Skip to content
Cyber Unboxed
AI + SOC Workflows

AI in Incident Response: How I Use It During Real Investigations

Where an AI assistant can genuinely save an analyst time during an incident, and where a human must stay in charge.

2 min readIntermediate Sep 7, 2026

Explain Like I'm Not a Hacker

It's like having a fast junior analyst who reads everything instantly and drafts a first summary โ€” you still check their work before you trust it.

The 30-second explanation

Think of AI as a fast, tireless junior colleague. It can read a lot and draft a first summary, but it can be confidently wrong, so you check its work.

How it works

  1. 1

    1. Evidence

    Collect logs and artefacts.

  2. 2

    2. Assist

    AI drafts a summary or query.

  3. 3

    3. Verify

    The analyst checks it against the source.

  4. 4

    4. Decide

    A human approves the response.

During a ransomware incident, analysts face a mountain of information: alerts, logs, screenshots and messages, and time matters. An AI assistant can help by summarising long text, suggesting what to look at next, and turning scattered notes into a clear timeline, freeing the analyst to focus on judgement. The limits matter just as much: AI can invent details that sound right, so it should never be the final word, and sensitive incident data should only go into approved tools.

Real-world example

An analyst pastes a redacted set of process events into an approved assistant and asks for a plain-language timeline. The draft points to a suspicious sequence. The analyst then confirms each step in the original logs before writing it into the report.

How to spot it

  • Claims without a source

    Output that states a fact without pointing to the evidence it came from.

  • Data leaving approved tools

    Sensitive logs pasted into a service the organisation hasn't approved.

  • Untrusted content in the prompt

    Text from logs or files that could contain hidden instructions.

  • Actions without sign-off

    A consequential step, like isolating a host, taken without human approval.

What to do

  1. 1Treat every AI-drafted conclusion as a hypothesis to verify, not a finished finding.
  2. 2Only use tools your organisation has approved for handling incident data.
  3. 3Keep a human in the loop for any action with real consequences.

Stay curious. Stay safer.

This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.

Explore More

Keep reading