with Microsoft Security Copilot?
Security Copilot can help convert approved technical investigation findings into concise executive summaries covering incident scope, business impact, response status, remaining risk and required decisions.
Executive cybersecurity incident reporting
Executive reports should use plain language, separate confirmed and suspected impact, state uncertainty and avoid unnecessary logs, queries and technical detail.
Validate AI-generated executive summaries
Every number, date, status, impact statement and recommendation should be checked against the approved technical timeline and reviewed by authorised technical and business owners.
