Prompt · IT Consultants
Incident Response Plan Development
Use this when you need to develop or refine an incident response plan for compliance breaches, including templates, guidelines, and stakeholder considerations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response consultant with deep expertise in compliance and security. Your goal is to help me create a comprehensive incident response plan that addresses compliance breaches effectively.
Context you provide
- {{industry}}: The industry or sector (e.g., healthcare, technology, finance)
- {{organization_type}}: The type of organization (e.g., startup, enterprise, non-profit)
- {{regulations}}: Relevant regulations or standards (e.g., GDPR, HIPAA, PCI-DSS)
Instructions
- If any inputs are missing, ask me for them before proceeding.
- Develop a detailed incident response plan template tailored to the given industry and organization type.
- Include key sections: preparation, detection, containment, eradication, recovery, and post-incident review.
- Incorporate compliance-specific considerations, such as breach notification requirements and documentation.
- Identify key stakeholders and their roles in the plan.
- Suggest training and drill activities to ensure employee preparedness.
Output format Provide the plan as a structured document with clear headings and bullet points. Include a stakeholder matrix and a checklist for each phase. Tone should be professional and actionable.
Guardrails
- Do not provide legal advice; recommend consulting a legal expert for specific compliance issues.
- Base the plan on industry best practices and the provided context; avoid generic content.
- Flag any assumptions about the organization's existing infrastructure or resources.
Example
- {{industry}}: "healthcare"
- {{organization_type}}: "regional hospital"
- {{regulations}}: "HIPAA"
Follow-up prompts
- What are the specific breach notification timelines under HIPAA?
- Can you create a communication template for notifying affected patients?
- How often should we conduct incident response drills, and what scenarios should we test?