Course overview
Lesson 6 of 8 · 3 promptsAI for Chief Information Security Officers (CISOs)
LESSON 06 OF 8

Incident Response Planning

3 prompts for Chief Information Security Officers (CISOs)

Prompts for Chief Information Security Officers (CISOs): copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Incident Response Playbook CreationUse this when you need to develop a structured playbook for responding to specific types of incidents.
  2. 02Design Tabletop Exercises for Incident ResponseUse this when you need to design tabletop exercises that simulate security incidents to test your response plan and team readiness.
  3. 03Incident Communication TemplatesUse this when you need to draft clear and effective communication templates for notifying stakeholders about security incidents.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Incident Response Playbook Creation

Use this when you need to develop a structured playbook for responding to specific types of incidents.

Prompt

Role You are an incident response and crisis management expert. Your goal is to create a detailed, actionable playbook that ensures a consistent and effective response to {{incident_type}} incidents.

Context you provide

  • {{incident_type}}: The type of incident (e.g., cybersecurity, IT infrastructure, data privacy, natural disaster).
  • {{response_phases}}: The phases you want to cover (e.g., identification, containment, recovery).
  • {{specific_procedures}}: Any specific procedures or compliance requirements (e.g., notification timelines).

Instructions

  1. If any inputs are missing, ask me for them before proceeding.
  2. Outline a step-by-step response procedure for each phase, from initial detection to post-incident review.
  3. Include roles and responsibilities for each step, ensuring clarity on who does what.
  4. Incorporate communication protocols, including internal and external notifications.
  5. Add a section on testing and updating the playbook to keep it current.

Output format Provide the playbook in a structured format with sections for each phase, including checklists, roles, and communication templates. Use clear headings and bullet points. Keep the tone authoritative and practical.

Guardrails

  • Do not invent compliance requirements; ask for them if not provided.
  • Ensure the playbook is specific to the incident type and not generic.
  • Flag any assumptions about team structure or tools.

Example

  • {{incident_type}}: Cybersecurity incidents; {{response_phases}}: Identification, Containment, Recovery; {{specific_procedures}}: Data breach notification within 72 hours.
3 follow-up prompts
  • How can we test the playbook with a tabletop exercise?
  • What are the key metrics to evaluate the playbook's effectiveness?
  • Can you suggest a process for updating the playbook after each incident?

Open as its own page

02

Design Tabletop Exercises for Incident Response

Use this when you need to design tabletop exercises that simulate security incidents to test your response plan and team readiness.

Prompt

Role You are a security exercise facilitator who designs tabletop exercises to help organizations test and improve their incident response plans in a controlled, discussion-based setting.

Context you provide

  • {{attack_scenario}}: The type of attack to simulate (e.g., ransomware, phishing, insider threat).
  • {{organization_details}}: Key details about the organization (e.g., size, industry, critical systems) to make the scenario realistic.

Instructions

  1. If attack scenario or organization details are not provided, ask for them or use generic assumptions.
  2. Create a detailed tabletop exercise scenario, including the attack initiation, impact on critical systems, and required response actions.
  3. Include injects (e.g., new information, decisions) to keep participants engaged and test decision-making.
  4. Provide a facilitator guide with discussion questions and key points to cover.
  5. Suggest key performance indicators to measure the exercise's success and how to debrief participants.

Output format Provide a complete exercise package with sections: Scenario Overview, Injects, Facilitator Guide, and Evaluation Criteria. Use clear headings and bullet points. The tone should be practical and actionable.

Guardrails

  • Do not include unrealistic or overly complex scenarios without explanation.
  • Flag any assumptions about the organization's infrastructure.
  • Keep the exercise focused on testing the incident response plan, not other areas.

Example Attack scenario: ransomware; Organization details: 500-employee healthcare provider with EHR systems.

3 follow-up prompts
  • What key performance indicators should we measure during this exercise?
  • How can we ensure all relevant stakeholders are involved in the exercise?
  • How can we debrief participants effectively after the exercise?

Open as its own page

03

Incident Communication Templates

Use this when you need to draft clear and effective communication templates for notifying stakeholders about security incidents.

Prompt

Role You are a cybersecurity communications specialist who crafts precise, empathetic, and compliant notification templates for various stakeholders during security incidents.

Context you provide

  • {{incident_type}} — the nature of the security incident (e.g., data breach, ransomware).
  • {{audience}} — the recipient group (e.g., customers, employees, regulators, partners).
  • {{incident_details}} — key facts such as date, impact, and actions taken (if known).

Instructions

  1. Ask for the incident type, audience, and any available details if not provided.
  2. Determine the appropriate tone and level of detail for the audience (e.g., customers need reassurance, regulators need compliance specifics).
  3. Generate a template with sections: subject line, incident summary, impact assessment, actions taken, recommended actions for the recipient, and contact information.
  4. Ensure the template includes placeholders for missing information and notes on what to fill in.
  5. Provide guidance on how to customize the template for different audiences.

Output format A ready-to-use template with clear sections, placeholders in {{brackets}}, and brief instructions for customization. The tone should be professional, transparent, and reassuring.

Guardrails

  • Do not invent specific facts about the incident; use placeholders for unknown details.
  • Ensure the template complies with common regulatory requirements but note that legal review is needed.
  • Keep the language clear and avoid technical jargon for non-technical audiences.

Example Incident type: data breach; Audience: customers; Details: date of breach, types of data exposed, steps taken to secure systems.

3 follow-up prompts
  • How can I adapt this template for internal employees?
  • What are the legal requirements for notifying regulators in my jurisdiction?
  • Can you provide a template for a press release about the incident?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.