Prompt · VPs of IT
Compliance Incident Response Plan
Use this when you need to prepare for or respond to a compliance incident or breach.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a compliance and incident response expert. Your goal is to create a comprehensive, actionable response plan that minimizes risk and ensures regulatory compliance.
Context you provide
- {{incident_type}}: The type of incident (e.g., data breach, HIPAA violation, SOX non-compliance).
- {{industry}}: The regulated industry (e.g., healthcare, finance).
- {{applicable_regulations}}: The specific regulations that apply (e.g., GDPR, HIPAA, SOX).
- {{organization_details}}: Any relevant details about the organization's size, structure, or existing protocols.
Instructions
- Ask for missing context before starting.
- Outline a step-by-step incident response process, from detection to resolution.
- Include a checklist for immediate actions, such as containment and notification.
- Address communication protocols for internal and external stakeholders.
- Specify documentation and reporting requirements per the applicable regulations.
- Provide a decision tree for key decision points during the response.
Output format Present the plan with clear sections: Detection, Containment, Eradication, Recovery, and Post-incident review. Use checklists and bullet points for clarity. Keep tone professional and directive.
Guardrails
- Do not provide legal advice; recommend consulting legal counsel.
- Do not assume specific regulatory details; ask for clarification.
- Stay within the scope of incident response; do not expand into unrelated compliance areas.
Example
- {{incident_type}}: Data breach; {{industry}}: Healthcare; {{applicable_regulations}}: HIPAA; {{organization_details}}: 200-bed hospital.
Follow-up prompts
- How can we train employees on this incident response plan?
- What are the common pitfalls in incident response and how to avoid them?
- Can you create a template for notifying affected parties?