Skip to Content
PurviewSOCI Incident Responder

SOCI Incident Responder

TL;DR: This skill drafts a structured incident brief to support a cyber incident report under the Security of Critical Infrastructure Act. It captures assets, impact classification, containment and service impact. A person reviews it and reports to the ASD’s ACSC. It makes no legal determinations.

How does the SOCI Incident Responder skill structure a critical infrastructure notification?

The SOCI Incident Responder skill drafts a structured incident notification brief for a critical infrastructure entity under the Security of Critical Infrastructure Act, recording affected assets, classification, containment, service impact, indicators of compromise and recipient details, then formatting them so a person can make the report to the ASD’s ACSC. It frames the response for a Microsoft 365 cloud environment and keeps the brief audit-ready.

When should you run this skill?

Run the SOCI Incident Responder skill when a Microsoft 365 environment supporting a critical infrastructure asset has a suspected or confirmed cyber security incident and you need a consistent, audit-ready notification brief drafted quickly from Microsoft Defender and Microsoft Purview evidence, before a person reviews and lodges it.

Example prompts:

  • “Prepare a SOCI incident report”
  • “Build a SOCI-aligned incident brief”
  • “Draft the critical cyber security incident notification brief”
  • “Respond to a critical infrastructure cyber incident”

How this skill works, step by step

  1. Confirm the asset classification under SOCI with the entity’s legal and compliance team
  2. Record incident first-detected timestamp and current containment state
  3. Classify the incident by impact, using the entity’s own reading of the Act: significant impact (critical cyber security incident) vs relevant impact (other cyber security incident)
  4. Identify affected services and Australian population segments
  5. Record containment, eradication, and recovery actions taken to date
  6. List who needs to be told: the report goes to the ASD’s ACSC, and the entity’s legal and compliance team decides any other notifications
  7. Produce the brief below

What are the SOCI reporting windows?

Incident typeReport to the ASD’s ACSC withinIf reported verbally, written record within
Critical cyber security incident (significant impact)12 hours of becoming aware84 hours of verbally notifying
Other cyber security incident (relevant impact)72 hours of becoming aware48 hours of verbally notifying

Make a written report at cyber.gov.au/report, or a verbal report on 1300 CYBER1. The obligation sits in Part 2B of the Security of Critical Infrastructure Act 2018. Whether an incident is reportable, and its classification, are determined by the entity against the Act, not by this skill.

Output format

SOCI Incident Notification Brief 1. Reporting Entity: <legal name + ABN> 2. Asset(s) in scope: <names + SOCI classification> 3. Incident Classification: Significant impact (critical) | Relevant impact (other) 4. First Detected: <ISO 8601> 5. Containment Status: <Contained | Active | Eradicated | Recovering> 6. Service Impact: <description + affected population> 7. Indicators of Compromise: <list> 8. Actions Taken: <chronology> 9. Reported To: <ASD ACSC + method, time, reference> 10. Written Record Due (if verbal): <ISO 8601>

Scope and safety

This skill does NOT:

  • Submit the notification (drafts the brief only — a person reports to the ASD’s ACSC)
  • Make legal determinations on reportability
  • Replace the entity’s critical infrastructure risk management program obligations (Part 2A of the Act)
  • Change any Microsoft 365 configuration (it reads incident evidence only)

Licensing and permissions

Licences and add-ons

Capability usedLicence position on Microsoft Learn
Microsoft Purview Audit (Standard) for the incident chronologyEnabled by default for most Microsoft 365 organisations; 180-day retention
Microsoft Purview Audit (Premium) for longer retention and intelligent insightsRequires an E5 licence or an appropriate add-on, such as the Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance)
Microsoft Defender XDR incident and alert timelineA Microsoft 365 security product licence generally entitles use; Learn recommends E5, E5 Security, A5 or A5 Security for all supported services

Least-privilege roles

  • Security Reader: a Microsoft Entra role that can access Microsoft Defender XDR incidents and alerts
  • Audit Reader role group in the Microsoft Purview portal: read access to audit evidence supporting the chronology

Microsoft Graph permissions (read-only)

This skill drafts the brief from incident evidence and does not call Microsoft Graph to submit anything. Where the chronology is assembled from Microsoft 365 telemetry, SecurityIncident.Read.All reads Microsoft Defender security incidents (with the alerts correlated into them). Audit records are searched in the Microsoft Purview portal, which the Sources below document.

The report is made to the ASD’s ACSC, not via Microsoft Graph.

Sources

The SOCI statements above (reporting windows, incident types, written-record windows, ASD ACSC as recipient, reporting channels, Part 2A risk management program) were checked on 2026-09-30 against the CISC and cyber.gov.au pages below, via search results. Notifications to sector regulators or customers were not verified and have been removed from this page. The Microsoft licence, role and permission statements were not re-verified in this review, so lastReviewed is unchanged.

Keep the brief in the organisation’s incident response repository for SOCI audit purposes.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-06-02

Last updated on