SOCI Incident Responder
TL;DR: This skill drafts a structured incident brief to support a cyber incident report under the Security of Critical Infrastructure Act. It captures assets, impact classification, containment and service impact. A person reviews it and reports to the ASD’s ACSC. It makes no legal determinations.
How does the SOCI Incident Responder skill structure a critical infrastructure notification?
The SOCI Incident Responder skill drafts a structured incident notification brief for a critical infrastructure entity under the Security of Critical Infrastructure Act, recording affected assets, classification, containment, service impact, indicators of compromise and recipient details, then formatting them so a person can make the report to the ASD’s ACSC. It frames the response for a Microsoft 365 cloud environment and keeps the brief audit-ready.
When should you run this skill?
Run the SOCI Incident Responder skill when a Microsoft 365 environment supporting a critical infrastructure asset has a suspected or confirmed cyber security incident and you need a consistent, audit-ready notification brief drafted quickly from Microsoft Defender and Microsoft Purview evidence, before a person reviews and lodges it.
Example prompts:
- “Prepare a SOCI incident report”
- “Build a SOCI-aligned incident brief”
- “Draft the critical cyber security incident notification brief”
- “Respond to a critical infrastructure cyber incident”
How this skill works, step by step
- Confirm the asset classification under SOCI with the entity’s legal and compliance team
- Record incident first-detected timestamp and current containment state
- Classify the incident by impact, using the entity’s own reading of the Act: significant impact (critical cyber security incident) vs relevant impact (other cyber security incident)
- Identify affected services and Australian population segments
- Record containment, eradication, and recovery actions taken to date
- List who needs to be told: the report goes to the ASD’s ACSC, and the entity’s legal and compliance team decides any other notifications
- Produce the brief below
What are the SOCI reporting windows?
| Incident type | Report to the ASD’s ACSC within | If reported verbally, written record within |
|---|---|---|
| Critical cyber security incident (significant impact) | 12 hours of becoming aware | 84 hours of verbally notifying |
| Other cyber security incident (relevant impact) | 72 hours of becoming aware | 48 hours of verbally notifying |
Make a written report at cyber.gov.au/report, or a verbal report on 1300 CYBER1. The obligation sits in Part 2B of the Security of Critical Infrastructure Act 2018. Whether an incident is reportable, and its classification, are determined by the entity against the Act, not by this skill.
Output format
SOCI Incident Notification Brief
1. Reporting Entity: <legal name + ABN>
2. Asset(s) in scope: <names + SOCI classification>
3. Incident Classification: Significant impact (critical) | Relevant impact (other)
4. First Detected: <ISO 8601>
5. Containment Status: <Contained | Active | Eradicated | Recovering>
6. Service Impact: <description + affected population>
7. Indicators of Compromise: <list>
8. Actions Taken: <chronology>
9. Reported To: <ASD ACSC + method, time, reference>
10. Written Record Due (if verbal): <ISO 8601>Scope and safety
This skill does NOT:
- Submit the notification (drafts the brief only — a person reports to the ASD’s ACSC)
- Make legal determinations on reportability
- Replace the entity’s critical infrastructure risk management program obligations (Part 2A of the Act)
- Change any Microsoft 365 configuration (it reads incident evidence only)
Licensing and permissions
Licences and add-ons
| Capability used | Licence position on Microsoft Learn |
|---|---|
| Microsoft Purview Audit (Standard) for the incident chronology | Enabled by default for most Microsoft 365 organisations; 180-day retention |
| Microsoft Purview Audit (Premium) for longer retention and intelligent insights | Requires an E5 licence or an appropriate add-on, such as the Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance) |
| Microsoft Defender XDR incident and alert timeline | A Microsoft 365 security product licence generally entitles use; Learn recommends E5, E5 Security, A5 or A5 Security for all supported services |
Least-privilege roles
- Security Reader: a Microsoft Entra role that can access Microsoft Defender XDR incidents and alerts
- Audit Reader role group in the Microsoft Purview portal: read access to audit evidence supporting the chronology
Microsoft Graph permissions (read-only)
This skill drafts the brief from incident evidence and does not call Microsoft Graph to submit anything. Where the chronology is assembled from Microsoft 365 telemetry, SecurityIncident.Read.All reads Microsoft Defender security incidents (with the alerts correlated into them). Audit records are searched in the Microsoft Purview portal, which the Sources below document.
The report is made to the ASD’s ACSC, not via Microsoft Graph.
Related skills
- Defender Incident Hygiene Review: run before an incident to check the Defender XDR queue for response gaps
- Audit Log Retention and Coverage Validator: run before an incident to confirm audit logging and retention are in place
- Compliance Manager Control Mapper: run after this to map tenant controls to the ISM, Essential Eight, SOCI and the Privacy Act
- Australian Compliance for Microsoft 365 Copilot and AI: pillar page for Australian compliance evidence across the tenant
Sources
The SOCI statements above (reporting windows, incident types, written-record windows, ASD ACSC as recipient, reporting channels, Part 2A risk management program) were checked on 2026-09-30 against the CISC and cyber.gov.au pages below, via search results. Notifications to sector regulators or customers were not verified and have been removed from this page. The Microsoft licence, role and permission statements were not re-verified in this review, so lastReviewed is unchanged.
- Notification of Cyber Security Incidents (CISC guidance)
- Cyber Security Incident Reporting (CISC)
- Mandatory Incident Reporting (cyber.gov.au)
- Security of Critical Infrastructure Act 2018 (CISC)
- Security of Critical Infrastructure Act 2018 (Federal Register of Legislation)
- Guidance for the critical infrastructure risk management program (CISC)
- Learn about auditing solutions in Microsoft Purview
- Get started with auditing solutions
- Search the audit log
- Manage access to Microsoft Defender XDR with Microsoft Entra global roles
- Turn on Microsoft Defender XDR
- Microsoft Graph permissions reference
- Step 4: eDiscovery and audit premium plans (Audit Reader role group)
Keep the brief in the organisation’s incident response repository for SOCI audit purposes.
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-06-02